Skip to main content

CAREERS · SECURITY & COMPLIANCE

Head of Security & Compliance

Bring senior security and compliance judgement to Lawnise—strengthening our institutional credibility, guiding consequential decisions and representing our position with regulated enterprises.

Apply for this role
Location
Kuala Lumpur · Hybrid
Engagement
Full-time or fractional · To be agreed
Works with
Executive leadership, engineering and external counsel

About Lawnise

Lawnise is building Independent AI Trust Infrastructure for enterprises. Our platform verifies the AI an organisation deploys and the public AI that represents it, producing traceable evidence across trust, risk and security. We begin with regulated financial services in Malaysia and Singapore.

Read why we are building Lawnise

The mandate

What this role is here to establish

Independent verification is credible only when the verifier can withstand scrutiny itself. You will be Lawnise's senior security and compliance authority: advising leadership, challenging material decisions and setting a proportionate direction for security, privacy and enterprise assurance.

You will help Lawnise earn trust in senior customer and industry conversations, without turning the role into ceremonial oversight. Engineering, operations and counsel will execute within their disciplines; you will make sure priorities, risk decisions, evidence and accountability remain coherent.

Why now

Why this role matters now

Lawnise is moving into deeper enterprise engagements with regulated organisations. Customers and partners need to see credible senior judgement behind our control position, customer commitments and security boundaries. This role gives leadership an experienced challenger and gives the market a trusted counterpart who can represent Lawnise with substance.

Accountability

What you will own

  • Advise the CEO and engineering leadership on security, privacy, technology-risk and enterprise-assurance priorities.
  • Set and periodically challenge Lawnise's control roadmap, risk posture and path toward independent assurance or certification.
  • Review material risk acceptances, security positions and customer commitments within documented authority; binding commitments remain with authorised executives and counsel.
  • Guide customer security, privacy and technology-risk assessments, joining the consequential review conversations rather than acting as a questionnaire administrator.
  • Oversee the quality of Lawnise's assurance evidence, incident readiness and executive review cadence, with operational controls owned by the teams that run them.
  • Provide senior governance for ThreatGuard authorisation, rules of engagement and safety boundaries before security assessments are undertaken.
  • Represent Lawnise credibly with CISOs, risk leaders, regulated buyers and relevant professional forums.
  • Develop trusted relationships across financial services, cybersecurity, governance, legal and assurance communities, and make relevant introductions where appropriate.

Evidence of impact

What strong performance looks like

  • 01Customer assessments are answered consistently from maintained evidence rather than recreated for each request.
  • 02Commitments made in contracts map to named controls, owners and review dates.
  • 03Security decisions and accepted risks are recorded, challengeable and visible to the right leadership.
  • 04Incidents and exercises produce learning, corrective action and reliable communication.
  • 05Lawnise's security position is represented credibly in senior customer and industry conversations.
  • 06Engineering teams understand the control objective without security becoming a ceremonial approval layer.

Evidence of fit

Experience that will help

  • Significant responsibility in information security, technology risk, audit or third-party risk in—or supplying—regulated financial institutions.
  • First-hand experience leading or assessing enterprise security questionnaires and the review conversations behind them.
  • Working knowledge of Malaysian financial-sector technology-risk expectations and data-protection obligations, with the judgement to know when specialist legal interpretation is needed.
  • Experience translating policy and contractual commitments into operating controls and evidence.
  • Participation in incident response, notification or exercises with accountable follow-through.
  • Enough technical depth to examine cloud, identity, secrets, network and database-access controls with engineers.
  • Clear written communication and the composure to represent a control position under scrutiny.
  • Established relationships across regulated financial services, cybersecurity, technology risk or assurance, with the judgement to make relevant introductions without implying influence or guaranteed access.

Additional context

Relevant, not required by default

Experience with ISO 27001, SOC 2, CISSP, CISM or CRISC may be useful, but certification is not a substitute for operating judgement. Experience on both sides of regulated-enterprise vendor assessment is particularly relevant. Bahasa Malaysia is useful for the launch market.

Working together

How the engagement works

We are open to a full-time or fractional arrangement, depending on the candidate, availability and the operating model agreed together. In either form, this is a substantive leadership mandate with documented access, responsibility and direct engagement with executive and engineering owners.

Work that requires legal opinion or binds the company remains with external counsel and authorised executive signatories.

The final arrangement, responsibilities and decision authority will be confirmed in writing before the engagement begins.

Hiring process

What happens after you apply

  1. 01

    Application review

    We review your CV and response against the published mandate.

  2. 02

    Introductory conversation

    We discuss your experience, the role and the current engagement model.

  3. 03

    Structured role discussion

    We use a bounded, fictionalised or Lawnise-provided work sample. It is not unpaid production work.

  4. 04

    References and engagement

    With your permission, we speak with referees you nominate before discussing final terms in writing.

If another specialist conversation is needed, we will explain why before adding it to the process.

Application

Apply for this role

Send your CV and a short response to the role question. We use both only to assess this application.

Share an example that demonstrates your judgement. Keep your response to 300 words or fewer, and do not include confidential information belonging to another organisation.

No CV selected.

Tell us about a security, privacy or technology-risk responsibility you owned. What did you need to establish, how did you use evidence, and what changed because of your work?

Do not include confidential information.

0 / 300 words

By submitting, you acknowledge that Lawnise will process your information to assess and manage your application as described in our Privacy Policy. Questions about your application or how we handle it: careers@lawnise.com.