Shopee

Automation Compliance Engineer, IT Compliance (2026 Graduate)

Shopee

Singapore · Full Time

Be the first to apply

Experience
Any
Salary
Openings
1
Posted
3 weeks ago
Work mode
In office
Education
Bachelor's degree
Eligibility
Candidates who already have the right to work in Singapore and do not need visa sponsorship are prioritized. The hiring team will consider only one active recruitment process per person within Sea Group, in the order applications are received. This role is aimed at 2026 graduates.
Resume
Required to apply

Where you'll work

Job description

About the team

The IT Compliance group works like the company’s internal technology health check team, partnering with business stakeholders to create technical solutions that improve the user experience while keeping product and system controls aligned with regulatory requirements. A major part of the role is helping secure certifications by working closely with internal and external stakeholders. The team’s scope offers broad exposure to regional business realities and cross-functional coordination, supporting long-term solutions as the company continues to scale.

The employer gives priority to candidates who already have the legal right to work in Singapore and do not need visa sponsorship. In addition, each candidate may only be active in one recruitment process at a time within Sea Group, and applications are assessed in the sequence they are submitted.

Role overview

This position focuses on building workflow-driven compliance automation for regulatory controls, especially ISO standards and SOX 404 IT general controls. The work centers on turning control requirements into reliable, repeatable, API-connected automation that can generate audit-ready evidence with minimal manual effort.

Key duties

  • Develop and deploy automated, workflow-based controls for regulatory requirements such as ISO and PCI, as well as SOX 404 ITGCs, using clearly defined start, action, evidence, and end stages.
  • Create trigger-based automations from ticketing events, change-management systems, HR events, and identity-access-management changes.
  • Build solutions with orchestration and automation platforms such as n8n, Camunda, Azure Logic Apps, or custom MCP-style services.
  • Create and run MCP-style or compatible services that provide tools, structured resources, and authentication patterns usable by agents and external systems.
  • Expose endpoints for tasks like triggering evidence collection, running access reviews, and checking change-ticket completeness.
  • Organize standardized data sources such as logs, IAM records, and ticket data so they can be consumed by AI agents or workflow engines.
  • Develop API-first automations by writing scripts and connectors in Python, Node.js, Bash, or similar tools.
  • Integrate with IAM, IdP, PAM, HRIS, ticketing, cloud IAM, logging, and GRC platforms through REST APIs.
  • Implement secure API patterns including keys, bearer tokens, OAuth2, JWT, Basic Auth, and mutual TLS.
  • Design for pagination, retries with backoff, rate limits, idempotency, and safe failure handling, especially where audit integrity matters.
  • Convert ISO 27001 controls and SOX 404 ITGC requirements into automated workflows, such as validating access changes and writing evidence to GRC systems.
  • Maintain a single authoritative source for control logic in code or configuration, and link workflow IDs to control evidence.
  • Build interfaces that are ready for AI-agent use, including structured endpoints or OpenAPI specifications that can be called by agents or workflow tools.
  • Support dynamic policy controls such as short-lived tokens, context-sensitive access, and logging for every agent or AI-driven action.
  • Use logs, change tickets, and identity events as inputs for workflow processing.
  • Create automated control-effectiveness tests, for example flagging and recording a failure when an unapproved production change is detected, mapped to control IDs.
  • Keep workflow artifacts audit-ready by logging timestamps, inputs, user or agent context, and outputs for every step.
  • Ensure outputs are machine-readable, such as JSON or structured logs, so they can be replayed or reviewed by auditors or AI agents.

Requirements

  • A bachelor’s degree or higher in computer science, computer engineering, or a closely related field.
  • Strong knowledge of authentication and authorization methods, including API keys, bearer tokens, OAuth2 variants, Basic Auth, mutual TLS, and OIDC-style flows.
  • Practical implementation experience with these patterns in Python, Node.js, Go, or comparable languages.
  • Solid working knowledge of REST APIs, including HTTP verbs, status codes, pagination, throttling, and idempotency.
  • Experience building or consuming API clients that can manage authentication, retries, and errors across large data volumes.
  • Hands-on experience with workflow or orchestration platforms such as n8n, Airflow, Logic Apps, Camunda, or with MCP-style / Model Context Protocol-compatible tooling.
  • Experience integrating with GRC platforms through APIs, such as ServiceNow, 6clicks, or similar systems.
  • Working familiarity with ISO 27001 controls, especially those tied to access management, change control, and operations.
  • Understanding of SOX 404 IT general controls, including logical access, change management, computer operations, and data integrity.

Preferred qualifications

  • Exposure to OpenAPI or Swagger-based conversion into MCP-style tools, including turning production APIs into AI-agent utilities.
  • Experience with MCP servers or related control-plane setups that provide tools, resources, and prompts for AI agents.
  • Background in security automation, CI/CD, or DevSecOps, with tools such as n8n, Terraform, Ansible, Docker, and logging pipelines.
  • Prior participation in SOX 404 audits or ISO 27001 certification work, especially where evidence gathering was automated instead of handled through spreadsheets.

Additional information

This role is intended for 2026 graduates. No salary, stipend, duration, or start date was provided in the source information.

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help