Security Governance Engineer
7 days ago
Join to apply for the Security Governance Engineer role at OKX At OKX, we believe that the future will be reshaped by crypto, and ultimately contribute to every individual's freedom. OKX is a leading crypto exchange, and the developer of OKX Wallet, giving millions access to crypto trading and decentralized crypto applications (dApps). OKX is also a trusted brand by hundreds of large institutions seeking access crypto markets. We are safe and reliable, backed by our Proof of Reserves. Across our multiple offices globally, we are united by our core principles: We Before Me, Do the Right Thing, and Get Things Done. These shared values drive our culture, shape our processes, and foster a friendly, rewarding, and diverse environment for every OK-er. OKX is part of OKG, a group that brings the value of Blockchain to users around the world, through our leading products OKX, OKX Wallet, OKLink and more. Responsibilities Security Architecture Review: Conduct comprehensive security architecture assessments for new and existing systems using Threat Modeling methodologies to identify structural vulnerabilities before they go live. AI & MCP Security Assessment: Evaluate the security posture of Artificial Intelligence implementations, specifically focusing on MCP integrations, LLM interactions, and AI Agent permissions to prevent prompt injection, unauthorized data access, and excessive agency. Access Control Assessment: Evaluate permission control mechanisms across enterprise systems to identify over-provisioning and control deficiencies. Cloud Infrastructure Review: Audit cloud platform configurations and overall architecture to detect potential security vulnerabilities. Data Flow Analysis: Evaluate technical safeguards during critical data flows to uncover leakage risks. Technical Governance & Solution Design AI Governance Framework: Design security standards and guardrails for AI adoption, ensuring that MCP servers, AI clients, and data connectors adhere to strict authentication and authorization policies. Remediation Framework Design: Design technical remediation plans and long-term governance frameworks based on identified issues. IAM Optimization: Design optimization paths for IAM systems based on the Principle of Least Privilege (PoLP). Data Protection Strategy: Formulate technical control strategies for sensitive data across its entire lifecycle. Tool Evaluation: Evaluate and integrate security technologies into the overall security architecture. Cross-Functional Collaboration: Work with technical teams to drive effective implementation of security remediations. Verification Testing: Design and execute technical verification tests (e.g., penetration testing) to confirm remediation effectiveness. Tracking Mechanism: Establish a tracking mechanism for security improvements and potential regression risks. Continuous Review & Reporting: Regularly review projects and consolidate results into strategic reports. Requirements Bachelor’s degree or higher in Computer Science, Information Security, or related fields. 5+ years of experience in security technology or operations, with a strong background in security governance and architecture. Familiarity with large-scale enterprise IT environments, multi-cloud/hybrid cloud models, and modern AI technology stacks. Proficiency in performing Security Architecture Reviews and Threat Modeling (e.g., STRIDE, PASTA); ability to dissect complex microservices and distributed systems. Deep understanding of AI/LLM security risks, including secure design of MCP, RAG architectures, and AI Agent sandboxing. Proficient in cloud security architecture (AWS, Alibaba Cloud). Strong understanding of identity protocols (RBAC, OAuth, ABAC) and their integration. Technical knowledge of DLP, encryption, and data masking best practices. Capability in Python/Shell scripting and familiarity with security tools (SIEM, WAF, etc.). Soft Skills Analytical Thinking: Outstanding problem discovery skills for both traditional and emerging (AI) systems. Communication: Ability to articulate technical security requirements to cross-functional teams. Project Management: Excellent ability to coordinate resources and drive remediation projects. Business Acumen: Ability to balance security requirements with business innovation. Drive & Resilience: Proactive, patient, and capable of maintaining efficiency under pressure. Benefits & Perks L&D programs and Education subsidy for employees' growth and development. Various team building programs and company events. Wellness and meal allowances. Comprehensive healthcare schemes for employees and dependants. #J-18808-Ljbffr
-
Security Governance Engineer
5 days ago
Hong Kong Island, Hong Kong SAR China P2P Full timeWho We Are At OKX, we believe that the future will be reshaped by crypto, and ultimately contribute to every individual's freedom. OKX is a leading crypto exchange, and the developer of OKX Wallet, giving millions access to crypto trading and decentralized crypto applications (dApps). OKX is also a trusted brand by hundreds of large institutions seeking...
