Governance and Security Engineer
3 days ago
Security · APAC (Hong Kong or Singapore) · Hybrid / Remote
Governance & Security EngineerReinvent finance with Reap. We're building resilient, compliant, and secure infrastructure for global money movement. As our Governance & Security Engineer, you'll bridge ICT governance and hands‑on security operations-standing up controls and practices aligned to DORA while keeping our systems hardened day to day. You'll help define the playbook, tune the tools, and raise the bar on operational resilience across the company.
Security at ReapAt Reap, security is how we earn trust. We merge traditional finance with digital assets, so our standards must be clear, auditable, and resilient by design. You will help operationalize DORA, ISO 27001, and our ICT risk framework-from policy and control design to real‑time operations-so teams can ship quickly without compromising safety.
- Implement and mature our ICT Risk Management Framework aligned with DORA, ISO 27001, and NIST CSF.
- Maintain policies, standards, and procedures; ensure consistent adoption across cloud, on‑prem, and vendors.
- Contribute to control testing plans, RCSA updates, and risk registers; support control attestation and board‑level reporting.
- Support vendor risk management and outsourcing oversight in line with DORA Article 30.
- Coordinate periodic self‑assessments and independent audits (internal, external, and regulator‑driven).
- Operate and tune EDR platforms such as SentinelOne or CrowdStrike.
- Drive configuration baselines, patch compliance, and vulnerability remediation tracking.
- Support detection, triage, escalation, and post‑incident reviews in line with DORA Article 17.
- Maintain logs, alerts, and metrics across SIEM, MDM, and security tooling; contribute to playbooks and runbooks.
- Participate in penetration testing and prioritize remediation with engineering teams.
- Manage SSO and the user lifecycle across cloud platforms and SaaS tools.
- Enforce MFA, least privilege, and periodic access reviews.
- Support encryption controls, secure configurations, and data protection measures.
- Maintain MDM/DR processes that support ICT service continuity per DORA Article 28.
- Run resilience testing, scenario simulations, and disaster recovery exercises.
- Define and document RTOs and RPOs; maintain asset inventories and dependency maps to critical business functions.
- Deliver security awareness sessions and contribute to company‑wide communications.
- Track and report metrics on incidents, vulnerabilities, access reviews, and training effectiveness.
- Feed lessons learned into control improvements and operating procedures.
- Experience building or maintaining information security management systems.
- Strong understanding of regulatory expectations under DORA, GDPR, and MiCAR.
- Skilled in policy drafting, governance documentation, and control monitoring.
- Proficient with modern EDR platforms (SentinelOne, CrowdStrike).
- Hands‑on with network security, vulnerability management, and secure configurations.
- Familiar with AWS and cloud hardening practices.
- Working knowledge of SIEM operations, MDM/DR, patch management, and integrating security tooling.
- Excellent communicator who partners across IT, Engineering, Risk, and Compliance.
- Comfortable operating in a fast‑paced, cross‑functional environment.
- Strong analytical and documentation skills that support audit readiness.
- 4+ years in Information Security or ICT Governance.
- Strong technical knowledge of endpoint protection, access management, and network controls.
- Experience supporting ISO 27001, SOC 2, or equivalent frameworks.
- Familiarity with DORA Articles 5-8 and 28-30 or comparable regulatory frameworks.
- Ability to draft and maintain policies, standards, registers, and control evidence.
- Practical experience operating EDR, MDM, SSO, and vulnerability management tools.
- Experience in fintech, crypto, or regulated financial services.
- Knowledge of AWS or other cloud environments.
- Recognized certifications such as CompTIA Security+, ISO 27001 Lead Implementer, or Google Cybersecurity.
- Experience preparing materials for board or regulator reporting.
- A chance to build a DORA‑aligned ICT governance and security capability from the ground up.
- Exposure to both regulatory frameworks and advanced technical controls.
- Growth pathways toward Governance Manager or Security Architect.
- Direct collaboration with the CISO, CIO, and Compliance on enterprise resilience.
Reap is a leading global payment technology provider that enables financial connectivity and access for businesses worldwide. By merging traditional finance with digital assets, bridging disparate economies, and connecting key financial players, we are transforming the financial landscape into a more interconnected and interoperable space for efficient money movement.
