GL

Security and Compliance Engineer

GliderApplies on LinkedInLegal & Compliance
Hiring from
Philippines
Work type
Remote
Posted
Is this job info correct?

537,316 remote jobs, straight from company career pages

100% free · New jobs every hour

Show job description

Type: Full-Time

Reports to: CEO (AML/CTF Compliance Officer)

Works Closely With: Technology, Customer Success, Product, Fractional CFO, external auditors and assessors

Location: Remote (Philippines)


⭐ Role Overview


Glider is an Australian payments platform. We help enterprise billers collect faster using PayTo, real-time bank payments and smart payment journeys. Our customers include major billers, banks and federal government agencies, and they all expect strong security and compliance from us.


Glider is SOC 2 Type 2 certified, aligned to ISO 27001 and pursuing IRAP. We run our compliance program on Drata.


This is a hands-on role. When a control fails, a scan flags a vulnerability or an audit raises a finding, you fix it, whether that's tightening IAM in AWS, enforcing MFA, hardening configuration or scripting the evidence. You'll work with Technology on larger platform changes, but you won't just log issues and wait.


You'll own Glider's security assurance program end to end and run AML/CTF compliance day to day with the CEO, Glider's appointed AML/CTF Compliance Officer. Like the rest of Glider, this function is AI-native: you'll use AI tools every day to work faster and scale assurance.


⭐ Key Responsibilities


1. Certifications & Audits

- SOC 2 Type 2: run controls through each observation period, fix exceptions, and lead the annual audit.

- ISO 27001: lead certification, maintain the ISMS scope, Statement of Applicability and risk treatment plan, run internal audit and management review, and see us through Stage 1, Stage 2 and surveillance audits.

- IRAP: map controls to the ASD ISM and Essential Eight, implement the technical changes needed to close gaps, prepare the System Security Plan and work with our IRAP assessor to completion.

- Maintain one control set mapped across SOC 2, ISO 27001 and the ISM, and keep Glider audit-ready at all times.


2. Hands-On Security Engineering & Remediation

- AWS: find and fix misconfigurations in IAM, logging, encryption, security groups, S3 and backups, using Security Hub, GuardDuty and Config.

- Identity: administer and harden our identity provider, including SSO, MFA, role-based access and deprovisioning.

- Endpoints: manage device compliance through MDM (encryption, patching, EDR).

- Code and CI/CD: maintain branch protection, required reviews, secrets scanning and dependency scanning.

- Vulnerabilities: triage scanner and pen test findings, fix what's in scope, and drive platform fixes with Technology to closure.

- Essential Eight: implement and evidence maturity improvements.

- Automation: write scripts (Python, Bash) and infrastructure-as-code to remediate issues, enforce configuration and collect evidence.

- All production changes go through change management with Technology approval.


3. Drata

- Own Drata as system administrator.

- Configure and fix integrations (AWS, identity, code, HR, devices), and build custom tests where standard coverage falls short.

- Resolve failing tests directly where possible.

- Manage personnel compliance, vendor risk (including AI providers), framework mappings, our trust centre and our questionnaire answer library.


4. Policies, Risk & Access

- Own the information security policy suite and the annual review cycle.

- Make sure policies match how systems are actually configured, and fix whichever is wrong.

- Maintain AML/CTF policies (approved by the Compliance Officer).

- Maintain the risk register and deliver assigned technical treatments.

- Run quarterly access reviews and remove excess access.

- Maintain privacy controls under the Australian Privacy Principles.

- Support incident response hands-on: log investigation, containment, post-incident review.

- Support PCI DSS where customers require it.


5. AML/CTF Operations

- Keep the ML/TF risk assessment current, for Compliance Officer sign-off.

- Run KYC/KYB and due diligence on merchant onboarding, escalating higher-risk cases.

- Run sanctions and PEP screening.

- Review transaction monitoring alerts.

- Draft suspicious matter and annual compliance reports.

- Run AML/CTF and security awareness training.


6. Customer & Partner Assurance

- Answer security questionnaires and due-diligence requests from customers, banks, government and partners, including technical architecture questions.

- Prepare security material for sales and partner reviews.


7. AI-Enabled Compliance

- Use AI to draft policies, map controls, write remediation scripts, prepare evidence narratives and complete questionnaires.

- Build and document repeatable AI-assisted workflows.

- Ensure safe AI use: approved tools, appropriate data handling, and human review before anything reaches auditors, regulators, customers or production.

- Support governance of AI features in our platform.


⭐ Governance & Accountability


The CEO, as AML/CTF Compliance Officer, remains accountable for AUSTRAC engagement, final decisions on suspicious matter reports and enhanced due diligence, and approval of AML/CTF policies and risk assessments. Production changes require Technology approval.


⭐ Success Measures (First 12–18 Months)

- SOC 2 Type 2 recertified with no unresolved exceptions.

- ISO 27001 certified.

- IRAP assessment completed.

- Drata control health consistently green.

- Vulnerabilities and findings fixed within agreed SLAs.

- Measurable Essential Eight maturity improvement.

- Policies current, accepted by all staff and matching actual configuration.

- Merchant checks and monitoring reviews on time and documented.

- AI-assisted and scripted workflows delivering measurably faster turnaround.


⭐ Ideal Background & Experience


Required

- 4–6+ years in security engineering, GRC or security compliance at a SaaS, payments, fintech or regulated business, with a record of fixing issues, not just reporting them.

- Hands-on AWS security (IAM, logging, encryption, networking, Security Hub, GuardDuty).

- Experience administering an identity provider (e.g. Google Workspace, Okta, Entra ID) and MDM (e.g. Jamf, Kandji, Intune).

- Scripting in Python, Bash or PowerShell.

- Led a company through SOC 2 Type 2 and ISO 27001 audits.

- Administered Drata, Vanta or similar, including troubleshooting integrations.

- Written and maintained information security policies.

- Working knowledge of KYC/KYB and AML controls, ideally under the Philippine AMLA/AMLC or BSP regime or another FATF-aligned framework.

- Confident daily use of AI tools such as Claude or ChatGPT, including for code.

- Strong written English.


Preferred

- Drata, including custom tests.

- Terraform or CloudFormation.

- Secure SDLC tooling (GitHub Advanced Security, Snyk, Dependabot).

- ASD ISM, Essential Eight or IRAP exposure.

- AWS Security Specialty, ISO 27001 Lead Implementer/Auditor, CISA or CISM.

- AI governance frameworks (ISO/IEC 42001, NIST AI RMF).

- Australian AML/CTF and AUSTRAC knowledge (we'll help you learn).

- Philippine Data Privacy Act and Australian Privacy Principles.

- Remote work with Australian, US or UK companies.

- PCI DSS exposure.


⭐ Attributes

- Fixer mindset: sees a gap and closes it.

- Comfortable in cloud consoles, config files and scripts.

- Structured, detail-oriented and reliable.

- Owns outcomes and follows through.

- AI-native, and checks AI output carefully.

- Works independently and remotely, mostly in writing.

- Raises issues early.

- Turns frameworks into simple, automated workflows.

Similar jobs

Apply on LinkedIn