-
Security Governance Architect — AI
7 days ago
Hong Kong Island, Hong Kong SAR China OKX Full timeA leading crypto exchange located in Hong Kong is seeking a Security Governance Engineer. This role involves conducting security assessments, implementing governance frameworks, and ensuring compliance with security standards. Ideal candidates have a background in security governance and architecture, with over 5 years of relevant experience. Join us to...
-
Senior Security Systems Engineer
5 days ago
Hong Kong Island, Hong Kong SAR China BluOcean Security Pte Ltd Full timeA leading security solutions provider in Hong Kong is seeking a Senior Technical Engineer with at least 2 years of experience in systems engineering. The role involves maintaining and optimizing security systems, executing planned preventative maintenance, and supporting investigations into system failures. Candidates should have extensive knowledge of...
-
Security Technical Engineer
5 days ago
Hong Kong Island, Hong Kong SAR China BluOcean Security Pte Ltd Full time1. Be proactive in ensuring the security systems are operating optimally. 2. Undertake planned and reactive services to the ’s security systems. The schedule will be agreed at the beginning of each year. 3. Undertake Planned Preventative Maintenance (PPMs) across the Estate covering all assets and systems assigned to them. 4. PPMs are to be completed to an...
-
SailPoint IAM Engineer
1 week ago
Hong Kong Island, Hong Kong SAR China MIGSO-PCUBED Full timeA leading consulting firm in Hong Kong is seeking a Cybersecurity Engineer to focus on identity governance and access management. The ideal candidate will have robust experience with SailPoint IdentityIQ and a solid understanding of IAM concepts. Responsibilities include implementing identity solutions, monitoring security incidents, and ensuring compliance...
-
IT Security Governance
5 days ago
Hong Kong Island, Hong Kong SAR China Global Talent Services Limited Full timeA recruitment agency is seeking an IT Security Governance Officer for a contract position with a large bank in Hong Kong. This role involves strengthening IT security governance, establishing security standards, and managing audit remediation actions. Ideal candidates possess a degree in IT or related fields and have at least 2 years of experience in IT...
-
Lead, Credit Risk Management
18 hours ago
Hong Kong Island, Hong Kong SAR China Lead, Credit Risk Management (Policy and Governance) Full timeLead, Credit Risk Management (Policy and Governance) Mox is built by and for the ones who aspire to live life to the fullest – we call them Generation Mox! The name Mox reflects the endless opportunities we can create, - Mobile e Why Mox Everything at Mox – from our products, features, to rewards – is designed based on customer research, tailor made...
-
IT Security Governance Officer
5 days ago
Hong Kong Island, Hong Kong SAR China CLPS Technology (Hong Kong) Co., Limited Full timeResponsibilities Assist IT Security Governance team to strengthen IT Security of the bank to improve oversight of technology and cybersecurity risk and support the rapid Fintech initiatives. Assist in independent assessment with external assessor for critical IT projects. Assist the Key Risk Indicator (KRI) monitoring and reporting. Review technology...
-
Security Governance Architect for AI
5 days ago
Hong Kong Island, Hong Kong SAR China P2P Full timeA leading crypto exchange in Hong Kong is seeking a Security Risk Assessment Expert with strong skills in security architecture, AI risk knowledge, and cloud security. The role involves assessments, governance design, and collaboration across teams to ensure security remediations. Successful candidates will have at least 5 years of industry experience and a...
-
Government IT Security Auditor
5 days ago
Hong Kong Island, Hong Kong SAR China PERSOL Full timeA recruitment agency is seeking candidates for a role in a government department in Hong Kong. The ideal applicant will provide IT assistance, conduct security audits, and maintain security projects. Required qualifications include a High Diploma or Degree in Computer Science and relevant IT experience. This position entails review and implementation of...