Head of Information Security

Open 38d

You will drive regional information security by translating APAC regulatory requirements into actionable controls, leading risk assessments and mitigation for cloud infrastructure, APIs, and trading systems. You will collaborate with engineering to embed secure-by-design principles, guide IAM and network architecture, manage audits and regulatory exams, and develop regional policies, standards, and controls.

Responsibilities

  • Manage APAC information security program
  • Interpret and implement local regulatory requirements into security controls
  • Serve as APAC security compliance and regulatory expert
  • Ensure alignment with global security, legal, and compliance on financial services and data protection regulations
  • Lead risk identification, assessment, and mitigation for cloud infrastructure, APIs, and trading systems
  • Manage and evolve regional risk registers, reporting, and governance
  • Ensure adherence to global frameworks such as ISO 27001, SOC 2, and CSA STAR
  • Partner with engineering for secure-by-design cloud-native infrastructure
  • Provide guidance on IAM, network security architecture, Secure SDLC, and infrastructure hardening and monitoring
  • Review architecture to embed security and compliance early
  • Lead and support regulatory exams, audits, and assessments
  • Act as primary liaison for regulators, external auditors, and local compliance partners
  • Develop and maintain regional security policies, standards, and procedures
  • Localize global policies for APAC regulatory environments
  • Drive control implementation and testing across security and compliance frameworks

Requirements

  • 6+ years of experience in information security, cybersecurity, or GRC, preferably in fintech or financial services
  • Fluent in Japanese and English, written and verbal
  • Strong understanding of cloud security, application security, and infrastructure security
  • Experience with security and compliance frameworks such as ISO 27001 and SOC 2
  • Direct experience supporting regulatory requirements in Japan and/or APAC (e.g., APPI, FSA, MAS)
  • Proven experience handling audits, regulatory exams, or compliance programs
  • Ability to work cross-functionally with engineering, product, and compliance teams
  • Strong communication skills with ability to translate technical risks into business impact

Benefits

  • Stock options
  • Health benefits
  • One-time home office setup stipend (USD 500)
  • Monthly stipend (USD 150 via Brex Card)