Joining Razer will place you on a global mission to revolutionize the way the world games. Razer is a place to do great work, offering you the opportunity to make an impact globally while working across a global team located across 5 continents. Razer is also a great place to work, providing you the unique, gamer-centric #LifeAtRazer experience that will put you in an accelerated growth, both personally and professionally.
Job Responsibilities :The Senior Compliance & Risk Manager will be responsible for building and operating the regulatory compliance framework required to launch and sustain Bank of Thailand (BOT) regulated payment services in Thailand, ensuring full adherence to all license conditions, BOT notifications, AML/CFT requirements, and internal governance standards. The role also covers ongoing legal entity compliance, including management of the Foreign Business License (FBL) and the appointment and oversight of the Data Protection Officer (DPO) function under the PDPA. The role is further responsible for drafting, implementing, and enforcing compliance policies, procedures, and internal controls, and for delivering training and awareness programs for all relevant teams and employees.Role Summary
The Risk & IT Compliance Manager is responsible for overseeing technology risk management, IT regulatory compliance, information security governance, third-party risk management, business continuity, audit coordination, and regulatory engagement activities. The role is the accountable owner for the technology-related regulatory obligations. It is also the entity's single point of coordination for Bank of Thailand submissions, examinations and audits on technology matters. Ensuring that the organization maintains an effective risk and control environment, complies with applicable regulatory requirements, and operates in a secure, resilient, and sustainable manner.
1. Technology Risk Management & Governance
Develop and maintain the organization's Technology Risk Management Framework.
Maintain the Technology Risk Register; conduct technology risk assessments and where required risk control self-assessments.
Define, monitor, and report Technology Key Risk Indicators (KRIs).
Track Technology Risk Remediation Plans through to closure and monitor remediation progress, reporting progress and overdue items.
Assess technology risks associated with new products, services, projects, and system changes.
Prepare and present technology risk reports to senior management, the Risk Committee and the Board.
Support the establishment and review of Technology Risk Appetite and Risk Tolerance statements.
2. IT Regulatory Compliance & Technology Governance
Monitor, analyze, and interpret applicable technology-related laws, regulations, and regulatory expectations.
Assess the impact of new regulatory requirements on the organization.
Conduct compliance gap assessments and identify remediation actions.
Develop and maintain the Technology Compliance Roadmap.
Review and enhance the IT Governance Framework, policies, and standards.
Coordinate compliance initiatives with Group/HQ stakeholders.
Prepare supporting evidence and documentation for regulatory reviews and inspections.
3. Information Security, Cybersecurity and PCI DSS Oversight
Monitor compliance with Information Security policies, standards, and procedures.
Review Vulnerability Assessment and Penetration Testing (VA/PT) results.
Track security findings and remediation activities.
Assess the adequacy of security and cybersecurity controls.
Oversee the management of security incidents and cyber incidents.
Oversee data breach management and response activities.
Support Data Protection Impact Assessments (DPIA) and privacy risk assessments.
Manage and assist on PCI DSS annual renewal assessment.
4. Outsourcing & Third-Party Risk Management
Assess risks associated with third-party service providers before onboarding.
Conduct periodic Vendor Risk Assessments.
Evaluate risks arising from cloud services and critical service providers.
Review service level agreements (SLAs) and control requirements.
Monitor remediation activities undertaken by vendors and service providers.
Report outsourcing and third-party risks to management.
Maintain outsourcing register for all TPSP.
5. Business Continuity & Operational Resilience
Oversee the development and maintenance of the Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP).
Facilitate and challenge the Business Impact Analysis (BIA), validate recovery time objectives against regulatory expectations and customer commitments.
Conduct BCP / DR testing at least annually or on material change, report on test outcomes and track remedial actions (where required).
Assess the operational resilience of critical business services, including dependencies on Group and third-party.
6. Audit & Regulatory Examination Management
Act as the primary coordinator for IT audits.
Coordinate activities with Internal Auditors and External Auditors.
Coordinate regulatory examinations and inspections.
Prepare and maintain audit and compliance evidence.
Track audit findings and remediation plans.
Report remediation progress and audit status to management.
