Назад
Company hidden
16 часов назад

Lead Security Management Engineer (Cryptocurrency)

Формат работы
remote (только Indonesia/Malaysia)
Тип работы
fulltime
Грейд
lead
Английский
c1
Страна
Indonesia/Malaysia
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Lead Security Management Engineer (Cryptocurrency): Maintaining information security compliance systems for a global cryptocurrency exchange with an accent on regulatory cooperation, audit readiness, and local ISMS alignment. Focus on performing risk assessments, preparing technical evidence, managing access controls, and coordinating remediation across technical and non-technical teams.

Location: Jakarta, Indonesia or Kuala Lumpur, Malaysia

Company

hirify.global is a cryptocurrency exchange and digital financial platform serving users across more than 200 countries and regions.

What you will do

  • Support regulatory inspections and remote reviews involving OJK, Bappebti, Kominfo, and other local agencies.
  • Explain information security architecture, controls, and current system status to regulators and prepare audit evidence, including architecture and data-flow documentation.
  • Maintain the local compliance system and align it with the headquarters ISMS framework, including gap analysis, documentation, and certification or licensing support.
  • Conduct information security threat and risk assessments, maintain risk registers, and review access-control permissions.
  • Coordinate security incident response, awareness training, supplier security evaluations, third-party risk management, penetration testing, and vulnerability scanning.
  • Track regulatory and audit remediation activities, coordinate internal stakeholders, and ensure timely closure and reporting.

Requirements

  • 4–5 years of experience in information security, compliance, or a related field.
  • Experience with regulatory reception or audit support; experience involving OJK, Bappebti, or Kominfo is preferred.
  • Knowledge of ISO 27001, SOC 2, NIST, or equivalent information security frameworks.
  • Experience with gap analysis, threat and risk assessment, compliance documentation, access control, incident response, and security awareness training.
  • Fluent spoken and listening Chinese and English, with strong written communication skills. Indonesian language skills are preferred.
  • Strong cross-functional coordination, communication, documentation, and organizational skills.

Nice to have

  • Background in financial technology, cryptocurrency, or financial services.
  • CISA, CISSP, ISO 27001 Chief Auditor, ISO 27001 Chief Implementer, or equivalent certification.
  • Experience working with multinational companies and headquarters compliance teams.

Culture & Benefits

  • Study Growth Fund supporting professional development and continuous learning.
  • Team-building activities, workshops, and internal events.
  • Collaboration with an international team across global locations.
  • Career advancement and internal mobility opportunities.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →