GRC Specialist (Compliance)

Posted 5 Days Ago
Be an Early Applicant
Hiring Remotely in Bangkok, Phra Nakhon, Bangkok, THA
Remote
Mid level
Marketing Tech • Retail • Software
The Role
Run daily compliance operations for ISO 27001, PDPA, and PCI-DSS: manage evidence collection, coordinate audits, track remediation, validate controls, maintain dashboards, and support vendor assessments to keep the organisation audit-ready.
Summary Generated by Built In

You will run the day-to-day compliance operations that keep CP Axtra audit-ready year-round. This means managing the evidence collection lifecycle for ISO 27001, PDPA, and PCI-DSS; coordinating with control owners across the business to ensure evidence is current and complete; and tracking remediation actions from audits and assessments to verified closure.

You'll be the go-to person when an auditor asks 'show me evidence of control X operating effectively.' Your job is to ensure that question is never stressful — because the evidence is already organised, validated, and ready. You'll also coordinate internal and external audit logistics, manage the audit calendar, and produce compliance dashboards that give the GRC Department Manager instant visibility into compliance health.

This role is ideal for someone who thrives on organisation, attention to detail, and driving accountability — someone who gets genuine satisfaction from turning a messy evidence folder into a clean, traceable audit trail.

Responsibilities:

·       Manage the end-to-end evidence collection process for ISO 27001, PDPA, and PCI-DSS — define evidence requirements, assign collection tasks to control owners, validate completeness, and organise evidence repositories

·       Coordinate internal and external audit schedules — manage logistics, prepare control owners for audit interviews, ensure evidence packages are ready, and track audit finding responses

·       Track and drive remediation of audit findings and compliance gaps — maintain a remediation tracker with owners, deadlines, and status; escalate overdue items; validate closure evidence

·       Conduct control validation testing — verify that documented controls are operating effectively through sample testing, walkthroughs, and evidence review

·       Produce and maintain the compliance dashboard — real-time view of compliance status across frameworks, evidence collection progress, remediation pipeline, and upcoming audit milestones

·       Manage the security exception register — track approved exceptions, monitor expiration dates, ensure risk acceptance documentation is complete, and trigger renewal reviews

·       Support vendor compliance assessments — collect and review vendor security questionnaires, track vendor compliance gaps, and maintain the vendor risk register

·       Coordinate with IT and business teams on control implementation — translate compliance requirements into operational tasks and track implementation progress

·       Maintain compliance documentation — audit reports, finding responses, remediation evidence, exception approvals, and compliance correspondence with regulators and auditors


Requirements

·       Manage the end-to-end evidence collection process for ISO 27001, PDPA, and PCI-DSS — define evidence requirements, assign collection tasks to control owners, validate completeness, and organise evidence repositories

·       Coordinate internal and external audit schedules — manage logistics, prepare control owners for audit interviews, ensure evidence packages are ready, and track audit finding responses

·       Track and drive remediation of audit findings and compliance gaps — maintain a remediation tracker with owners, deadlines, and status; escalate overdue items; validate closure evidence

·       Conduct control validation testing — verify that documented controls are operating effectively through sample testing, walkthroughs, and evidence review

·       Produce and maintain the compliance dashboard — real-time view of compliance status across frameworks, evidence collection progress, remediation pipeline, and upcoming audit milestones

·       Manage the security exception register — track approved exceptions, monitor expiration dates, ensure risk acceptance documentation is complete, and trigger renewal reviews

·       Support vendor compliance assessments — collect and review vendor security questionnaires, track vendor compliance gaps, and maintain the vendor risk register

·       Coordinate with IT and business teams on control implementation — translate compliance requirements into operational tasks and track implementation progress

·       Maintain compliance documentation — audit reports, finding responses, remediation evidence, exception approvals, and compliance correspondence with regulators and auditors

TECHNICAL REQUIREMENTS

·       Compliance frameworks: ISO 27001 (control mapping), PDPA requirements, PCI-DSS basics

·       Evidence management: Document management systems, evidence repositories, audit trail maintenance

·       Tracking and reporting: Project management tools, compliance dashboards, Excel/Google Sheets for tracker management

·       Control testing: Basic understanding of IT controls — access management, change management, logging, backup — to validate evidence

MUST-HAVE REQUIREMENTS

These are non-negotiable. If you do not meet all of these, this role is not the right fit.

·       4+ years in information security, IT audit, or compliance operations

·       Hands-on experience with audit evidence management — you've collected, organised, and presented evidence to external auditors

·       Working knowledge of ISO 27001 controls and audit processes — you understand what auditors look for and how to prepare for assessments

·       Strong project management and tracking skills — ability to manage multiple concurrent compliance workstreams with different deadlines

·       Excellent attention to detail and organisational skills — you can manage hundreds of evidence items across multiple frameworks without dropping anything

·       Fluent in Thai; reading English proficiency for compliance frameworks and documentation

NICE-TO-HAVE

These will set you apart from other candidates:

·       ISO 27001 Internal Auditor certification or equivalent

·       Experience with PDPA compliance operations or PCI-DSS evidence management

·       Familiarity with GRC tools (ServiceNow GRC, OneTrust, or similar) for automating evidence collection and tracking

·       Background in IT audit (Big Four or internal audit function) — understanding audit methodology and expectations

·       Experience building compliance dashboards or automated reporting

Skills Required

  • 4+ years in information security, IT audit, or compliance operations
  • Hands-on experience with audit evidence management and presenting evidence to external auditors
  • Working knowledge of ISO 27001 controls and audit processes
  • Strong project management and tracking skills to manage multiple concurrent compliance workstreams
  • Excellent attention to detail and organisational skills for managing many evidence items
  • Fluent in Thai and able to read English for compliance frameworks and documentation
  • Familiarity with PDPA and PCI-DSS basics
  • Experience with document management systems and evidence repositories for audit trail maintenance
  • Experience using project management tools, compliance dashboards, and Excel/Google Sheets for trackers and reporting
  • Basic understanding of IT controls (access management, change management, logging, backup) for control validation testing
  • ISO 27001 Internal Auditor certification or equivalent
  • Experience with PDPA compliance operations or PCI-DSS evidence management
  • Familiarity with GRC tools (ServiceNow GRC, OneTrust, or similar)
  • Background in IT audit (Big Four or internal audit function)
  • Experience building compliance dashboards or automated reporting
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Khet Suan Luang, Bangkok
103 Employees

What We Do

Makro PRO is an exciting new digital venture by the iconic Makro. Our proud purpose is to build a technology platform that will help make business possible for restaurant owners, hotels, and independent retailers, and open the door for sellers. Makro PRO brings together the best talent across multi-nationals to transform the B2B marketplace ecosystem. We welcome bold, energetic, and thoughtful people who share our belief in collaboration, diversity, excellence, and putting customers at the heart of our work.

Similar Jobs

Ericsson Logo Ericsson

Intern - Talent Acquisition

Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
Remote
Bangkok, Phra Nakhon, Bangkok, THA
88000 Employees

Capco Logo Capco

Platform Engineer

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
Bangkok, Phra Nakhon, Bangkok, THA
6000 Employees
200K-250K Annually

Capco Logo Capco

Devops Engineer

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
Bangkok, Phra Nakhon, Bangkok, THA
6000 Employees
3-5 Annually

Capco Logo Capco

Managing Principal (Tech)

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
Bangkok, Phra Nakhon, Bangkok, THA
6000 Employees
80K-120K Annually

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account