Staff/Senior Data Security and Governance Engineer(Technology Governance and Compliance)

3 days ago


Hong Kong, Central and Western District, Hong Kong SAR China Tbwa ChiatDay Inc Full time
Staff/Senior Data Security and Governance Engineer (Technology Governance and Compliance)

Hong Kong, Hong Kong SAR

Who We Are

At OKX, we believe that the future will be reshaped by Crypto, ultimately contributing to every individual's freedom. OKX began as a crypto exchange, giving millions of people access to crypto trading and has become one of the largest platforms in the world. We have developed one of the most connected Web3 wallets used by millions to access decentralized crypto applications (dApps). OKX is a trusted brand by hundreds of large institutions seeking access to crypto markets on a reliable platform that seamlessly connects with global banking and payments. In the last year, OKX has expanded into new markets including Australia, Brazil, Netherlands, Singapore, and Turkey, with plans to launch in the US, Belgium, and the UAE. We are committed to shaping a fairer, more transparent, and accessible society through blockchain technology.

About the Team

The Technology Governance team provides security advice and guidance to OKX entities across all coverage areas, supporting business growth by working with all teams within the company. This team collaborates closely with compliance and legal teams to interpret global requirements for licensing and regional compliance.

About the Opportunity

Security breaches are the number one cause of death amongst digital currency companies. Security is core to our mission and a key competitive differentiator as we scale.

As a Security Engineer on the Technology Governance & Compliance team, you will lead and manage multiple initiatives to mature OKX security programs globally. You will pitch, lead, and participate in cross-functional initiatives that enhance the security of all OKX products and services. This role works horizontally across the business to provide guidance for the design and implementation of key security controls, tools, and technologies.

What You'll Be Doing
  • Analyze and assess security and compliance gaps identified by internal and external audits.
  • Develop and execute remediation plans and solutions for audit findings.
  • Coordinate with relevant departments to implement problem fixes and governance measures.
  • Conduct IT security and architecture governance to ensure compliance with relevant standards and regulations.
  • Track remediation progress and report to management on governance work progress and effectiveness.
  • Develop and refine IT governance-related policies and procedures (P&P) and provide implementation guidance.
  • Communicate with external auditors and regulators, coordinating audit work.
  • Continuously monitor and evaluate the company's security compliance status, proposing improvement suggestions.
  • Stay up-to-date on industry trends and best practices to drive continuous improvement of the company's security compliance capabilities.
What We Look For In You
  • At least 8 years of relevant work experience, including IT audit, risk management, compliance, and security governance.
  • In-depth understanding of various audit standards such as ISO 27001, COBIT, SOC2, SOC1, PCI-DSS, and NIST.
  • Familiarity with relevant laws and regulations, including industry-specific norms and data protection regulations (e.g., GDPR).
  • Excellent project management skills, able to manage multiple complex audit finding remediation plans simultaneously.
  • Outstanding communication and coordination abilities, capable of effectively interacting with stakeholders at all levels.
  • Strong analytical and problem-solving skills, able to handle complex security compliance challenges.
  • At least 3 years of experience in IT process governance and technology governance projects within large internet enterprises.
  • Familiarity with specific risks and compliance requirements in large internet enterprises or blockchain companies.
  • Adaptability and flexibility to work in a rapidly changing technological and regulatory environment.
  • Knowledge of cyber security/cloud security/coding and related processes, such as change management, incident response, and computer forensics.
Nice to Haves
  • One or more of the following certifications: CISA, CISSP, CRISC, CISM, or equivalent qualifications.
  • Knowledge of Alibaba Cloud, AWS, GCP, and their related services (e.g., SLS/DMS).
  • Familiarity with risks and compliance challenges brought by emerging technologies (such as AI, blockchain).
  • Experience in successfully participating in large-scale security compliance remediation projects.
  • Fluent in both Chinese and English, with excellent oral and written communication skills.
Benefits

L&D programs and education subsidy for employees' growth and development. Various team building programs and company events. Wellness and meal allowances. Comprehensive healthcare schemes for employees and dependants.

