DevSecOps Engineer (GRC)

📍 Kuala Lumpur, MY 🏢 Full-Time 💼 Backend

Location: Kuala Lumpur, MY

Department: Backend

Role: DevSecOps Engineer (GRC)

Mode: Full-time role

About Aelyst

Aelyst is an AI-powered omnichannel CRM and messaging automation platform built for SMBs in Indonesia and Malaysia. We help businesses capture, convert, and retain customers across WhatsApp, Instagram, and every channel their customers already use — all from one inbox, powered by AI agents that actually close deals.

We are a lean, fast-moving team building for the fastest-growing SMB market in Southeast Asia. Join us and help shape how millions of businesses talk to their customers.

Our Culture

  • Solve Real Problems: Every feature must solve a real customer pain point. No guesswork — just feedback and shipped value.
  • The 80/20 Rule: We focus on the 20% of work that creates 80% of the value. Simple is powerful.
  • Be Direct: Honest feedback, problems tackled head-on. Clarity moves us forward.
  • Own It: We step up, help out, and drive outcomes — together.
  • Speed Is a Feature: We ship fast, learn fast, and fix fast.

Role Description

You will own governance, risk, and compliance at Aelyst as we scale into a platform trusted with millions of customer conversations. You turn security frameworks into practical, auditable processes — making compliance an accelerator for enterprise deals, not a blocker for engineering.

Responsibilities

  • Own our compliance roadmap: drive ISO 27001 and SOC 2 readiness from gap assessment through audit
  • Ensure compliance with Indonesian PDP Law, Malaysian PDPA, and GDPR for our data processing activities
  • Build and maintain the security policy library, risk register, and vendor risk assessment program
  • Run security awareness training and phishing simulations across the team
  • Own customer security questionnaires and trust documentation to unblock sales
  • Coordinate audits, evidence collection, and remediation tracking with the technical security function
  • Manage incident disclosure and regulatory reporting processes

Qualifications

  • 3+ years in GRC, security compliance, or IT audit roles, ideally in SaaS
  • Working knowledge of ISO 27001, SOC 2, and privacy regulations (GDPR; familiarity with Indonesian PDP Law or Malaysian PDPA is a strong plus)
  • Experience running or supporting at least one full certification or audit cycle
  • Enough technical literacy to translate between auditors and engineers: cloud, CI/CD, and access control concepts
  • Excellent documentation skills: policies people actually read, evidence auditors actually accept
  • Clear written and spoken English

What's In It For You

  • You will be part of a small team with real ownership — your work ships to customers, fast.
  • You will grow more here than you would anywhere else. That is a promise.
  • A highly competitive compensation package.
  • Flexible working environment and working hours that fit your lifestyle.

Apply To Position