DevSecOps Engineer (GRC)

 Posted 14 hours ago
     
2-5 years experience
Apply Now

Please mention DailyRemote when applying

AI Summary

Own the end-to-end governance layer, including continuous compliance automation, external audit pipelines, and SaaS vendor risk management. Act as the primary control owner for security certifications and translate compliance requirements into actionable engineering tasks.

Location: Kuala Lumpur, Malaysia

Role: DevSecOps Engineer (GRC)

Department: Backend

About Respond.io

Founded in Hong Kong in early 2017, respond.io is an AI-powered business messaging platform that helps companies manage customer conversations across chat, calls and email — all in one place.

Trusted by businesses in over 127 countries and recognized by G2 and SME100, respond.io enables fast-growing companies around the world to capture, convert, and retain customers at scale.

We operate as a globally distributed team with employees based around the world, contributing to a diverse and inclusive culture. Join us, and be part of a team that is shaping the future of customer conversation management!

Our Culture

At respond.io, we move fast, work smart, and always keep our customers at the heart of what we do. Here’s what we stand for:

  • Solve Customer Problems: Every effort must solve real customer pain points. No guesswork—just real feedback and clear value!
  • The 80/20 Rule: We focus on 20% of actions that create 80% of the value. Simple is powerful—it gets us moving fast.
  • 100% Alignment, 80% Accuracy: We aim 100% team alignment and 80% accuracy. Perfect plans can wait—clear goals come first.
  • Be Direct: We give honest feedback, and tackle problems head-on. Clarity moves us forward!
  • Own It and Support Each Other: We step up, help out, and drive outcomes—together.
  • Build Human Connections: Work is better when we trust, care, and celebrate wins together. We’re a team!

Role Description

At respond.io, compliance is an engineering discipline, not a paperwork exercise. We are hiring a DevSecOps Engineer (GRC) to own our governance layer end to end: our continuous compliance platform, our external audit pipeline (ISO 27001, GDPR), SaaS vendor risk, and enterprise customer trust. You will be the control owner and the primary audit subject for our security certifications, and the translator who turns abstract framework controls into requirements our engineers can implement without confusion.

What You Will Be Doing

Continuous Compliance Architecture

  • Own, scale, and optimize our compliance automation platform.
  • Orchestrate automated evidence collection, control validation, and policy-to-framework mapping so evidence holds up in audit without manual scrambles.
  • Continuously verify endpoint fleet compliance scores and drive them up over time.
  • Apply AI-driven tooling to automate compliance checks, control monitoring, evidence collection, and policy drafting.

Signal Routing & Operations

  • Monitor continuous compliance drift alerts; isolate and eliminate false positives so engineers only ever see real work.
  • Write tight, well-scoped remediation issues and route them into engineering backlogs via Linear, sized so a developer can pull one into a single cycle without clarification.
  • Track remediation milestones, identify blockers, and escalate early and clearly.

Governance & Enterprise Trust

  • Command our external audit pipeline: drive ISO 27001 and GDPR audits end to end (scoping, auditor management, evidence delivery, findings remediation, retest) and own our multi-month SOC 2 Type 2 readiness window.
  • Act as the control owner and main audit subject for our technology controls.
  • Serve as the technical expert behind enterprise customer security questionnaires and due-diligence reviews.
  • Run continuous security gap assessments against current and upcoming EU/US mandates to keep us ahead of regulation, not behind it.

SaaS Vendor Risk Management

  • Gatekeep our third-party stack: run formal SaaS security vetting, perform Data Privacy Impact assessments on incoming vendors, and maintain the vendor risk register.
  • Author and maintain corporate governance and security policy definitions, and keep policies synchronized with enforced configuration (the policy-to-configuration handshake).

Security Incident Response

  • Act as the regulatory and communication anchor during incidents: breach disclosure tracking (e.g., GDPR 72-hour constraints), post-mortem logging, and external compliance reporting, in partnership with the technical responder.

Qualifications

  • 3-5+ years in GRC or security compliance roles, with a proven track record implementing and maintaining ISO 27001 and GDPR, and managing operational audit timelines for SOC 2 Type 2.
  • Compliance automation native: strong hands-on experience with API-driven platforms like Sprinto, Drata, or Vanta. You prefer live continuous evidence pipelines over manual screenshots, and you've administered one at scale (ideally including a platform migration).
  • Technical fluency: you don't need to write production code, but you must understand how modern microservice environments, AWS IAM, GitHub Actions, CI/CD, and identity layers (SSO/MFA) actually work, so your controls stay pragmatic and enforceable.
  • Audit management: experience running external auditors end to end, covering scoping, evidence, findings triage, remediation tracking, and cross-functional stakeholder engagement.
  • Masterful agile translator: the rare ability to read an abstract compliance control or rigorous enterprise requirement and turn it into a clear, actionable, well-scoped engineering issue.
  • Clear written and spoken English: able to hold your own with auditors, enterprise customers' security teams, and backend engineers alike.
  • Certifications such as ISO 27001 Lead Auditor/Implementer, CISA, CRISC, or CISSP.

What's in it for you

  • You will become part of an amazing culture with smart, collaborative teammates who actually care about each other's growth and success.
  • You will grow more here than you would anywhere else, that is a promise.
  • Virtual events like talent shows, Among Us nights, and online game sessions to keep the fun going, no matter where you are!
  • We offer a highly competitive compensation package.
  • You'll receive a mental health allowance to support your health and wellness needs.
  • Flexible working environment and working hours that fit your lifestyle, wherever you're based.

Similar Jobs

See all Remote Software Development jobs →

Personalize your Remote Job Search in 3 Easy Steps!

Discover remote opportunities in Software Development

Answer easy questions

Answer easy questions

200,000+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified