Compliance & Security Assurance Specialist
- Hiring from
- Philippines
- Work type
- Remote
- Posted
- Oct 2, 2026
Type: Full-Time
Reports to: CEO (AML/CTF Compliance Officer)
Works Closely With: Technology, Customer Success, Product, Fractional CFO, external auditors and assessors
Location: Remote
⭐ Role Overview
Glider is an Australian payments platform. We help enterprise billers collect faster using PayTo, real-time bank payments and smart payment journeys. Our customers include major billers, banks and federal government agencies, and they all expect strong security and compliance from us.
Glider is SOC 2 Type 2 certified and has a control environment aligned to ISO 27001. We're pursuing IRAP assessment to support our federal government customers. We run our compliance program on Drata.
Glider is building an AI-native platform, and our compliance function works the same way. In this role you'll use AI tools every day to work faster, keep our compliance current and scale assurance as we grow.
You'll own Glider's security assurance program end to end: Drata, our policy suite, our certifications and our audits. You'll also run our AML/CTF compliance day to day, working with the CEO, who is Glider's appointed AML/CTF Compliance Officer.
This is a remote role based in the Philippines, working closely with our team in Sydney.
⭐ Key Responsibilities1. Certifications & Audits
SOC 2 Type 2 recertification
- Run Glider's SOC 2 controls throughout each observation period, keeping evidence continuous and complete.
- Monitor how controls are performing and make sure any exceptions are fixed promptly.
- Lead the annual SOC 2 Type 2 audit with our independent auditor, covering scoping, evidence, walkthroughs and the final report.
ISO 27001 certification
- Lead Glider's ISO 27001 certification, building on our existing control environment.
- Keep the ISMS scope, Statement of Applicability and risk treatment plan current.
- Run the internal audit and management review, and address any findings.
- Work with our certification body through the Stage 1 and Stage 2 audits, then the annual surveillance audits.
IRAP for federal government customers
- Lead Glider's IRAP program against the ASD Information Security Manual (ISM) and Essential Eight.
- Map Glider's controls to the ISM, check how well we meet it, and work with the Technology team on any improvements needed.
- Prepare the System Security Plan and supporting documentation.
- Work with our ASD-endorsed IRAP assessor through to a completed assessment.
Across all frameworks
- Maintain one control set mapped across SOC 2, ISO 27001 and the ISM, so evidence is collected once and reused.
- Keep Glider ready for audit at all times, with a planned calendar for audits and control testing.
2. Drata Ownership
- Own Glider's Drata instance as system administrator.
- Manage the integrations (AWS, identity, code repositories, HR, devices) so automated evidence stays complete and accurate.
- Monitor control health and coordinate fixes with control owners.
- Manage personnel compliance in Drata: onboarding and offboarding, security training, policy acceptance, background checks and device compliance.
- Set up frameworks and control mappings, including ISM controls.
- Run vendor risk management through Drata, including for AI and cloud providers.
- Maintain Glider's trust centre and our library of answers for security questionnaires.
- Keep finding ways to automate more of our compliance work.
3. Policy Ownership
- Own Glider's information security and compliance policies. These cover information security, access control, acceptable use, incident response, business continuity and disaster recovery, change management, data classification and retention, privacy, vendor management and risk management.
- Write, update and version-control policies, and run the annual review and approval cycle.
- Make sure policies match how Glider actually works, and that all staff have read and accepted them.
- Maintain Glider's AML/CTF policies and procedures. Changes are approved by the Compliance Officer.
4. Risk, Access & Data Assurance
- Maintain the information security risk register and risk treatment plan.
- Run quarterly user access reviews, and keep change management evidence up to date with the Technology team.
- Maintain privacy and data-handling controls in line with the Australian Privacy Principles.
- Support incident response, including logging, post-incident reviews and corrective actions.
- Support PCI DSS alignment where customers require it.
