11 дней назад
Chief Information Security Officer (Digital Assets)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Chief Information Security Officer (Digital Assets): Building and governing Spark’s cybersecurity framework for a regulated digital-asset platform with an accent on SFC compliance, ISO/IEC 27001 alignment, and crypto infrastructure security. Focus on leading independent assessments, incident readiness, Zero-Trust architecture, vendor risk management, and securing wallet, MPC, HSM, and blockchain systems.
Location: Hong Kong SAR; on-the-ground presence in Hong Kong required
Company
operates a global cryptocurrency exchange and digital financial platform covering trading, payments, wealth management, custody, institutional services, and Web3.
What you will do
- Serve as the primary cybersecurity lead for Spark, working with responsible officers and MIC-IT to design, implement, and evidence the cybersecurity framework.
- Prepare for, facilitate, and complete SFC-mandated pre-launch independent cybersecurity assessments, remediating findings before go-live.
- Architect, deploy, and govern security controls aligned with ISO/IEC 27001, SFC guidelines, and best practices for network, application, and endpoint security.
- Develop and test Cyber Incident Response Plans and Disaster Recovery/Business Continuity Plans, including tabletop exercises.
- Establish continuous monitoring, penetration testing, vulnerability scanning, threat intelligence, and Zero-Trust architecture.
- Lead security culture, employee awareness training, third-party vendor risk management, and security communication with the Board, executives, and regulators.
Requirements
- Relevant Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related technical discipline; a Master’s degree is preferred.
- Active professional cybersecurity certification such as CISSP, CISM, CISA, or CRISC.
- 10+ years of experience in cybersecurity, risk management, or IT audit, including 3–5 years in senior security leadership or Head of Information Security roles within financial services.
- Direct experience navigating Hong Kong SFC VASP/VATP Type 1 and Type 7 license applications from a cybersecurity perspective.
- Hands-on experience securing digital-asset infrastructure, including hot, cold, and warm wallets, MPC, HSMs, and node networks.
- Exceptional written and verbal English communication skills; Mandarin fluency is a strong plus.
Nice to have
- Cloud security, offensive security, or blockchain and smart-contract security certifications, such as CCSP or OSCP.
- Fluency in Mandarin.
Culture & Benefits
- Supportive, fast-moving environment focused on innovation, collaboration, and user-first product development.
- Study Growth Fund for professional development and continuous learning.
- Internal team-building events, workshops, and collaboration activities.
- International collaboration with colleagues across global markets.
- Career advancement and internal mobility opportunities.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →