Search Jobs

Search by job, company or skills

Automation Compliance Engineer, IT Compliance (2026 Graduate)

Automation Compliance Engineer, IT Compliance (2026 Graduate)

Shopee
Early Applicant
  • Posted 2 months ago
  • Be among the first 10 applicants

Job Description

Job Description:

  • Design and implement workflowbased control automation for Regulatory Standards (e.g., ISO, PCI) and SOX 404 ITGCs, using:
    • Explicit start-action-evidence-end flows.
    • Triggers from tickets, changemanagement systems, HR events, or IAM changes.
    • Delivered via tools such as n8n, Camunda, Azure Logic Apps, or custom MCPstyle servers.
  • Build and operate MCPstyle or MCPcompatible servers that expose:
    • Tools: RESTful endpoints for trigger evidence collection, run access review, validate change ticket, etc..
    • Resources: Standardized data sources (logs, IAM, ticket data) formatted for AI agents or workflow engines.
    • Auth patterns: API keys, bearer tokens, OAuth2, or OIDCstyle flows that can be consumed by agents or external tools.
  • Engineer APIfirst automation:
    • Write scripts and connectors (Python, Node.js, Bash, etc.) that call, compose, and orchestrate APIs from:
      • IAM, IdP, PAM, HRIS, ticketing, cloud IAM, and logging platforms, etc.
      • GRC platforms (e.g., ServiceNow, 6clicks, or similar) via REST APIs.
    • Implement:
      • Authentication and authorization (API keys, Bearer, OAuth2, JWT, Basic, MTLS).
      • Pagination, retry with backoff, ratelimiting, and safe error handling.
      • Idempotency and safe state transitions for auditcritical operations.
  • Translate ISO 27001 controls and SOX 404 ITGCs into automated workflows:
    • Example pattern:
      • Trigger: new user join or role change in IAM.
      • Action: call APIs to validate entitlements, crosscheck against SoD, and emit evidence to a GRC tool.
      • Outcome: workflowgenerated record for ISO 27001 access control and SOX logicalaccess control.
    • Maintain one source of truth for control logic (code / config) and use workflow IDs as controlevidence bindings.
  • Design AIagentready interfaces:
    • Expose structured, MCPstyle endpoints or OpenAPI specs so that LLM agents or workflow tools can call concrete tools (e.g., get latest access review for System X, run changeticketcompleteness check).
    • Handle dynamic policy enforcement: shortlived tokens, contextaware access, and audit logging for each AI or agent call.
  • Integrate with data platforms and SIEM/logging:
    • Use logs, change tickets, and identity events as workflow inputs.
    • Build automated tests for control effectiveness (e.g., if a production change is not approved, fire an alert and record as control failure) linked to ISO / SOX control IDs.
  • Maintain auditready workflow artifacts:
    • Log all workflow steps, including timestamps, input, user/agent context, and outputs.
    • Ensure workflow outputs are machinable (JSON, structured logs) and can be replayed or reasoned over by auditors or AI agents.

Requirements:

  • Bachelor's degree or above in computer science, computer engineering or related disciplines.
  • Strong understanding of authorization and authentication:
    • API keys, Bearer tokens, OAuth2 (client, JWT, PKCE), Basic Auth, MTLS, and OIDCstyle flows.
    • Handson experience implementing these in Python, Node.js, or Go (or similar).
  • Deep practical experience with:
    • RESTful APIs: understanding of HTTP methods, status codes, pagination, ratelimiting, and idempotency.
    • API clients: writing or using libraries that handle auth, retries, and error handling for large datasets.
  • Experience building or integrating with:
    • Workflow / orchestration tools (n8n, Airflow, Logic Apps, Camunda, etc.) or MCPstyle servers / Model Context Protocolcompatible tooling.
    • GRC platforms via APIs (e.g., ServiceNow, 6clicks, or similar).
  • Familiarity with:
    • ISO 27001 (especially Annex A controls related to access management, change control, and operations).
    • SOX 404 ITGCs (logical access, change management, computer operations, data integrity).

Preferred Qualifications:

  • OpenAPI / Swagger to MCPstyle tool generation (e.g., converting production APIs into MCP servers or AIagent tools).
  • Experience with MCP servers or similar controlplane architectures that expose tools, resources, and prompts for AI agents.
  • Background in security automation, CI/CD, or DevSecOps (number of tools: n8n, Terraform, Ansible, Docker, logging pipelines).
  • Prior involvement in SOX 404 audits and ISO 27001 certification projects, with a focus on how to automate evidence collection rather than manual spreadsheets.

More Info

Job Type:
Employment Type:

About Company