Назад
23 часа назад

Tech Governance - Security Compliance & Governance Engineer (Mandarin Bilingual Required) (AI)

223 611 - 268 333$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Tech Governance - Security Compliance & Governance Engineer (Mandarin Bilingual Required) (AI): Building infrastructure-grade compliance capability through audit remediation, security governance reviews, policy operationalization, and AI-assisted compliance workflows with an accent on regulatory rigor, cross-functional leadership, and crypto-specific governance. Focus on designing evidence collection and control-monitoring workflows, translating regulatory requirements into implementation-ready guidance, and coordinating auditors, regulators, and senior stakeholders.

Location: San Jose, California, United States; hybrid work arrangement

Salary: $223,611–$268,333 per year, plus potential performance bonus, long-term incentives, and benefits.

Company

OKX is a crypto exchange and developer of the OKX Wallet, providing access to crypto trading and decentralized applications for individuals and institutions across more than 50 jurisdictions.

What you will do

  • Lead audit remediation programs by assessing gaps, creating structured plans, and driving verified closure across engineering, product, legal, finance, and operations.
  • Own cross-functional technology governance work streams, milestones, accountability, and blocker removal with limited management oversight.
  • Conduct IT security and architecture governance reviews and issue findings with clear ownership and remediation timelines.
  • Draft, refine, and operationalize IT governance policies and translate regulatory requirements into implementation-ready guidance.
  • Coordinate external auditors and regulators, prepare governance dashboards and executive briefs, and monitor regulatory developments across active jurisdictions.
  • Prototype and scale AI-assisted workflows for evidence collection, control monitoring, audit response, policy generation, and compliance operations.

Requirements

  • 8+ years of experience in IT audit, risk management, compliance, or security governance.
  • 3+ years leading governance programs at a large-scale internet, financial services, or crypto company.
  • Demonstrated ability to lead complex multi-stakeholder work streams independently and influence engineering, legal, finance, and operations without formal authority.
  • Daily practical use of AI tools, including experience building or scaling AI-assisted compliance and governance workflows, plus working knowledge of AI governance and risk.
  • Deep working knowledge of ISO 27001, SOC 1/2, PCI-DSS, COBIT, NIST, GDPR, and APAC data protection regimes.
  • Executive-level English communication and Mandarin proficiency in written and verbal communication are required for the role. Ability to interpret code, architecture diagrams, technical design documents, and cloud security tooling is also expected.

Nice to have

  • Security or governance certifications such as CISA, CISSP, CRISC, CISM, CCISO, or Agentic AI.
  • Experience with AI-powered compliance tooling, audit automation, continuous control monitoring, or policy-to-control mapping.
  • Experience with SOX ITGC, SEC Reg S-K Item 106, Proof of Reserves, SAB 121, Travel Rule, or AML/CFT governance.
  • Experience with regulatory programs involving MAS, VARA, FCA, HKMA/SFC, or equivalent authorities.

Culture & Benefits

  • Fast-moving startup operating style combined with financial-institution standards for accuracy, documentation, and accountability.
  • Learning and development programs and an education subsidy.
  • Team-building programs and company events.
  • Wellness and meal allowances.
  • Comprehensive healthcare coverage for employees and dependents, plus potential performance and long-term incentives.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →