Our client is an expanding global technology company, seeking an experienced Compliance and Information Security Analyst to safeguard its digital infrastructure and maintain top-tier international standards. You will oversee corporate compliance, audit readiness, data privacy frameworks, and threat mitigation across multi-region operating markets. This position is ideal for a detail-oriented security professional looking to drive enterprise compliance, AI data governance, and proactive risk management in a fast-paced environment.
Own end-to-end vulnerability management—scheduling automated scans, prioritizing SAST/DAST findings, and driving technical remediation across application and infrastructure layers.
Lead the complete incident response lifecycle, managing security event monitoring, containment, forensic mitigation, and root-cause reporting for executive leadership.
Direct internal and external IT audits, maintaining certification programs across ISO 27001, ISO 42001 standards and SOC compliance.
Develop, implement, and maintain data governance and privacy frameworks (e.g., GDPR) across existing and expanding global operating regions.
Conduct continuous threat hunting using updated threat intelligence to proactively strengthen controls and prevent security violations.
Partner with engineering and operational squads to enforce security standards, evaluate risks in new initiatives, and conduct staff cybersecurity training.
2+ years of hands-on experience in information security, IT compliance, or risk management within modern technology or cloud environments.
Practical expertise with core compliance frameworks and standards, specifically ISO 27001, SOC reporting, and ISO 42001 (Artificial Intelligence Management Systems).
Solid technical understanding of software development lifecycles, IT infrastructure, network architectures, vulnerability scanning, and structured incident response.
Deep knowledge of global data privacy regulations (e.g., GDPR) and data governance frameworks.
Industry security or compliance certifications (e.g., CISSP, CCEP, ISO Lead Implementer/Auditor, or equivalent professional credentials) are strongly preferred.
Excellent analytical, problem-solving, and communication skills to effectively translate technical risks to cross-functional stakeholders.

nahc.io is a full service recruitment firm providing talent acquisition and human capital solutions for startups and innovative companies in Asia.
We work with employers to address recruitment challenges and reach their business goals by attracting and hiring the best available talent, and help candidates unleash their full career potential by matching them with jobs that are best suited to their unique skills, experience and aspirations.
At nahc.io, we prioritize building and maintaining long-term relationships with our clients and candidates and emphasize a people-first approach as a business. We believe that the recruiting process should be transparent and designed to create a comfortable experience for all parties involved.
Services:
1. Talent Acquisition
Core specialties:
- Sales
- Marketing
- Information Technology
- Human Resources
- Strategy & Operations
- Finance
- Web3
2. Bespoke Human Capital Solutions
- Remote worker hiring and remote office set up
- Employer branding
- Setting up HR systems and processes
- Startup hiring and scaling advisory
*Whether you are hiring, exploring the market, or interested to partner with us, tell us your needs. Let us help you achieve the results you're looking for.
Follow our page and stay up-to-date with latest market movements and trends.