Who We Are
About the Opportunity
What You’ll Be Doing
-
Collaborate with internal stakeholders across the company to proactively identify, escalate, assess, and mitigate Technology and Security risks, ensuring adherence to the Technology Risk Policy.
-
Providing oversight of Technology and Security Risk incidents and issues, and partnering with 1LOD stakeholders to enhance related processes and ensure effective oversight
-
Lead the Technology Risk and Control Self-Assessment (RCSA) process from a 2LOD perspective, ensuring adherence to the ERM RCSA methodology, and providing effective challenge and oversight of 1LOD Security risks and controls.
-
Support the Security Key Risk Indicators (KRIs) definition, monitoring, and reporting.
-
Supporting the implementation and ongoing enhancement of Governance, Risk, and Compliance (GRC) systems to enable effective risk oversight
-
Advocate and support the implementation of Risk Management frameworks for technology stakeholders, serving as a trusted advisor for the first line.
-
Stay up to date on emerging trends and regulations in the digital asset space, proactively identifying and addressing new risk considerations.
What We Look For In You
-
Bachelor’s degree in Information Technology, Computer Science, or a related field
-
Minimum 8+ years of experience in Cyber Risk or Information Security; experience in fintech, crypto, blockchain, or cloud-native environments is preferred
-
Strong understanding of core cybersecurity domains and tools
-
Solid knowledge of cybersecurity and data risk frameworks and standards, including NIST Cybersecurity Framework (CSF), ISO/IEC 27001, and data privacy and protection regulations (e.g., GDPR, PDPA)
-
Proven track record in project and stakeholder management, including independently conducting risk-control assessments, control testing, incident/issue management, and driving remediation efforts
-
Experience working with Governance, Risk, and Compliance (GRC) platforms in a global or complex organizational setting
-
Excellent communication and presentation skills, with the ability to convey technical and risk concepts clearly to a range of audiences
-
Strong interpersonal skills and the ability to collaborate effectively across functions and geographies
-
Comfortable working in a dynamic, fast-paced environment, with a proactive mindset for piloting initiatives and refining them over time
-
Relevant certifications such as CISSP, CEH, CISA, CISM, or other recognized cybersecurity qualifications
Perks & Benefits
-
Competitive total compensation package
-
L&D programs and Education subsidy for employees' growth and development
-
Various team building programs and company events
-
Wellness and meal allowances
-
Comprehensive healthcare schemes for employees and dependants
- More that we love to tell you along the process!
Disclaimer: Please note that Hong Kong is a group-level service hub, and OKX does not carry on a business of operating a virtual asset trading platform in Hong Kong.
#LI-CZ1
#LI-ONSITE
