Save Job Back to Search Job Description Summary Similar JobsOwn security program at scaleHigh-impact role in AI SaaSAbout Our ClientOur client is a fast-growing & well funded series A - AI SaaS company building advanced browser-based solutions for enterprise customers. They operate in a highly technical, fast-paced environment, serving global clients with strong security and compliance expectations as they scale.Job DescriptionSecurity & Compliance Program OwnershipManage ISO 27001 lifecycle and drive SOC 2 readiness (Type 1 & 2)Own audit processes, external auditor relationships, and evidence management (e.g., Vanta)Operational Security ProgramsLead vulnerability management program (SLA tracking, escalation, reporting)Manage policy lifecycle, including reviews, updates, and compliance trackingOversee security training, access reviews, and people-related security controls in partnership with HRRisk & Vendor ManagementOwn vendor risk assessments, inventory, and ongoing compliance monitoringMaintain risk register and coordinate incident management framework and tabletop exercisesCustomer & External EngagementManage customer security questionnaires, RFPs, and audit responsesRepresent the security program in enterprise customer discussionsCross-functional CoordinationWork closely with Security, Engineering, HR, and leadership to ensure security requirements are operationalized effectivelyDrive continuous improvement of security processes, tools, and reporting cadenceThe Successful Applicant4-7 years of experience in security, GRC, or compliance program management, ideally in B2B SaaSProven experience managing ISO 27001 and SOC 2 audits end-to-endStrong familiarity with tools such as Vanta, Drata, or equivalent platformsExperience handling enterprise customer security requirements and audit processesStrong written communication and stakeholder management skillsAbility to assess and prioritize real security risks versus procedural gapsNice to Have:Exposure to AI/ML security or modern SaaS security environmentsExperience with additional frameworks (e.g., HIPAA, ISO 27017/27018, FedRAMP)Background in vulnerability management, pen-testing coordination, or bug bounty programsWhat's on OfferHigh-impact role with direct ownership of security program at scaleOpportunity to work with cutting-edge AI products and enterprise clientsFast-paced, high-growth environment with strong leadership exposureCompetitive compensation and flexible working modelStrong career growth in a globally relevant security leadership trackContactDaniel NguyenQuote job refJN-062026-7039766Job summaryFunctionITSpecialisationSecurityWhat is your area of specialisation?Technology & TelecomsLocationHo Chi Minh CityContract TypePermanentConsultant nameDaniel NguyenJob ReferenceJN-062026-7039766