About the job
About HitPay
HitPay is a leading full-stack payments infrastructure platform dedicated to empowering growing businesses across the Asia-Pacific region. As a Singapore-based company, regulated by central banks throughout Southeast Asia, we facilitate seamless online and in-person payments for over 20,000 small and medium-sized businesses (SMBs) through trusted local methods. Our innovative solutions, which include real-time payment systems, e-wallets, and credit card terminals, are revolutionizing the payment landscape in Southeast Asia.
About the Role
As the Compliance and Security Program Manager at HitPay, you will play a pivotal role in spearheading our compliance, IT governance, and security initiatives across the organization. This dynamic position requires a unique blend of program management, compliance oversight, and technical expertise. You will collaborate closely with auditors, regulators, and internal teams (including product, engineering, and operations) to ensure that HitPay adheres to regulatory frameworks and industry standards while developing secure and resilient products.
Key Responsibilities
Compliance & Governance
Lead regulatory compliance programs including PCI DSS, SOC 2, and MAS PSA.
Coordinate audit processes with both internal stakeholders and external auditors.
Manage the compliance calendar, including penetration tests, ASV scans, policy reviews, and risk assessments.
Develop and enhance internal policies, IT governance frameworks, and controls.
Security Oversight
Collaborate with engineering teams to design and implement robust security features such as encryption, access controls, and logging.
Monitor security incidents, conduct risk assessments, and perform vendor due diligence.
Support business continuity planning, disaster recovery strategies, and incident response efforts.
Cross-Functional Program Management
Drive initiatives across teams to ensure that security and compliance are integrated into product development processes.
Translate compliance requirements into actionable tasks for engineering and product teams.
Serve as the primary point of contact for compliance and security inquiries from both internal and external stakeholders.

