About audax
audax means courage. To have the courage to change the banking scene, eliminating constraints caused by existing legacy infrastructure. Our mission is to empower banks and financial institutions to scale and modernise at speed, reaching new customers without breaking the bank.
We began our journey supplying services to and powering Standard Chartered'swhite-label plug and play Banking-as-a-Service (BaaS) solution, Standard Chartered nexus, through our technology capabilities. At audax, we seek go-getters who are hungry for growth and can bring fresh perspectives.
Website - https://www.audax.io
What You'll Do:
We are looking for a seasoned security professional to act as the primary interface between our customers security teams and our internal product, engineering, and compliance stakeholders. This role is responsible for understanding customer security and regulatory requirements, mapping them to our product security controls, and confidently articulating, negotiating, and guiding customers toward mutually acceptable security outcomes.
In addition, the role will support internal security and risk initiatives by providing security architecture and risk oversight across project lifecycles.
You will serve as a trusted security advisor to clients / stakeholders while ensuring our products meet regulatory, risk, and security expectations in a scalable and consistent manner. Your key responsibilities are:
(1) Client & Stakeholder Engagement
- Act as the primary security point of contact when engaging with customer security, risk, and compliance teams.
- Build and maintain trusted relationships with bank stakeholders including CISO, Technology Risk, Compliance, Audit, and Operations teams.
- Lead security discussions, assessments, and reviews with customers to understand their security, regulatory, and risk requirements.
- Clearly articulate our product security architecture, controls, and risk posture to customers.
- Manage and resolve differing security views by negotiating practical, risk-based and mutually acceptable solutions.
- Support customer due diligence activities including security questionnaires, audits, and regulatory assessments.
(2) Security Standards & Regulatory Alignment
- Maintain strong working knowledge of relevant security andregulatory standards including ISO/IEC 27001, CIS, GDPR, MAS TRM, and otherapplicable frameworks.
- Translate and harmonize multiple customer and regulatory standards into a unified, consistent set of product security controls.
- Ensure consistent interpretation and implementation of security controls across products and environments.
(3) Product Security & Risk Management
- Perform threat modeling and security risk reviews against defined security control frameworks.
- Assess product architectures (cloud, containerized,API-based, mobile) for security risks and control effectiveness.
- Partner with engineering and product teams to validate control implementation and remediate gaps.
- Provide security design guidance aligned with regulatory and customer expectations.
(4) Data Protection & Privacy
- Advise on data protection, privacy, and data residency requirements relevant to customer and regulatory needs.
- Assess product data flows and controls to ensure alignment with applicable privacy regulations.
(5) Internal Advisory & Enablement
- Serve as a subject matter expert to internal teams on customer security expectations and regulatory interpretations.
- Support sales, pre-sales, and customer success teams during security-related discussions.
- Contribute to security documentation, control mappings, and assurance materials.
(6) Internal Security & Risk Project Support
- Support internal security and risk initiatives includingarchitecture reviews, project rollout reviews, and major change assessments.
- Review solution designs and project implementations toensure alignment with approved security architectures and control requirements.
- Identify security risks arising from new products, features, or infrastructure changes and recommend appropriate risk treatments.
- Provide security sign-off or input as part of internal governance, risk, and change management processes.
- Collaborate with internal security, risk, and compliance teams to continuously improve security standards, controls, and assurance processes.
Who You Are:
- 8+ years experience in cybersecurity delivery, technologyrisk, or security consulting within financial services.
- Proven experience delivering security programs for bankingor regulated financial institutions.
- Strong background in baseline security controls andcontrol assurance in a banking context.
- Experience working in a vendor or managed servicesenvironment serving banking clients.
- Strong working knowledge of security and regulatorystandards (e.g. ISO27001, CIS, GDPR, MAS TRM).
- Proven experience harmonizing multiple security and regulatory standards into a unified control framework.
- Solid understanding backed by hands-on experience (either engineering, operations or penetration testing) in:
- Cloud security (IaaS, PaaS,SaaS)
- Container and platform security
- Application security (API, web, mobile)
- Experience performing threat modeling and security risk assessments.
- Working knowledge of data protection and privacy requirements.
- Strong communication skills with the ability to confidently explain security concepts to technical and non-technical audiences.
- Demonstrated ability to manage differing security viewpoints and guide stakeholders toward risk-based, pragmatic outcomes.
Why Join Us
- Be Part of a Bold Vision - At audax, we're not just building software - we're transforming how financial institutions and businesses manage risk, compliance, and growth. Join a team that's fearless in challenging the status quo.
- Flexible, People-First Workplace - We value the importance of Family, Team, Self. In that order.
- Competitive Rewards and Startup Perks - We offer competitive salaries and meaningful benefits that look after your well-being.
Privacy Notice:
Please note: by submitting your application, you acknowledge that you have read and understood audax's Privacy Policy for Employees, Freelancers, Contractors and Job Applicants (the Policy), and consent to the collection, use and disclosure of your personal data by audax for the purposes set out in the Policy. You may withdraw consent for such collection, use and disclosure, and make an access or correction request in respect of your personal data, in accordance with the Policy by emailing [Confidential Information].