Head of Information Security (APAC)

Remote $75k–$125k head English ANY 4 months ago full-time quality 8.9/10

Role in brief

Alpaca, a financial institution providing brokerage infrastructure, is hiring a Head of Information Security for the APAC region. This role involves managing the regional security program, ensuring compliance with local regulations, and overseeing risk mitigation. Candidates with strong experience in information security, GRC, and APAC regulatory requirements, who are fluent in Japanese and English, should consider applying.

SOC 2ISO 27001cloud securityapplication securityinfrastructure securityrisk managementGRCsecurity compliance

About the role

This role focuses on leading Alpaca's information security program within the APAC region. The chosen candidate will be responsible for translating local regulatory requirements into practical security controls and managing the overall security posture for the company's cloud infrastructure, APIs, and trading systems. This involves identifying, assessing, and mitigating risks specific to the APAC operational context.

A key aspect of this position is collaboration with the Engineering team to embed security principles from the initial design phase of cloud-native infrastructure. The Head of Information Security will also be crucial in preparing for and navigating regulatory exams, audits, and assessments within the region. This requires developing and maintaining regional security policies, standards, and procedures.

Success in this role means effectively safeguarding Alpaca's operations in APAC by ensuring robust security measures are in place and consistently adhered to. It involves proactive risk management and a strong understanding of both technical security aspects and the regulatory landscape. The role contributes directly to the company's ability to operate securely and compliantly in a critical growth market.

The salary for this position ranges from $75,000 to $125,000 USD annually.

Skills that matter here

  • SOC 2: This framework is relevant for ensuring the company's information security practices meet established trust service criteria, particularly in the context of audits.
  • ISO 27001: Experience with this international standard for information security management systems will be used to develop and maintain robust security policies and procedures.
  • cloud security: This skill is essential for managing and securing the company's cloud infrastructure and ensuring its resilience against threats.
  • application security: The role requires ensuring the security of the company's APIs and trading systems from design through deployment.
  • risk management: This involves identifying, assessing, and mitigating security risks across all regional operations, including cloud and trading systems.
  • GRC: Governance, Risk, and Compliance experience is fundamental for interpreting and implementing regulatory requirements and managing audits.

Who this role suits

  • A professional with at least six years of experience in information security, cybersecurity, or GRC.
  • Someone who is fluent in both Japanese and English, enabling effective communication within the APAC region.
  • An individual with direct experience navigating APAC regulatory requirements, such as APPI and FSA.
  • A candidate who has a proven track record of managing audits, regulatory exams, or compliance programs.

From the employer

  • Manage Alpaca’s APAC information security program.
  • Interpret and implement local regulatory requirements into security controls.
  • Lead risk identification, assessment, and mitigation for cloud infrastructure, APIs, and trading systems.
  • Partner with Engineering for secure-by-design, cloud-native infrastructure.
  • Lead and support regulatory exams, audits, and assessments.
  • Develop and maintain regional security policies, standards, and procedures.
  • 6+ years of experience in information security, cybersecurity, or GRC.
  • Fluent in Japanese and English.
  • Excellent understanding of cloud security, application and infrastructure security, and risk management frameworks.
  • Experience with security and compliance frameworks (ISO 27001, SOC 2).
  • Direct experience with APAC regulatory requirements (APPI, FSA).
  • Proven experience handling audits, regulatory exams, or compliance programs.
  • Competitive Salary & Stock Options.
  • Health Benefits.
  • New Hire Home-Office Setup: One-time USD $500.
  • Monthly Stipend: USD $150 per month via a Brex Card.

Questions about this role

What is the remote work policy for this role?

This is a fully remote position.

What is the seniority level for this position?

This role is at the Head level.

What skills are required for this role?

Required skills include experience with SOC 2, ISO 27001, cloud security, application security, infrastructure security, risk management, GRC, and security compliance, along with fluency in Japanese and English.

Similar jobs

Before you apply

  • Legitimate employers never ask you to pay anything to apply or get hired.
  • Never share seed phrases or private keys. No real job needs them.
  • Do not install software ("test tasks", "trading tools", "video call clients") sent during hiring.
  • Check that the application page's domain really belongs to Alpaca.