Reap
Reap
201 – 500 Employees
B2BCryptoFintech
Reap is a fintech company building borderless financial infrastructure for businesses operating across currencies and markets. Founded in 2018, the company combines stablecoin-enabled cross-border payments with business accounts, Visa corporate cards, multi-currency expense management, and embedded finance APIs. Its platform supports global fiat payouts, card issuing, payment automation, and treasury workflows for businesses seeking more flexible ways to manage international finances. Reap operates across fintech, crypto, and B2B markets with a team of 201–500 employees.

Data Access Control Analyst — Hybrid, Hong Kong

Protect client data across Reap’s global payment technology platform. Manage access reviews, audit controls, data classification, and GDPR compliance activities.

Description

  • Keep an up-to-date register of Payward-affiliated personnel and map access to Reap systems containing client data
  • Conduct monthly access certification reviews for employees, contractors, service accounts, and API keys
  • Record review findings and exceptions in complete, traceable audit records
  • Create and maintain audit logs showing who accessed client data, through which system, and when
  • Prepare monthly reports for the Data Governance Manager and CISO
  • Configure SIEM alert rules with the Detection/SecOps Security Engineer
  • Coordinate data-related DSARs with the external DPO
  • Maintain data classification labels across databases, dashboards, data warehouses, file storage, and analytics environments
  • Update GDPR Article 30 ROPA records when client data flows change due to products, geographies, or partners

Requirements

  • Experience managing user access reviews and certifications, including monthly review cycles, exception handling, and escalation
  • Hands-on experience with IAM platforms; Okta is strongly preferred
  • Ability to create and audit access policies
  • Experience using SQL or an equivalent tool to query access logs, produce reports, and detect anomalies
  • Working knowledge of GDPR Article 28 and data-access breach fundamentals, including notification implications
  • Experience managing evidence and producing audit trails suitable for regulatory review
  • Experience in financial services involving partner data segregation requirements is desirable
  • Operational experience with PDPA or PDPO is desirable
  • Experience with Microsoft Purview labeling or comparable DLP tools is desirable
  • Experience with access certification tools such as SailPoint, Saviynt, or an equivalent is desirable

Benefits

  • Inclusive, energetic workplace culture
  • Annual leave and public holidays
  • Health insurance budget
  • Opportunity to join a growing global team
  • Flexible remote-work options
  • Budget for home-office equipment
  • Corporate Reap Card with no out-of-pocket spending
  • Access to AI tools

Related Jobs