About the job Head of Security, Trust & Compliance
Confidential Hiring: Head of Security, Trust & Compliance
About the Company
Our client is a rapidly growing, venture-backed B2B SaaS company headquartered in Bangkok, Thailand, serving thousands of businesses across more than 100 countries. They develop AI-powered software solutions that help organizations streamline critical business processes and are recognized as one of the leading technology companies in the region.
With a highly international team and a strong engineering culture, the company values innovation, ownership, and collaboration. As they continue expanding globally, they are looking for an experienced security leader to strengthen their trust, security, and compliance capabilities.
About the Role
Reporting directly to the Chief Technology Officer (CTO), the Head of Security, Trust & Compliance will lead the organization's security, trust, and compliance initiatives. This strategic leadership role oversees Trust & Safety operations, security compliance, IT management, and enterprise security support throughout the customer lifecycle.
Managing a team of three, you will serve as the primary bridge between security operations and engineering, driving automation projects, strengthening security processes, and ensuring the organization maintains a strong security posture while supporting business growth.
Responsibilities
Trust & Safety
Own the end-to-end account verification workflow (KYB) after subscription, ensuring legitimate use of the platform.
Define and continuously improve fraud detection processes: fraudulent job postings and general abuse and misuse.
Act as the project manager for fraud detection automation: define requirements, timelines, and deliverables in collaboration with the Engineering team.
Establish and maintain Trust & Safety policies, escalation paths, and response playbooks.
Security & Compliance
Own and drive SOC 2 Type 2 compliance, including audit preparation, evidence collection, control monitoring, and remediation tracking.
Orchestrate the penetration testing program end-to-end: vendor selection, scoping, tooling setup, intake of findings into Jira, report negotiation, and remediation coordination with engineering teams.
Orchestrate the bug bounty program: vendor management, triage workflow, severity assessment coordination, and remediation tracking.
Own security incident response for non-product incidents (reported data breaches, unauthorized access, credential compromise). Product availability incidents remain with the Engineering Team.
Proactively identify security risks across the organization and implement mitigation strategies that balance security with operational velocity.
Sales Enablement
Directly answer complex or non-standard questions that require deep knowledge of Manatal's security posture.
Lead the technical response for security questionnaires, RFIs and RFPs, acting as the subject matter expert to support enterprise sales cycles.
IT Management
Manage the IT function (helpdesk, device management, access control, internal tooling).
Define and oversee the lifecycle management of all company IT assets, ensuring hardware and software inventory is secure, tracked, and compliant.
Ensure IT-related policies and operations align with SOC 2 and broader security requirements.
Culture & Cross-Functional Collaboration
Partner with Engineering to scope and prioritize security and trust-related automation projects.
Provide security input during product and architecture reviews when trust or compliance implications exist.
Foster a culture of security awareness across all departments through training and clear policy definitions.
Report on trust, security, and compliance posture to the CTO on a regular cadence.
Qualifications
6+ years of experience in information security, trust & safety, or GRC, with at least 2 years in a leadership role within a technology company
Hands-on experience owning a SOC 2 Type 2 program (audit preparation, evidence collection, remediation tracking)
Experience managing external security vendors (penetration testing firms, auditors, or bug bounty platforms)
Ability to define security and trust workflows and translate them into actionable projects for engineering teams
Strong understanding of cloud infrastructure security and web application security
People management experience
Excellent English communication skills, written and verbal. You will negotiate with vendors, write policies, and interface with clients
Technical fluency: you can read a vulnerability report, understand API-level risks, and write requirements that engineers can act on
Nice to Have
Experience with KYB/KYC processes
Familiarity with privacy regulations (GDPR, PDPA, CCPA)
Professional certifications (CISM, CISSP, CISA)
Familiarity with compliance automation tools (Vanta, Drata, or similar)
Background in recruitment technology or HR tech
Language Proficiency
Fluent in English
Benefits
Social Security
Comprehensive health insurance + Telemedicine service
15 days of paid annual leaves (Pro-rated)
~13 days of national holiday
2 weeks/year to work from anywhere (After probation)
Monthly new hire & birthday lunches
Personal development allowance
Working Conditions
Full-time position based in Bangkok, Thailand.
On-site working environment with flexibility to collaborate across global time zones.
Standard office hours with occasional flexibility depending on business needs.
Opportunity to work alongside an international, high-performing technology team.
Learn More About the Company
Please send your resume or enquiries to billie@startupbreed.com or connect with us on LinkedIn.