Reap is a leading global payment technology provider that enables financial connectivity and access for businesses worldwide. By merging traditional finance with digital assets, bridging disparate economies, and connecting key financial players, we are transforming the financial landscape into a more interconnected and interoperable space for efficient money movement.
With stablecoin‑enabled corporate cards, payout solutions, and expense management tools, we streamline financial operations and empower businesses to scale. Our APIs enable businesses to embed finance into their own products and services, from issuing Visa cards to facilitating cross‑border payments.
Reap is supported by a strong network of investors, including Acorn Pacific Ventures, Arcadia Funds, HashKey Capital, Hustle Fund, Fresco Capital, Abacus Ventures, and Payment Asia.
Founded in 2018
Reap builds financial connectivity for a multi‑rail world-traditional finance, stablecoins, and real‑time payments. Security is foundational to that mission. We're looking for a pragmatic engineer who can turn regulation into robust systems, and complex threats into clear controls. You'll partner with Engineering, Risk, and Operations to keep value moving safely, globally, and 24/7.
Reap operates under DORA, ISO 27001, PCI DSS, SOC 2, GDPR, PDPA, and PDPO across five jurisdictions.
Our EU regulatory programme has 10 DORA workstreams running through October 2026. SOC 2 Type II is stalled. And the CISO is currently the sole owner of all of it while simultaneously managing three live security incidents and M&A due diligence.
You will take the compliance machinery off the CISO and own it properly. That means running the DORA programme, coordinating the ISO 27001 and SOC 2 audit cycles, managing QSA engagement for PCI DSS, monitoring APAC regulatory developments, and keeping our policy library current. This is an operational role, not an advisory one.
• Own the DORA compliance programme: Register of Information maintenance, ICT risk register, third-partyICT risk assessments, testing programme scheduling, and the assurance phase that has not yet started.
• Manage ISO 27001 control ownership and internal audit coordination: evidence collection, remediation
tracking, and preparing for future recertification.
• Coordinate PCI DSS QSA engagement: manage evidence requests, track the audit cycle, and own the
relationship with the QSA.
• Drive SOC 2 Type II preparation: take over evidence collection from the CISO, coordinate with the auditor, and get this across the line.
• Monitor and report on regulatory developments across PDPA (Singapore), PDPO (Hong Kong), HKMA, SFC, MAS TRM, and EU DORA guidance.
• Keep our security policy library (42-050 series) current: own the annual review cycle and manage version control.
• Draft regulatory submissions and correspondence for CISO review.
• Run our third-party risk assessment process: vendor questionnaires, contract clause review, and ongoing monitoring.
• You have done GRC operationally, not just advised on it. You have run audit cycles, collected evidence
packs, and sat across from a QSA or internal auditor.
• ISO 27001 and/or SOC 2 hands-on experience. You have managed controls, tracked remediation, and
produced evidence that stands up to audit.
• Financial services regulatory background. Familiarity with at least one of CBI, MAS, or HKMA. You know how to write a submission that a regulator will accept.
• You are comfortable with DORA or can get comfortable fast. If you have not done DORA specifically,
you have done equivalent EU financial services regulation and you are a fast learner.
• GDPR Art. 30 ROPA and privacy framework knowledge. PDPA and PDPO familiarity is a genuine plus
given our APAC footprint.
• Policy drafting. You write clearly and in a register that works for regulators, auditors, and internal
stakeholders.
• CISM, CRISC, ISO 27001 Lead Implementer, or CISA certification.
• GRC tooling experience: Vanta, Drata, ServiceNow GRC, or Archer.
• PCI DSS QSA engagement experience.
• Crypto or MiCA regulatory background.
• You will own the compliance function for a regulated fintech operating across HK, SG, EU, MX, and the US, with a genuinely varied and interesting regulatory landscape.
• You will have direct access to the CISO and meaningful involvement in an M&A process with
Payward/Kraken.
• The role has clear scope and a real backlog to clear, so you will have impact from week one.
• APAC-friendly, remote-first, and we actively invest in AI tools for the team.
A vibrant, inclusive work culture.
Annual leave to relax and recharge, plus public holidays.
Health insurance budget.
Be part of a fast‑growing global team.
Flexible remote work options.
Home office equipment budget.
Your own Corporate Reap Card-no more out‑of‑pocket spending.
Reap is a leading global payment technology provider that enables financial connectivity and access for businesses worldwide. By merging traditional finance with digital assets, bridging disparate economies, and connecting key financial players, we are transforming the financial landscape into a more interconnected and interoperable space for efficient money movement.
With stablecoin‑enabled corporate cards, payout solutions, and expense management tools, we streamline financial operations and empower businesses to scale. Our APIs enable businesses to embed finance into their own products and services, from issuing Visa cards to facilitating cross‑border payments.
Reap is supported by a strong network of investors, including Acorn Pacific Ventures, Arcadia Funds, HashKey Capital, Hustle Fund, Fresco Capital, Abacus Ventures, and Payment Asia.
Founded in 2018 Coworkers 300+

Reap is a leading global payment technology provider that enables financial connectivity and access for businesses worldwide. By merging traditional finance with digital assets, bridging disparate economies, and connecting key financial players, we are transforming the financial landscape into a more interconnected and interoperable space for efficient money movement.
With stablecoin-enabled corporate cards, payout solutions, and expense management tools, we streamline financial operations and empower businesses to scale. Our APIs enable businesses to embed finance into their own products and services, from issuing Visa cards to facilitating cross-border payments.
Reap is supported by a strong network of investors, including Acorn Pacific Ventures, Arcadia Funds, HashKey Capital, Hustle Fund, Fresco Capital, Abacus Ventures, and Payment Asia. Founded in 2018 in Hong Kong, we have since expanded to a team of over 100 across the globe.