7. Regulatory Reporting & Regulatory Liaison
Prepare and submit IT regulatory reports within required timelines.
Act as a liaison with regulators, government agencies, and external reviewers.
Support regulatory licensing and ongoing compliance requirements.
Track regulatory commitments and follow-up actions.
Prepare technology risk and compliance reports for management and governance committees.
Qualifications
Bachelor's Degree or Master’s Degree in Information Technology, Computer Science, Information Security, Cybersecurity, Information Systems, Risk Management, or a related field.
Minimum 8-10 years of experience in Technology Risk, IT Compliance, IT Governance, Information Security, or IT Audit.
Experience within FinTech, Payment Service Providers (PSP), Acquiring Businesses, E-Wallets, Banking, or Financial Services environments.
Strong knowledge of Technology Risk Management, Operational Risk Management, and IT Control Frameworks.
Experience working with regulators, auditors, and external assessors.
Professional certification: CISA, CRISC, CISM, CISSP or equivalent preferred.
Razer is proud to be an Equal Opportunity Employer. We believe that diverse teams drive better ideas, better products, and a stronger culture. We are committed to providing an inclusive, respectful, and fair workplace for every employee across all the countries we operate in. We do not discriminate on the basis of race, ethnicity, colour, nationality, ancestry, religion, age, sex, sexual orientation, gender identity or expression, disability, marital status, or any other characteristic protected under local laws. Where needed, we provide reasonable accommodations - including for disability or religious practices - to ensure every team member can perform and contribute at their best.
Are you game?
Skills Required
- Experience managing compliance obligations under Bank of Thailand payment licenses and Payment Systems Act B.E. 2560
- Deep knowledge of AML/CFT frameworks, KYC/CDD, KYM onboarding and STR reporting to AMLO
- Experience with sanctions screening, sanctions risk assessments, and remediation processes
- Experience coordinating with regulators and submitting regulatory filings, audits, and operational readiness reports
- Experience overseeing Vulnerability Assessment / Penetration Testing and tracking remediation for BOT submissions
- Experience planning and managing IT audit cycles and coordinating third-party IT auditors
- Experience managing Foreign Business License (FBL) obligations and interacting with Department of Business Development (DBD)
- Acting as or overseeing a Data Protection Officer (DPO) and implementing PDPA compliance, DPIAs and breach reporting
- Designing and operating anti-fraud detection mechanisms and merchant remediation processes
- Ability to draft, implement, and deliver compliance policies, procedures, controls, and training programs
Razer Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Razer and has not been reviewed or approved by Razer.
-
Healthcare Strength — Health coverage options include medical plan choices, dental, vision, HSA/FSA, and mental health/EAP, indicating solid core coverage. Global leave and healthcare frameworks are described, reinforcing consistency across locations.
-
Retirement Support — A 401(k) with company matching and immediate vesting in some cases supports long‑term savings. This adds tangible value to the core total rewards package.
-
Wellbeing & Lifestyle Benefits — Free in‑office lunches on several weekdays and notable employee discounts on company gear enhance day‑to‑day value. Volunteering time and donation matching further complement lifestyle and purpose‑oriented needs.
Razer Insights
What We Do
Razer™ is the world’s leading lifestyle brand for gamers. The triple-headed snake trademark of Razer is one of the most recognized logos in the global gaming and esports communities. With a fan base that spans every continent, the company has designed and built the world’s largest gamer-focused ecosystem of hardware, software and services. Razer’s award-winning hardware includes high-performance gaming peripherals and Blade gaming laptops. Razer’s software platform, with over 70 million users, includes Razer Synapse (an Internet of Things platform), Razer Chroma™ (a proprietary RGB lighting technology system), and Razer Cortex (a game optimizer and launcher). In services, Razer Gold is one of the world’s largest virtual credit services for gamers, and Razer Fintech is one of the largest online-to-offline digital payment networks in SE Asia. Founded in 2005 and dual-headquartered in Irvine and Singapore, Razer has 18 offices worldwide and is recognized as the leading brand for gamers in the USA, Europe and China. Razer is listed on the Hong Kong Stock Exchange (Stock Code: 1337).