With stablecoin‑enabled corporate cards, payout solutions, and expense management tools, we streamline financial operations and empower businesses to scale. Our APIs enable businesses to embed finance into their own products and services, from issuing Visa cards to facilitating cross‑border payments.
Reap is supported by a strong network of investors, including Acorn Pacific Ventures, Arcadia Funds, HashKey Capital, Hustle Fund, Fresco Capital, Abacus Ventures, and Payment Asia.
Founded in Coworkers 300+
-
Manager / Deputy Manager ()
2 days ago
Singapore OT Security Governance & Compliance Full timeYou will be part of a team responsible for maintaining governance oversight on PSA's security policies, standards, and best practices, and ensuring compliance with regulatory and enterprise requirements.Requirements:Processes a degree in Computer Engineering, Computer Science, Cybersecurity, Information Security, Electrical & Electronics Engineering or...
-
Senior Security Governance Engineer
3 days ago
Singapore Shopee Full timeSenior Security Governance Engineer - Infrastructure Security About The Team We are looking for a senior security engineer to support security governance projects and optimise security tool operations. This role requires a strong technical foundation in security engineering, risk management, and automation, along with the ability to drive security...
-
Singapore Home Team Science and Technology Agency (HTX) Full time**What the role is** - The jobholder will be part of the Cloud Engineering Team. The team is charged with a mission to transform the way HTX delivers software by leveraging on cloud innovation to enable agile software development, zero-trust security, continuous devsecops and artificial intelligence. We are looking for Lead Cloud Engineer, Governance who is...
-
Security Governance Senior Engineer
2 weeks ago
Singapore Shopee Full timeDepartment Engineering and Technology - LevelExperienced (Individual Contributor) - LocationSingapore The Engineering and Technology team is at the core of the Shopee platform development. The team is made up of a group of passionate engineers from all over the world, striving to build the best systems with the most suitable technologies. Our engineers do...
-
Data Governance Consultant
2 days ago
Singapore MHA - Internal Security Department (ISD) Full time**What the role is** - Data is integral to ISD's operations. As the use of data and analytics grows, having a vigorous data security and management regime becomes even more essential to enable secure data operations. You will join the central data management and governance team that reports to the Chief Data Officer (CDO), where you will work together with...
-
Governance and Security Lead
1 hour ago
Singapore Reap Full timeSecurity · APAC (Hong Kong or Singapore) · Hybrid / RemoteGovernance & Security LeadReinvent finance with Reap. We're building resilient, compliant, and secure infrastructure for global money movement. As our Governance & Security Lead, you'll bridge ICT governance and hands‑on security operations-standing up controls and practices aligned to DORA while...
-
Security Supervisor
2 days ago
Singapore STAR SECURITY SERVICES Full timeThe security supervisor is responsible for managing various aspects of a security department for a government agency or business. Some of the duties that make up the security supervisor job description include monitoring security equipment, supervising other security staff, like the security guards, and assembling, documenting abnormal occurrences on a job...
-
Security Governance Manager
2 weeks ago
Singapore Robert Half Full time**The Company** Our client is a leading MNC in the medical devices industry with worldwide presence. They are currently looking for a Security Governance Manager to join the team. This is an APAC focused role. **The Role** As a Security Governance Manager, you will be responsible for developing and implementing an enterprise security governance program...
-
Network and Security Engineer
3 days ago
Singapore NCS Hong Kong and Singapore Full timeNCS is a leading technology services firm that operates across the Asia Pacific region in over 20 cities, providing consulting, digital services, technology solutions, and more. We believe in harnessing the power of technology to achieve extraordinary things, creating lasting value and impact for our communities, partners, and people. Our diverse workforce...
-
Lead Engineer, Planning
2 days ago
Singapore Home Team Science and Technology Agency (HTX) Full time**What the role is** - The Home Team Science and Technology Agency (HTX) is a statutory board under the Ministry of Home Affairs (MHA) which aims to pioneer innovation solutions and develop world class science and technology capabilities to transform and support the Home Team Departments (HTD) operations in maintaining order and enhancing security for...