#J-18808-Ljbffr

  • Hong Kong, Central and Western District, Hong Kong SAR China ConnectedGroup Full time

    ConnectedGroup, a world-class operator of public services, seeks an experienced Senior Data Governance Manager to lead the development and implementation of a robust data governance framework.This framework will align with industry best practices and regulatory requirements. As the Senior Data Governance Manager, you will be responsible for establishing and...


  • Hong Kong, Central and Western District, Hong Kong SAR China ConnectedGroup Full time

    Job DescriptionWe are seeking an experienced Senior Data Governance Manager to lead the development and implementation of a robust data governance framework. This framework will align with industry best practices and regulatory requirements.As the Senior Data Governance Manager, you will be responsible for establishing and leading an enterprise-wide data...


  • Hong Kong, Central and Western District, Hong Kong SAR China Tbwa ChiatDay Inc Full time

    Compliance and Governance SpecialistWe are looking for a Compliance and Governance Specialist to provide guidance on the design and implementation of key security controls, tools, and technologies. As a member of the Technology Governance & Compliance team, you will work closely with cross-functional teams to enhance the security of all OKX products and...


  • Hong Kong, Central and Western District, Hong Kong SAR China Tbwa ChiatDay Inc Full time

    Data Security Governance LeadAt OKX, we strive to create a secure and transparent environment for our users. As a Data Security Governance Lead, you will be responsible for developing and implementing robust security controls to protect our assets and ensure compliance with relevant regulations. Your expertise in IT risk management and compliance will help...


  • Hong Kong, Central and Western District, Hong Kong SAR China ConnectedGroup Full time

    We are seeking an experienced Senior Data Governance Manager to join our team at ConnectedGroup.The ideal candidate will have a deep understanding of data governance frameworks, principles, and best practices.Responsibilities include developing and implementing a comprehensive data governance strategy, leading the establishment of a data governance...


  • Hong Kong, Central and Western District, Hong Kong SAR China ConnectedGroup Full time

    Job DescriptionAt ConnectedGroup, we are seeking an experienced Senior Data Governance Manager to lead the development and implementation of a robust data governance framework. This framework will align with industry best practices and regulatory requirements.This role requires a strategic thinker with deep expertise in data governance principles, tools, and...


  • Hong Kong, Central and Western District, Hong Kong SAR China Pinpoint Asia Full time

    About UsAt Pinpoint Asia, we are a leading specialist firm for technology recruitment, headquartered in Hong Kong. Our team of expert tech recruiters has an intimate understanding of the marketplace and a proven ability to deliver results.Job DescriptionWe are seeking a highly skilled Senior IT Governance Specialist to join our team. As a key member of our...


  • Hong Kong, Central and Western District, Hong Kong SAR China Hong Kong Exchanges and Clearing Limited Full time

    Company Overview: Hong Kong Exchanges and Clearing Limited (HKEX) is a world-class exchange group that provides exceptional services to our stakeholders. We connect, promote, and progress our markets and the communities they support for the prosperity of all.About the Role: As a Risk Governance Specialist in our Enterprise Risk Management (ERM) Team, you...


  • Hong Kong, Central and Western District, Hong Kong SAR China Pinpoint Asia Full time

    IT Governance Associate - Insurance Group Our client is a leading insurance group with a sizeable Technology presence in Hong Kong. We are currently looking for an IT Governance Associate to join the firm and look after the IT Control and related IT Compliance matters. This role will work closely with the IT Management team and drive firmwide policy. Great...


  • Hong Kong, Central and Western District, Hong Kong SAR China Hong Kong Maxim's Group Full time

    Manager – Governance & Security, Information Technology (Regional Role)Responsible for driving the company's IT governance and security management frameworks and their ongoing development. Working on reviewing and improving established IT practices and controls, engaging stakeholders for effective implementation, execution, and continuous improvements.Job...


