AI Cloud Security Compliance Manager
Save this job and keep your search organized
Create a free account to save jobs, create alerts and return to this listing from your dashboard.
By continuing, you agree to our Terms & Privacy Policy.
Bitdeer is a world-leading technology company for Bitcoin mining and AI cloud. Bitdeer is committed to providing comprehensive Bitcoin mining solutions for its customers. Apart from designing industry-leading ASIC chips and manufacturing mining rigs, the Group handles complex processes involved in computing across the value chain. This includes equipment procurement, transport logistics, datacenter design and construction, equipment management, and network and facility operations. Bitdeer also offers advanced cloud capabilities to customers with a high demand for artificial intelligence. Headquartered in Singapore, Bitdeer operates globally with a diversified 3 GW energy portfolio, and deploys Bitcoin mining and HPC datacenters in the United States, Bhutan, Norway, Canada, Malaysia, and Ethiopia.
About the teamOwn the security compliance program for Bitdeer's AI Cloud business line, leading multi-framework certifications, AI governance implementation, customer compliance engagement, and evidence automation. This role requires both traditional cloud compliance expertise (SOC 2, ISO 27001) and emerging AI compliance frameworks (ISO 42001, NIST AI RMF, EU AI Act, IMDA AI Verify), as well as the ability to engage platform engineering teams at a deep technical level.
What you will be responsible for- Multi-Framework Certification Leadership: Serve as Program Owner for AI Cloud's SOC 2 Type I/II and ISO/IEC 27001:2022 certifications, managing the end-to-end process from gap assessment through certification. Define audit scope covering GPU bare metal, virtualized GPU, AI Studio, model hosting, and other product modules. Lead ISO/IEC 42001 (AI Management System) certification, designing AI governance processes, AI Impact Assessments, and model lifecycle controls from the ground up. Plan and drive additional certifications such as CSA STAR Level 2 and IMDA AI Verify framework adoption. Build and maintain a Unified Control Framework that maps SOC 2 TSC, ISO 27001 Annex A, ISO 42001, CCM, and NIST AI RMF requirements into a single control library to eliminate cross-framework duplication. Coordinate external audit firms, managing audit timelines, control testing, finding remediation, and management responses.
- AI Governance & Emerging AI Regulation Implementation: Operationalize NIST AI RMF (Govern / Map / Measure / Manage) into concrete governance processes and control points for the AI Cloud platform. Track EU AI Act implementation timeline (especially GPAI provisions effective 2 August 2026), assess responsibility pass-through for AI Cloud customers hosting high-risk AI systems, and design compliance guardrails. Lead IMDA AI Verify framework adoption and engagement with Singapore local regulators. Translate OWASP LLM Top 10 and MITRE ATLAS into AI Cloud security control checklists, partnering with platform teams to operationalize detection capabilities. Design AI model supply chain governance – customer-uploaded model weight review, Hugging Face / GitHub model source security assessment, Model Card and Datasheet requirements.
- Customer Compliance & Sales Enablement: Serve as the AI Cloud security team's primary customer-facing compliance interface, responding to Security Questionnaires (SIG Lite/Core, CAIQ v4, custom customer templates). Maintain the Trust Center / Security Portal, proactively publishing AI Cloud security control descriptions, compliance certificates, pen test summaries, and SOC 2 bridge letters to reduce repeated customer inquiries. Support Sales and Solution Architect teams in addressing customer AI security concerns during the pre-sales phase – training data isolation, model weight confidentiality, inference API non-retention. Negotiate security and privacy clauses in customer contracts (DPA, SLA, Right to Audit, Breach Notification Timeline) with technical and compliance input. Coordinate and execute customer audits, including on-site or remote audits of AIDC facilities.
- Technical Control Evidence Automation & GRC Platform Operations: Lead GRC platform selection (Vanta / Drata / Secureframe / OneTrust / Tugboat Logic) and drive deployment. Design evidence automation integrating AI Cloud's critical technical systems: cloud management platform, HIDS (Wazuh), Tetragon, Kafka audit pipeline, Vault, Teleport, Jira, Git. Drive evidence collection automation rate to 70 %+, dramatically reducing manual evidence gathering. Collaborate with SecOps to establish continuous control effectiveness monitoring, ensuring controls remain auditable outside formal audit periods.
- AI Cloud Business Line Security Governance: Draft, maintain, and publish the AI Cloud security policy framework (Information Security Policy, Access Control, Incident Response, Business Continuity, AI Ethics, etc.). Build and maintain the AI Cloud risk register; lead quarterly risk assessment meetings and produce risk heat maps for management