Reap is a leading global payment technology provider that enables financial connectivity and access for businesses worldwide. By merging traditional finance with digital assets, bridging disparate economies, and connecting key financial players, we are transforming the financial landscape into a more interconnected and interoperable space for efficient money movement.
With stablecoin‑enabled corporate cards, payout solutions, and expense management tools, we streamline financial operations and empower businesses to scale. Our APIs enable businesses to embed finance into their own products and services, from issuing Visa cards to facilitating cross‑border payments.
Reap is supported by a strong network of investors, including Acorn Pacific Ventures, Arcadia Funds, HashKey Capital, Hustle Fund, Fresco Capital, Abacus Ventures, and Payment Asia.
Founded in 2018
Reap builds financial connectivity for a multi‑rail world-traditional finance, stablecoins, and real‑time payments. Security is foundational to that mission. We're looking for a pragmatic engineer who can turn regulation into robust systems, and complex threats into clear controls. You'll partner with Engineering, Risk, and Operations to keep value moving safely, globally, and 24/7.
We had a data breach. Employees downloaded data from Snowflake and uploaded it to consumer AI tools including ChatGPT and Gemini. That data included customer records, counterparty financial data, and card- related data. Under GDPR Art. 28, sharing personal data with a third-party processor without a DPA is a breach, regardless of intent.
DNS blocking and an emergency policy are in place as interim controls. You will build what comes next: the CASB controls that give us visibility into AI tool usage across the company, the DLP policies that stop sensitive data leaving our environment, the approved enterprise AI tooling that gives people a safe way to be productive, and the detection rules that catch it if something slips through.
What You Will Do
• Deploy and operationalise Microsoft Defender for Cloud Apps (CASB): configure app discovery, shadow IT reporting, session controls, and data upload blocking for unsanctioned AI platforms.
• Build and maintain DLP policies for AI platform data submission: define sensitive data patterns (PAN, IBAN, account numbers, customer identity fields) and enforce blocking rules across CASB, Microsoft Purview, and endpoint DLP.
• Write SIEM detection rules for AI-related data leakage: bulk Snowflake exports followed by AI platform uploads, anomalous SaaS upload volumes, AI platform access from corporate devices outside the approved list.
• Own the technical onboarding of approved enterprise AI tools: zero data retention configuration, no model training on Reap data, audit logging, and Okta SSO integration.
• Run and maintain the shadow AI inventory: identify every AI tool in use across the company, classify it
against our risk framework, and report monthly to the CISO.
• Own prompt injection detection and prevention for any AI-integrated products or internal tools.
• Assess the security posture of AI vendors we work with: data retention policies, sub-processors, DPA
coverage, and what actually happens to data we submit.
• Build and own the AI data leakage incident response playbook.
• Hands-on CASB deployment experience. Microsoft Defender for Cloud Apps, Netskope, or Zscaler. You have configured shadow IT discovery and data upload controls, not just read the documentation.
• DLP policy authoring. Microsoft Purview or equivalent. You have built sensitive information types, tuned false positive rates, and enforced policies that actually work in practice.
• You understand how the major AI platforms handle data. OpenAI, Anthropic, Google. You know what a
zero-retention enterprise DPA looks like and how to verify it is being honoured.
• SIEM detection rule writing. KQL or equivalent. You can write a query that detects bulk Snowflake access followed by an upload event to a consumer AI domain within a defined time window.
• AWS security fundamentals. IAM, network controls, API gateway security. You understand how AI API
calls move through a cloud environment.
• GDPR Art. 28 and AI platform DPA implications. You know what the legal exposure is when data is
submitted to an AI platform without a valid DPA.
• Microsoft SC-400 (Information Protection) or CCSP certification.
• Prompt injection attack and defence experience.
• PDPA or PDPO familiarity.
• DORA third-party ICT risk requirements.
• Prior experience responding to an AI-related data incident.
• This is one of the most current and genuinely interesting problems in enterprise security right now. You will
be building controls for a threat vector that most companies are still figuring out.
• You will have a confirmed incident to build against, which means your work will have immediate, measurable
impact.
• We use AI tools extensively ourselves. You will work inside an AI-first company while helping make that safe.
• Remote-first, global team, and a fast-moving fintech mid-acquisition by Payward/Kraken.r.
A vibrant, inclusive work culture.
Annual leave to relax and recharge, plus public holidays.
Health insurance budget.
Be part of a fast‑growing global team.
Flexible remote work options.
Home office equipment budget.
Your own Corporate Reap Card-no more out‑of‑pocket spending.
Reap is a leading global payment technology provider that enables financial connectivity and access for businesses worldwide. By merging traditional finance with digital assets, bridging disparate economies, and connecting key financial players, we are transforming the financial landscape into a more interconnected and interoperable space for efficient money movement.
With stablecoin‑enabled corporate cards, payout solutions, and expense management tools, we streamline financial operations and empower businesses to scale. Our APIs enable businesses to embed finance into their own products and services, from issuing Visa cards to facilitating cross‑border payments.
Reap is supported by a strong network of investors, including Acorn Pacific Ventures, Arcadia Funds, HashKey Capital, Hustle Fund, Fresco Capital, Abacus Ventures, and Payment Asia.
Founded in 2018 Coworkers 300+

Reap is a leading global payment technology provider that enables financial connectivity and access for businesses worldwide. By merging traditional finance with digital assets, bridging disparate economies, and connecting key financial players, we are transforming the financial landscape into a more interconnected and interoperable space for efficient money movement.
With stablecoin-enabled corporate cards, payout solutions, and expense management tools, we streamline financial operations and empower businesses to scale. Our APIs enable businesses to embed finance into their own products and services, from issuing Visa cards to facilitating cross-border payments.
Reap is supported by a strong network of investors, including Acorn Pacific Ventures, Arcadia Funds, HashKey Capital, Hustle Fund, Fresco Capital, Abacus Ventures, and Payment Asia. Founded in 2018 in Hong Kong, we have since expanded to a team of over 100 across the globe.