Data Security and Compliance Engineer
Who Are We?
dtcpay is a MAS licensed payment service provider that bridges traditional finance and digital assets. We enable businesses to accept and make payments in both fiat and digital currencies, delivering secure, efficient, and seamless payment experiences across borders. As we expand globally, we are shaping the future of digital payments. We are also recognised as one of Singapore’s Top 10 Startups in the LinkedIn Top Startups 2025 list, a reflection of our momentum and the exciting journey ahead for our team.
What You'll Do:
- Monitor cybersecurity, data security, and privacy requirements in Singapore and other jurisdictions where we operate. Identify local obligations and cross-border data risks, and produce gap analyses, risk assessments, and remediation plans.
- Develop and maintain data security SOPs covering data inventory, classification, collection, storage, transfer, sharing, disclosure, masking, access control, disposal, and incident response. Drive adoption across teams, assess effectiveness, and track remediation to completion.
- Conduct security and compliance reviews for key products and projects. Assess risks across jurisdictions, improve product compliance processes, and contribute to security requirements, architecture, and exception reviews for cross-border use cases.
- Support management system development and certification efforts related to ISO 27001 and ISO 27701. Work with regulators, external assessors, and internal audit teams to prepare for reviews and resolve findings.
- Build and operate the data security management framework, conduct cross-regional risk assessments, and use models such as DSMM to guide improvements. Coordinate data inventory and classification efforts across business and technical teams.
- Develop data security controls suited to different business needs and jurisdictions. Advise on encryption, access control, and data masking, and support the evaluation and rollout of security tools.
- Deliver cybersecurity, data security, and privacy training to global teams. Work with internal and external partners to embed security requirements into everyday business processes.
What We're Looking For:
- Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or a related discipline.
- A minimum of 5 years of experience in information security, data security, privacy, or technology risk, including hands-on delivery of security controls or compliance programs.
- Experience building and implementing security or data compliance frameworks across regions, with knowledge of Singapore’s information security and personal data protection requirements and how they differ from requirements elsewhere.
- Familiarity with Singapore’s Personal Data Protection Act (PDPA), ISO 27001, ISO 27701, GDPR, and the practical application of regulatory requirements through policies, processes, and controls.
- Knowledge of security controls such as encryption, access control, intrusion detection, vulnerability scanning, and data masking. Experience with data inventory and classification; familiarity with data security maturity models such as DSMM.
- Practical experience with cross-border data risk assessments and security incident response. Ability to write data security policies, standards, and SOPs and drive their adoption across regional teams.
- Strong communication, risk assessment, English documentation, and project delivery skills. Ability to work independently with regulators, auditors, and external assessors.
- Proficiency in both English and Mandarin as you will need to work closely with Chinese vendors.
- The role is based fully onsite, requiring your presence in the office.
Nice to Have:
- Experience in financial services or payments, cross-border business compliance, or implementing data security controls
- Certifications such as CISP, CISSP, or ISO 27001 Lead Auditor
Benefits
Competitive compensation and benefits packages
Regional exposure and career growth opportunities
Opportunity to work with a dynamic and innovative digital payments
Exposure to cross-functional collaboration and involvement
Mentorship and guidance from experienced professionals