SaaS Senior Security and Privacy Analyst, Bilingual Japanese and English

Posted:
5/19/2026, 7:35:02 AM

Location(s):
Cebu, Philippines

Experience Level(s):
Senior

Field(s):
IT & Security

Workplace Type:
On-site

About the role

We are looking for a Senior Security and Privacy Analyst to serve as the APAC regional lead for AvePoint's Privacy, Security & Risk (PSR) program.  You will help implement and drive initiatives, programs, and projects to raise our game in Information Security, Privacy, and Risk Management across the Asia-Pacific region. You are pragmatic, operational, and practical in your understanding of risk and security, but also have a business-minded approach. You will help us "say what we do, do what we say, and prove it." [ISMAP Supp...(red) 2026 | Word] 

This role is critical to supporting AvePoint's expanding APAC compliance footprint—including ISMAP (Japan), IRAP (Australia), and regional privacy regulations—while partnering closely with our global PSR team. 

Key Responsibilities 

  • Regional Compliance & Certification: Lead and operationalize APAC-specific certification and audit activities, with primary focus on Japan's ISMAP (Information system Security Management and Assessment Program) and Australia's IRAP (Infosec Registered Assessors Program), including evidence gathering, control mapping, and coordination with external assessors. [ismap.go.jp][cyber.gov.au] 
  • Privacy & Data Protection: Support compliance with APAC data protection laws and regulations, including Japan's APPI, Australia's Privacy Act, and other regional requirements such as South Korea's PIPA, in alignment with AvePoint's global privacy standards. [AvePoint G...ndard_2026 | Word] 
  • Security Operations: Contribute hands-on to the day-to-day operations of the information security and privacy program, including monitoring and responding to security incidents across the APAC region. [ISMAP Supp...(red) 2026 | Word] 
  • Audit & Risk Management: Operationalize activities around certifications, audits, and risk management initiatives. Support internal and external audit readiness, including SOC 2 Type II, ISO 27001, ISO 27701, and APAC-specific frameworks. [DRAFT Glob...022 Review | PowerPoint] 
  • Sales Enablement & Customer Trust: Partner with the APAC sales organization on PSR matters—respond to customer security questionnaires, RFPs, and due diligence requests, balancing deal velocity with AvePoint's PSR requirements. Serve as a regional representative and advocate of AvePoint's expertise in data security. [avepoint.com] 
  • Documentation & Communication: Update and maintain security and privacy documentation to keep current with frequent regulatory and programmatic changes in the APAC region. Create effective technical communications in both Japanese and English across a variety of media. [ISMAP Supp...(red) 2026 | Word] 
  • Security Champions Program: Collaborate with regional Security Champions (e.g., in Japan, Singapore, China, and ANZ) to enhance security awareness, promote best practices, and drive localized security initiatives. [AvePoint P...Masterlist | Excel] 
  • Cross-Functional Collaboration: Actively participate in cross-functional teams representing the PSR function. Collaborate with the CISO/CPO and senior leadership to develop and execute strategic plans for APAC security and privacy initiatives. 
  • Vendor & Third-Party Risk: Support vendor risk assessments and third-party security evaluations for APAC-based partners and subprocessors, ensuring compliance with AvePoint's data protection and information security standards. [AvePoint I...st Center) | Word] 
  • Continuous Improvement: Continuously improve internal PSR deliverables and content in response to feedback from APAC customers, colleagues, and evolving regulatory landscapes. 

Required Qualifications 

  • Education: Bachelor's degree in Information Security, Computer Science, Engineering, Law, or a related field. A master's degree is preferred. 
  • Experience: Approximately 5–8 years of experience in information security, privacy, compliance, or risk management, with at least 2 years of experience supporting APAC-region compliance programs. 
  • Language: Fluent in Japanese and English (spoken and written) — this is a hard requirement. The role requires the ability to translate technical security and privacy concepts between both languages, interact with Japanese government-adjacent auditing bodies, and produce professional documentation in both languages. 
  • Writing Skills: Strong background in writing with excellent editing and proofreading skills in both English and Japanese. 
  • Technical Knowledge: Solid understanding of networking, cloud infrastructure, and information security principles. Familiarity with security frameworks such as ISO 27001, ISO 27002, SOC 2, and NIST SP 800-53. 
  • Regulatory Knowledge: Working knowledge of APAC privacy and data protection regulations (e.g., Japan APPI, Australia Privacy Act, PDPA). 

Preferred Qualifications 

  • ISMAP Expertise: Familiarity with Japan's ISMAP framework, including ISMAP management standards, the audit process, and cloud service registration requirements. Experience supporting ISMAP audits or readiness assessments is highly valued. [ismap.go.jp] 
  • IRAP Expertise: Familiarity with Australia's IRAP framework, including the ISM (Information Security Manual), PSPF, and the four-stage IRAP assessment process (Plan & Prepare → Define Scope → Assess Controls → Report Findings). [cyber.gov.au][cyber.gov.au] 
  • Additional Languages: Proficiency in Chinese (Mandarin) and/or Vietnamese is a significant plus. 
  • Certifications: Relevant certifications such as CIPP/ACISSPCISMCISA, or ISO 27001 Lead Auditor are highly desirable. 
  • Industry Experience: Experience in a SaaS, cloud software, or technology company in the security, privacy, or compliance field. 
  • Sales Enablement: Experience supporting sales teams with security questionnaires, RFPs, and customer-facing trust narratives. 

What We Offer 

  • The opportunity to be the APAC voice of one of the most forward-thinking PSR programs in the data management industry 
  • Direct collaboration with AvePoint's global Security Team, including the CISO/CPO and senior leadership [AvePoint I...st Center) | PDF] 
  • A dynamic, global team culture that values agility, passion, and teamwork 
  • Professional development support, including certification sponsorship 
  • Competitive compensation and benefits aligned with APAC market standards

What’s in it for you?

  • HMO coverage from day 1 of employment (plus 2 free dependents)
  • Group life insurance (upon regularization)
  • Wellness Reimbursement Program (upon regularization)
  • Paid annual and sick leaves (convertible into cash)
  • Paid compassionate leave (5 days)
  • Employee Dedication Award (years of service)
  • Employee Referral Bonus Program
  • Promoting diversity and inclusion
  • Business Travel Opportunity (Top Performers)
  • Hybrid Working Arrangement (3 days onsite & 2 days' work-from-home)
  • Competitive compensation package, Performance bonuses/incentives
  • Career growth & advancement opportunities

         *Terms and conditions apply


AvePoint is proud to employ talent from many different backgrounds, experiences, and identities. We believe that diversity and inclusion drives our success and is at the core of how we hire, communicate, and collaborate to deliver value and excellence. We are committed to fostering an environment where people can bring their whole selves to work and feel a sense of belonging, and we continue to work toward creating a workforce that represents the diversity of our customers and communities.  

Any personal data you share with us during the application process will be processed strictly in compliance with applicable data protection laws and our Privacy Notice.

AvePoint

Website: http://avepoint.com/

Headquarter Location: Jersey City, New Jersey, United States

Employee Count: 1001-5000

Year Founded: 2001

IPO Status: Public

Last Funding Type: Post-IPO Secondary

Industries: Cloud Computing ⋅ Data Management ⋅ Document Management ⋅ Information Technology ⋅ SaaS ⋅ Software