5. AML/CTF Compliance Operations
- Keep Glider's ML/TF risk assessment current. The Compliance Officer signs it off.
- Run KYC/KYB and customer due diligence when we onboard merchants, and escalate higher-risk cases for enhanced due diligence.
- Run sanctions and PEP screening and keep records of the results.
- Review transaction monitoring alerts and keep clear case records.
- Draft suspicious matter reports and annual compliance reports for the Compliance Officer to review and lodge.
- Run AML/CTF and security awareness training.
6. Customer & Partner Assurance
- Respond to security questionnaires, risk assessments and due-diligence requests from enterprise customers, banks, government and partners.
- Prepare security and compliance material for enterprise sales and partner reviews.
7. AI-Enabled Compliance
- Use AI tools to speed up compliance work, including:
- drafting and updating policies
- mapping controls across frameworks
- preparing audit evidence narratives
- completing security questionnaires
- Build repeatable AI-assisted workflows and prompts for recurring compliance tasks, and document them so others can use them.
- Use AI to analyse regulatory changes and summarise what they mean for Glider's policies and controls.
- Make sure AI is used safely in compliance work: only approved tools, appropriate data handling, and a person reviews anything before it goes to auditors, regulators or customers.
- Support governance of the AI features in our platform. This includes vendor risk assessments for AI providers and mapping AI-related controls into SOC 2 and ISO 27001.
⭐ Governance & Accountability
Glider's CEO is the appointed AML/CTF Compliance Officer and remains accountable for:
- Engagement with AUSTRAC.
- Final decisions on suspicious matter reports and enhanced due diligence.
- Approval of AML/CTF policies and risk assessments.
⭐ Success Measures (First 12–18 Months)
- SOC 2 Type 2 recertified.
- ISO 27001 certification achieved.
- IRAP assessment completed for federal government customers.
- Controls monitored continuously in Drata, with evidence current and complete.
- All policies current and approved, and accepted by every staff member.
- Merchant onboarding checks and monitoring reviews completed on time and fully documented.
- Security questionnaires answered quickly and consistently.
- AI-assisted workflows in place for policy management, control mapping and questionnaire responses, with measurably faster turnaround.
- Compliance processes efficient, automated and part of how every team works.
⭐ Ideal Background & Experience
Required
- 4–6+ years in GRC, security compliance or compliance operations at a SaaS, payments, fintech or other regulated business.
- Hands-on experience leading a company through SOC 2 Type 2 and ISO 27001 audits.
- Experience administering Drata, Vanta or a similar compliance automation platform.
- Experience writing and maintaining a set of information security policies.
- Working knowledge of KYC/KYB, customer due diligence and AML controls, ideally under the Philippine AMLA/AMLC or BSP regime or another FATF-aligned framework.
- Confident everyday use of AI tools such as Claude or ChatGPT to speed up research, writing and analysis.
- Strong written English for policies, audit responses and questionnaires.
Preferred
- Drata specifically.
- Exposure to the ASD ISM, Essential Eight or IRAP assessments.
- ISO 27001 Lead Implementer or Lead Auditor certification, or similar (e.g. CISA, CISM).
- Experience building AI-assisted workflows or automations, such as prompt libraries, Drata's AI features, Zapier or Make.
- Familiarity with AI governance frameworks such as ISO/IEC 42001 or the NIST AI RMF.
- Knowledge of Australian AML/CTF requirements and AUSTRAC. We'll support you to learn them.
- Familiarity with the Philippine Data Privacy Act and the Australian Privacy Principles.
- Experience working remotely with Australian, US or UK companies.
- Familiarity with AWS environments.
- Exposure to PCI DSS.
⭐ Attributes
- Structured, detail-oriented and reliable.
- Takes ownership of outcomes and follows through.
- AI-native: turns to AI first to work smarter, and checks its output carefully.
- Comfortable working independently and remotely, mostly in writing.
- Raises issues early.
- Practical: turns frameworks into simple, repeatable workflows.