Avatar for Aspire
Aspire
Actively Hiring
The #1 all-in-one financial operating system for businesses
  • Top 10% of responders
    Aspire is in the top 10% of companies in terms of response time to applications
  • Responds within two weeks
    Based on past data, Aspire usually responds to incoming applications within two weeks
  • Scale Stage
    Rapidly increasing operations
  • +3

GRC Lead

Posted: 1 month ago
Visa Sponsorship

Not Available

RelocationAllowed
Hiring contact

Giovanni Casinelli

About the job

About the team:

At Aspire, we recognize that data and infrastructure security are paramount to the success and trust of our customers. Our Security Team is at the forefront of protecting and securing our systems, ensuring compliance with industry best practices, and continuously learning and evolving to stay ahead of emerging threats. Our emphasis extends to data privacy, seamlessly integrating it into our security initiatives.

About the role:

As the Governance, Risk, and Compliance (GRC) Lead, you will be responsible for hands-on driving IT certification, audits and licensing efforts within Aspire and subsidiaries. You will be reporting to Aspire’s Head of Information Security and will have the exciting opportunity to be part of a fast-growing team in one of the top 100 fintech companies globally!

  • Global Governance:
    • Create, maintain, and periodically review IT security policies, procedures, guidelines, and frameworks in accordance with industry standards.
    • Help to align IT/security solutions and infrastructure with MAS TRM, MAS Cyber Hygiene, PDPA, PCI-DSS, SOC2, ISO 27001, GDPR, DORA, CCPA, PDPO, CFI, Privacy Act 1988 and ACSC Essential Eight.
  • Risk Management:
    • Create and conduct risk assessments and drive other IT/security related activities and projects to identify vulnerabilities.
    • Run the IT Risk committee
    • Monitor the organization's risk posture and ensure mitigation strategies are in place.
  • Vendor Due Diligence:
    • Perform thorough due diligence on third-party vendors, assessing their security posture, compliance with relevant regulations, and overall risk level before onboarding.
    • Regularly review vendor risk profiles and monitor them for any changes that could impact the organization.
  • Compliance:
    • Ensure practices and standards compliance, particularly concerning MAS TRM, MAS Cyber Hygiene, PDPA, PCI-DSS, SOC2, ISO 27001, GDPR, DORA, CCPA, PDPO, CFI, Privacy Act 1988 and ACSC Essential Eight.
    • Conduct and drive audits, penetration tests, and other compliance efforts, addressing findings effectively.
  • Collaboration:
    • Liaise with internal and external auditors, plus directly with regulatory bodies across the region as well as in EU, US, AU, JP, HK and UK to ensure full compliance with technology related requirements.
    • Collaborate and drive cross-departmentally communication and full compliance with technology risk requirements over the whole technology stack.
  • Reporting:
    • Provide regular precise and condensed updates to stakeholders about the company's GRC status and initiatives.
    • Produce actionable reports based on audits, risk assessments, compliance efforts with key points, milestones, ETAs and high level considerations.
  • Continuous Improvement:
    • Drive information security awareness campaigns tailored to regulatory requirements and standards.
    • Stay updated with the latest changes and best practices in MAS TRM, MAS Cyber Hygiene, PDPA, PCI-DSS, SOC2, ISO 27001, GDPR, DORA, CCPA, PDPO, CFI, Privacy Act 1988 and ACSC Essential Eight and implement these into the organization.

Minimum qualifications:

  • A degree in Technology, Engineering, MBA or a related qualification.
  • Proven experience in cybersecurity, GRC, with direct contact to a regulatory body.
  • Minimum of 7 years of experience in the GRC sector.
  • Strong understanding with at least PCI-DSS, SOC2, and ISO 27001.
  • Proven experience to create/drive risk governance, policies and procedure from scratch
  • Ability to navigate several projects at the same time with tight deadlines.
  • Very strong communication skills in English, proficient in conveying complex technical and regulatory details in a structured and concise way.
  • Able to condense complex topics into a well organized and visually appealing slide deck for senior management.
  • Collaborative team player, eager to work across departments to ensure full compliance.

Preferred qualifications:

  • Familiarity with MAS TRM, MAS Cyber Hygiene, PDPA
  • Worked in MAS-regulated environments
  • Relevant certifications such as CISM, CISA, CISSP, PCI QSA or ISO 27001 Lead Auditor are highly desirable
  • Strong experience also in MAS TRM, MAS Cyber Hygiene, PDPA, GDPR, DORA, CCPA, PDPO, CFI, Privacy Act 1988 and ACSC Essential Eigh
  • This will be a hybrid position (2 days in office) based in Gurgaon or Bangalore.

About the company

Aspire company logo

Aspire

Actively Hiring
The #1 all-in-one financial operating system for businesses201-500 Employees
  • Top 10% of responders
    Aspire is in the top 10% of companies in terms of response time to applications
  • Responds within two weeks
    Based on past data, Aspire usually responds to incoming applications within two weeks
  • Scale Stage
    Rapidly increasing operations
  • Top Investors
    This company has received a significant amount of investment from top investors
  • YC Funded
    Startup funded by Y Combinator
  • Growing fast
    Showed strong hiring growth in the past month
Learn more about Aspire image

Funding

AMOUNT RAISED
$194M
FUNDED OVER
3 rounds
Rounds
B
$158,000,000
Series B - Sep 2021+2

Founders

Andrea Baronchelli
CEO / Co-founder • 3 years • 7 years
Singapore
image
Giovanni Casinelli
CTO • 3 years • 7 years
Singapore
image
View the team image