Назад
6 часов назад

Technology and Security Risk Director (Cybersecurity)

Формат работы
onsite
Тип работы
fulltime
Грейд
director
Английский
b2
Страна
Singapore
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Technology and Security Risk Director (Cybersecurity): Developing and scaling second-line technology and security risk oversight across a crypto exchange, with an accent on risk governance, control assessments, cyber resilience, and technical security controls. Focus on challenging first-line controls, assessing incidents and architecture evidence, monitoring KRIs, and driving remediation with engineering and security teams.

Location: Singapore, Singapore

Company

OKX is a crypto exchange and developer of OKX Wallet, OKLink, and decentralized crypto applications serving retail users and institutional customers.

What you will do

  • Develop and scale the second-line Technology and Security Risk oversight program.
  • Identify, assess, escalate, and mitigate technology and security risks with Engineering, Product, Risk, Compliance, and Internal Audit stakeholders.
  • Oversee technology and security incidents, issues, defects, and remediation activities with first-line teams.
  • Lead the second-line Technology Risk and Control Self-Assessment process and challenge first-line security risks and controls.
  • Define, monitor, and report Security Key Risk Indicators, while enhancing GRC systems and risk management frameworks.
  • Track emerging risks and regulatory developments in the digital asset sector.

Requirements

  • 8+ years of information security experience with a strong security architecture or technical security background.
  • Experience designing, implementing, or reviewing cloud, IAM, cryptographic, network, or application security controls.
  • Ability to threat-model systems and assess architecture diagrams, IAM policies, logging configurations, and dependencies.
  • Knowledge of cloud resilience, multi-region and availability-zone failover, RTO/RPO, and disaster recovery testing.
  • Working knowledge of NIST CSF, ISO 27001, SOC 2, GDPR, and PDPA as applied to technical controls.
  • Strong communication and stakeholder management skills, with a relevant degree or equivalent practical experience.

Nice to have

  • Fintech, crypto, or cloud-native experience.
  • Experience with GRC platforms.
  • CISSP, CCSP, CISA, CISM, or cloud security and architecture qualifications.

Culture & Benefits

  • Learning and development programs with an education subsidy.
  • Team-building programs and company events.
  • Wellness and meal allowances.
  • Comprehensive healthcare schemes for employees and dependants.
  • Competitive total compensation package.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →