Governance and Security Engineer

16 hours ago


WorkFromHome, Hong Kong SAR China Reap Full time

Governance & Security Lead Security · APAC (Hong Kong or Singapore) · Hybrid / Remote Reinvent finance with Reap. We're building resilient, compliant, and secure infrastructure for global money movement. As our Governance & Security Lead, you'll bridge ICT governance and hands‑on security operations – standing up controls and practices aligned to DORA while keeping our systems hardened day to day. You'll help define the playbook, tune the tools, and raise the bar on operational resilience across the company. At Reap, security is how we earn trust. We merge traditional finance with digital assets, so our standards must be clear, auditable, and resilient by design. You will help operationalize DORA, ISO 27001, and our ICT risk framework – from policy and control design to real‑time operations – so teams can ship quickly without compromising safety. What You’ll Do Implement and mature our ICT Risk Management Framework aligned with DORA, ISO 27001, and NIST CSF. Maintain policies, standards, and procedures; ensure consistent adoption across cloud, on‑prem, and vendors. Contribute to control testing plans, RCSA updates, and risk registers; support control attestation and board‑level reporting. Support vendor risk management and outsourcing oversight in line with DORA Article 30. Coordinate periodic self‑assessments and independent audits (internal, external, and regulator‑driven). Operate and tune EDR platforms such as SentinelOne or CrowdStrike. Drive configuration baselines, patch compliance, and vulnerability remediation tracking. Support detection, triage, escalation, and post‑incident reviews in line with DORA Article 17. Maintain logs, alerts, and metrics across SIEM, MDM, and security tooling; contribute to playbooks and runbooks. Participate in penetration testing and prioritize remediation with engineering teams. Manage SSO and the user lifecycle across cloud platforms and SaaS tools. Enforce MFA, least privilege, and periodic access reviews. Support encryption controls, secure configurations, and data protection measures. Maintain MDM/DR processes that support ICT service continuity per DORA Article 28. Run resilience testing, scenario simulations, and disaster recovery exercises. Define and document RTOs and RPOs; maintain asset inventories and dependency maps to critical business functions. Deliver security awareness sessions and contribute to company‑wide communications. Track and report metrics on incidents, vulnerabilities, access reviews, and training effectiveness. Feed lessons learned into control improvements and operating procedures. About You Governance and compliance Experience building or maintaining information security management systems. Strong understanding of regulatory expectations under DORA, GDPR, and MiCAR. Skilled in policy drafting, governance documentation, and control monitoring. Technical and operational security Proficient with modern EDR platforms (SentinelOne, CrowdStrike). Hands‑on with network security, vulnerability management, and secure configurations. Familiar with AWS and cloud hardening practices. Working knowledge of SIEM operations, MDM/DR, patch management, and integrating security tooling. How you work Excellent communicator who partners across IT, Engineering, Risk, and Compliance. Comfortable operating in a fast‑paced, cross‑functional environment. Strong analytical and documentation skills that support audit readiness. Requirements 4+ years in Information Security or ICT Governance. Strong technical knowledge of endpoint protection, access management, and network controls. Experience supporting ISO 27001, SOC 2, or equivalent frameworks. Familiarity with DORA Articles 5‑8 and 28‑30 or comparable regulatory frameworks. Ability to draft and maintain policies, standards, registers, and control evidence. Practical experience operating EDR, MDM, SSO, and vulnerability management tools. Preferred Experience in fintech, crypto, or regulated financial services. Knowledge of AWS or other cloud environments. Recognized certifications such as CompTIA Security+, ISO 27001 Lead Implementer, or Google Cybersecurity. Experience preparing materials for board or regulator reporting. What this role offers A chance to build a DORA‑aligned ICT governance and security capability from the ground up. Exposure to both regulatory frameworks and advanced technical controls. Growth pathways toward Governance Manager or Security Architect. Direct collaboration with the CISO, CIO, and Compliance on enterprise resilience. About Reap Reap is a leading global payment technology provider that enables financial connectivity and access for businesses worldwide. By merging traditional finance with digital assets, bridging disparate economies, and connecting key financial players, we are transforming the financial landscape into a more interconnected and interoperable space for efficient money movement. With stablecoin‑enabled corporate cards, payout solutions, and expense management tools, we streamline financial operations and empower businesses to scale. Our APIs enable businesses to embed finance into their own products and services, from issuing Visa cards to facilitating cross‑border payments. Reap is supported by a strong network of investors, including Acorn Pacific Ventures, Arcadia Funds, HashKey Capital, Hustle Fund, Fresco Capital, Abacus Ventures, and Payment Asia. Founded in 2018. Coworkers 300+ Referrals increase your chances of interviewing at Reap by 2x. Get notified about new Security Lead jobs in Quarry Bay, Hong Kong SAR. #J-18808-Ljbffr



  • WorkFromHome, Hong Kong SAR China Reap Full time

    Security · APAC (Hong Kong or Singapore) · Hybrid / Remote Governance & Security Engineer Reinvent finance with Reap. We're building resilient, compliant, and secure infrastructure for global money movement. As our Governance & Security Engineer, you'll bridge ICT governance and hands‑on security operations-standing up controls and practices aligned to...

  • FinTech Governance

    16 hours ago


    WorkFromHome, Hong Kong SAR China Reap Full time

    A global payment technology provider is seeking a Governance & Security Engineer to implement ICT Risk Management frameworks and enhance security operations. This role requires a strong background in information security and ICT governance, particularly with DORA, ISO 27001, and relevant policies. The position is hybrid/remote, offering exposure to...


  • WorkFromHome, Hong Kong SAR China Reap Full time

    Security · APAC (Hong Kong or Singapore) · Hybrid / Remote Governance & Security Lead Reinvent finance with Reap. We're building resilient, compliant, and secure infrastructure for global money movement. As our Governance & Security Lead, you'll bridge ICT governance and hands‑on security operations-standing up controls and practices aligned to DORA...


  • WorkFromHome, Hong Kong SAR China Reap Full time

    A leading global payment technology provider in Hong Kong is looking for a Governance & Security Lead to build resilient and compliant infrastructure for financial operations. The role involves bridging ICT governance with hands-on security operations and implementing necessary frameworks like DORA and ISO 27001. Candidates need solid experience in...


  • WorkFromHome, Hong Kong SAR China Reap Full time

    Security · APAC · Hybrid / Remote Crypto Asset Custody & Security Engineer (DORA‑Aligned) Help reinvent global finance with secure, resilient digital asset infrastructure. At Reap, you'll be the security backbone behind our custody operations—shaping how private keys are protected, how wallets operate at scale, and how our ICT controls meet DORA with...


  • WorkFromHome, Hong Kong SAR China Reap Full time

    Crypto Asset Custody and Security Engineer Join to apply for the Crypto Asset Custody and Security Engineer role at Reap . Security – Locations: APAC, Hybrid / Remote. What you’ll do Custody security engineering Operate and harden custody environments across hot, warm, and cold storage. Own key lifecycle controls: secure creation, rotation, backup,...

  • Crypto Asset Custody

    16 hours ago


    WorkFromHome, Hong Kong SAR China Reap Full time

    A leading payment technology provider is seeking a Crypto Asset Custody and Security Engineer to enhance security around digital assets. Responsibilities include operating custody environments, enforcing access controls, and ensuring compliance with ICT governance. The ideal candidate has hands-on experience in crypto custody and a solid understanding of...


  • WorkFromHome, Hong Kong SAR China Canonical Full time

    Join to apply for the Senior Security Operations Engineer role at Canonical 3 months ago Be among the first 25 applicants Join to apply for the Senior Security Operations Engineer role at Canonical Get AI-powered advice on this job and more exclusive features. We have opened several senior/staff Security Operations Engineer (SOC) positions, creating a new...


  • WorkFromHome, Hong Kong SAR China Reap Full time

    A leading global payment technology provider in Hong Kong is searching for a Governance & Security Lead to oversee ICT governance and hands-on security operations. You will implement risk frameworks aligned with DORA and ISO standards while managing security tools and operations. The ideal candidate has over 4 years in information security, a strong...


  • WorkFromHome, Hong Kong SAR China Reap Full time

    A leading global payment technology provider in Hong Kong seeks a Crypto Asset Custody & Security Engineer to bolster custody operations. You'll ensure the security of digital assets, enforce governance principles, and collaborate across teams to maintain operational resilience. The ideal candidate possesses hands-on experience in cryptocurrency custody and...