  • Hong Kong, Central and Western District, Hong Kong SAR China Hang Seng Bank Limited Full time

    Company Overview:Hang Seng Bank Limited is committed to service excellence and continually enhances its performance for customers by providing best-in-class products and services.Job Description:We are seeking a high-caliber professional to join our Data and Analytics Office as a Data Manager.The ideal candidate will have experience in managing risk and...


  • Hong Kong, Central and Western District, Hong Kong SAR China FortisHill Consulting Full time

    About Our TeamOur team at FortisHill Consulting is passionate about optimizing IT processes, operation, and fostering innovation. We are looking for a Senior Manager, IT to lead our team in delivering operational excellence.Key ResponsibilitiesDrive productivity and customer satisfaction in local insurance operationsManage project pipelines, ensuring timely...


  • Hong Kong, Central and Western District, Hong Kong SAR China West Kowloon Cultural District Authority Full time

    The West Kowloon Cultural District Authority is seeking a highly skilled and experienced Cyber Security Assistant Manager to join their team. As a key member of the security team, you will be responsible for leading initiatives on the assurance of security and integrity of our information systems, while contributing to the development and implementation of...


  • Hong Kong, Central and Western District, Hong Kong SAR China Hex Trust Full time

    Associate/Senior, IT Governance & Compliance Hex Trust is a fully-licensed and insured digital asset custodian. Led by veteran banking technologists and award-winning financial services experts, Hex Trust has built Hex Safe, a proprietary bank-grade platform that delivers solutions for digital asset protocols, foundations, financial institutions, and the...


  • Hong Kong, Central and Western District, Hong Kong SAR China DBS Bank (Hong Kong) Limited Full time

    As a leading financial institution in Asia, DBS Bank (Hong Kong) Limited relies on Group Strategy, Transformation, Analytics and Research (GSTAR) to drive the implementation of its strategic agenda. Data Management & Governance, an integral part of GSTAR, is responsible for establishing enabling infrastructures, policies, practices, and procedures that...


  • Hong Kong, Central and Western District, Hong Kong SAR China AIA International Limited. Full time

    Role OverviewAIA International Limited is committed to creating a healthier, more sustainable future for everyone. We're seeking an experienced Senior Operations Governance Specialist to oversee quality assurance processes within our insurance operations function. This pivotal role ensures compliance with regulatory standards and internal policies, focusing...


  • Hong Kong, Central and Western District, Hong Kong SAR China PrimePeak Group Full time

    Senior IT Auditor WantedOur client, PrimePeak Group, is seeking a skilled Senior Manager / Director to oversee Tech Risk / Cyber Security functions. The ideal candidate will have expertise in IT governance, cybersecurity frameworks, and digital transformation risks.Responsibilities Include:Leading risk-based assessments to ensure compliance with various...


  • Hong Kong, Central and Western District, Hong Kong SAR China Standard Chartered Life and Careers Full time

    We are seeking a highly experienced Governance, Risk, and Regulatory Expert to join our team. In this role, you will be responsible for highlighting significant matters for the attention of senior management and senior risk committees, and actively participating in key committees through standing membership/attendance.Your key responsibilities will...

  • Cloud Security Engineer

    57 minutes ago


    Hong Kong, Central and Western District, Hong Kong SAR China HKT Full time

    We are seeking a highly motivated and experienced Cloud Security Engineer to join HKT IT Cloud Technology team. In this role, you will be a key contributor to securing our public / private cloud-based environments, ensuring the confidentiality, integrity, and availability of our critical systems and data. You will work closely with infrastructure engineers,...


  • Hong Kong, Central and Western District, Hong Kong SAR China Hex Trust Full time

    About the RoleAs Hex Trust continues to expand its presence in multiple jurisdictions, we are seeking professionals with expertise in IT GRC (Governance, Risk, and Compliance) to support our Information Security Team.Your key responsibilities will include assisting the company in several areas, such as IT Regulatory Affairs, Security Certifications, Policy...