Search Jobs

Search by job, company or skills

IT Governance & Compliance Lead

IT Governance & Compliance Lead

Fundiin
  • Posted 13 hours ago
  • Be among the first 10 applicants

Job Description

Job Overview
  • Job title: IT Governance & Compliance Lead
  • Direct Manager: CTO

Established in 2019 as Vietnam's pioneering Buy Now, Pay Later provider, Fundiin is evolving into a data-first, AI-enabled platform for financial services in 2026. Fundiin partners with leading banks and financial institutions to orchestrate and optimize the distribution of a wide range of products - from BNPL and personal loans to credit cards - through a single and seamless app.

Leveraging proprietary data and AI-driven decisioning, Fundiin matches consumers with the most relevant offers, improving approval rates, user experience, and partner performance. By delivering a fully digital, end-to-end journey, Fundiin enables millions of users to access financial products with greater clarity, confidence, and control.

Role Overview

Fundiin is evolving into a multi-product consumer financial platform — expanding across lending products, onboarding new financial institution partners, and entering regulated markets. As this happens, IT governance and compliance are no longer optional — they are core to how Fundiin operates and scales.

As IT Governance & Compliance Lead, you will own the IT governance, technology risk, and compliance function end-to-end — ensuring Fundiin meets its regulatory obligations, maintains its certifications, and builds the documentation and audit readiness needed to support lender partnerships and regulatory requirements.

A significant part of this role involves managing complex, high-volume documentation workflows — and you are expected to leverage AI tools responsibly and actively to work efficiently at scale.

For the right person, this is an opportunity to build and own the compliance function at a high-growth fintech — shaping how governance is practiced across the organization, working directly with the CTO, and gaining exposure to the full spectrum of regulatory requirements as Fundiin scales into new financial products and regulated markets.

This is a role for someone who is detail-oriented, process-driven, and comfortable operating independently in a fast-moving fintech environment.

What you will working on:

 1. Regulatory Compliance

  • Ensure Fundiin complies with relevant technology, information security, and data protection requirements — Nghị định 13/2023/NĐ-CP, Thông tư 77/2025/TT-NHNN (where applicable to Fundiin or its partner obligations), Nghị định 85/2016/NĐ-CP, Thông tư 12/2022/TT-BTTTT, Thông tư 09/2020/TT-NHNN, Thông tư 50/2024/TT-NHNN, and other applicable regulations
  • Monitor regulatory changes and assess impact on Fundiin's technology operations and policies
  • Prepare compliance reports for management and external partners
  • Support regulatory engagements and serve as the primary technology compliance contact for auditors, partners, and relevant authorities
  • Manage compliance documentation and evidence for lender onboarding and partner security questionnaires

2. Certification & Audit Management

  • Own the ISO 27001, PCI-DSS, and An toàn TT Cấp độ 3 (Nghị định 85/2016/NĐ-CP & Thông tư 12/2022/TT-BTTTT) certification lifecycle — planning, evidence collection, auditor coordination, and renewal
  • Manage internal and external audit processes — track findings, coordinate remediation, and ensure timely closure
  • Maintain audit trails, compliance evidence, and control testing records

3. IT Governance Framework

  • Develop and maintain IT governance policies, standards, and procedures — change management, access control policy, data governance, and SDLC governance
  • Own the Business Continuity Plan for critical technology systems, ensuring alignment with regulatory and partner requirements
  • Ensure policies are aligned with regulatory requirements and continuously updated
  • Drive policy adoption, monitor compliance, manage exceptions, and escalate material gaps to management
  • Maintain the IT risk register and compliance dashboard — tracking risks, controls, and remediation status
  • Track exceptions, overdue actions, and vulnerability/patch management governance — escalating to management where required

4. Security Incident & Third-Party Governance

  • Govern security incident and data breach compliance — including evidence preservation, regulatory assessment, notification requirements, corrective-action tracking, and post-incident follow-up
  • Monitor third-party and lender security risk — ensuring partner compliance obligations are tracked and met
  • Support the assessment of technology and data risks introduced by new lender and partner integrations

5. Stakeholder Collaboration

  • Collaborate cross-functionally with engineering, security, legal, finance, and operations on compliance matters
  • Provide advisory on compliance requirements to engineering and product teams
  • Manage relationships with external auditors, certification bodies, and regulatory contacts
  • Respond to compliance and security questionnaires from lenders and financial partners

6. Operational Excellence

  • Actively use approved AI tools responsibly for compliance workflows — policy drafting, evidence preparation, audit response, and compliance reporting — with appropriate review, confidentiality, and data-handling controls
  • Continuously improve documentation efficiency and quality through AI-assisted processes
  • Contribute to Fundiin's AI-native working culture — share best practices and help establish team prompting standards for compliance workflows
What you will need:

Must Have

  • 5+ years of experience in IT governance, IT compliance, or IT risk in fintech, banking, or a regulated financial environment
  • Hands-on experience leading at least one major certification program — ISO 27001 or PCI-DSS — with strong exposure to the other
  • Strong understanding of technology, information security, and data protection regulatory requirements relevant to fintech in Vietnam — Nghị định 13/2023, Thông tư 77, or equivalent
  • Experience managing audits — internal and external — including evidence collection, finding tracking, and remediation coordination
  • Comfortable working independently and cross-functionally — coordinating across engineering, security, legal, and external parties
  • Willing and able to use approved AI tools responsibly for compliance workflows, with appropriate review, confidentiality, and data-handling controls
  • Good written English — sufficient for compliance documentation and partner/auditor communication
  • Strong ownership mindset — drives clarity, does not wait to be told what to do

Nice to have

  • Certifications — CISA, CISM, ISO 27001 Lead Implementer/Auditor, or equivalent
  • Experience with IT governance frameworks — COBIT, ITIL
  • Familiarity with An toàn TT Cấp độ 3 requirements (Nghị định 85/2016/NĐ-CP & Thông tư 12/2022/TT-BTTTT)
  • Experience standardizing compliance processes across multiple lenders or partners
  • Background in BNPL, consumer lending, or regulated financial products.

More Info

Job Type:
Industry:
Function:
Employment Type:

Key Skills

About Company