wagey.ggwagey.gg
38,923  jobs38,923  jobs
Browse Tech JobsCompaniesFeaturesPricingFAQs
Log InGet Started Free
Jobs(38,923)/CISO Role(56)/OKX (148) - CISO Office - Security Compliance & Governance Engineer
OKX

OKX - CISO Office - Security Compliance & Governance Engineer

Hong Kong, Hong Kong SAR; Singapore, Singapore1w ago
In OfficeC-levelAPACCryptocurrencyFintechCISOAuditorDocumentationReportingAWSGCPAlibaba CloudRisk ManagementMandarinCircomGovernance

Requirements

• Self-directed driver — You run cross-functional workstreams without being managed. Ambiguity is a starting point, not a blocker. • Self-directed driver • AI-native operator — You already use AI to do more, faster — and you raise the floor for the teams around you. • AI-native operator • Clear communicator — You earn trust across regulators, auditors, and C-suite through precision and consistency — in any room. • Clear communicator • Culture Fit • Startup velocity — Decisions move fast. Priorities shift. You ship, iterate, and adapt — without waiting for perfect conditions or top-down direction. • Startup velocity • Financial institution rigour — Audit trails matter. Regulators scrutinise. The bar for accuracy, documentation, and accountability is institutional-grade — always. • Financial institution rigour • > The tension between these two is not a bug — it is the job. We are looking for someone who holds both without compromise. • Active daily use of AI tools to accelerate compliance and governance work — demonstrated practice with measurable output impact, not theoretical awareness. • Ability to identify, build, and scale AI-assisted workflows within a CISO office context — evidence automation, policy generation, audit response, or control monitoring. • Working knowledge of AI governance and risk — sufficient to contribute to internal AI oversight frameworks and assess AI-related compliance obligations. • Independent Cross-Functional Leadership — Must Have • Demonstrated ability to own and drive complex, multi-stakeholder workstreams independently — setting direction, coordinating accountability, and delivering outcomes without management escalation. • Track record of influencing without authority across engineering, legal, finance, and operations in a fast-moving environment. • Comfortable operating under ambiguity and shifting priorities while maintaining institutional-grade standards for accuracy and documentation. • 8+ years in IT audit, risk management, compliance, or security governance • 3+ years leading governance programmes at a large-scale internet, financial services, or crypto firm • Exposure to IPO-readiness or high-scrutiny regulatory examination programmes preferred • Frameworks & Standards • ISO 27001, SOC 1/2, PCI-DSS, COBIT, NIST — deep working knowledge • GDPR and APAC data protection regimes • Crypto and blockchain-specific compliance risk awareness a strong asset • Engineering Sensibility • Able to read and interpret code, architecture diagrams, and technical design documents without engineer-translation dependency • Familiarity with cloud environments (Alibaba Cloud, AWS, GCP) and associated security tooling • Communication • Executive-level written and verbal communication in English — board-ready governance briefs, regulator responses, and CISO-level reporting produced independently • Proficiency in Mandarin (written and verbal) is a strong advantage for APAC regulatory and stakeholder engagement • Professional security or governance certification: CISA · CISSP · CRISC · CISM · CCISO · Agentic AI • CISA · CISSP · CRISC · CISM · CCISO · Agentic AI • Experience building AI-powered compliance tooling — audit automation, continuous control monitoring, or policy-to-control mapping • Prior involvement in SOX ITGC, SEC Reg S-K Item 106, or equivalent listing-authority tech governance programmes • Crypto-native compliance exposure — Proof of Reserves, SAB 121, Travel Rule, AML/CFT programme governance • Active regulatory footprint across MAS, VARA, FCA, HKMA/SFC, or equivalent

Responsibilities

• Independently lead audit remediation programmes — assess gaps, develop structured plans, and drive verified closure across engineering, product, legal, and operations without escalation dependency. • Own cross-functional governance workstreams — set milestones, coordinate accountability, and remove blockers across departments with limited management oversight. • Conduct IT security and architecture governance reviews — assess whether systems and processes meet applicable standards, and issue findings with clear ownership and remediation timelines. • Build and maintain the policy estate — draft, refine, and operationalise IT governance policies and procedures; translate regulatory requirements into implementation-ready guidance for first-line teams. • Lead regulator and auditor engagement — serve as the primary coordination interface for external audit and regulatory correspondence, representing the CISO Office with credibility and precision. • Deploy AI to accelerate compliance operations — prototype and scale AI-assisted workflows for evidence collection, control monitoring, audit response, and policy generation; drive team-wide adoption. • Deliver CISO-level reporting — produce governance dashboards and executive briefs on remediation status, risk exposure, and regulatory posture, independently and to publication standard. • Track the regulatory horizon — monitor evolving requirements across active jurisdictions, translate changes into prioritised internal action, and brief senior leadership proactively. • What We Look For In You

Benefits

• OKX operates across 50+ jurisdictions with live regulatory programmes spanning MAS, VARA, FCA, HKMA/SFC, and a US presence targeting NYSE listing by 2027. The CISO Office is building infrastructure-grade compliance capability — not checkbox compliance. This is a rare opportunity to shape how that work gets done: independently, at pace, and with AI at the centre of the method. • L&D programs and Education subsidy for employees' growth and development • Various team building programs and company events • Wellness and meal allowances • Comprehensive healthcare schemes for employees and dependants • More that we love to tell you along the process! • OKX Statement: • OKX Statement:

Apply in one click

Upload My Resume

Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT

Apply in One Click
Apply in One Click

Similar roles

RainRain - CISO5mo ago
·Remote - New York, NY, USA·$200k - $270k/year + Equity
RemoteNAC-levelFintechLife InsurancePaymentsInsuranceCISOAuditorRisk ManagementB2BGovernanceReporting
AirwallexAirwallex - Manager, Internal Audit (Technology)5mo ago
·Singapore
In OfficeAPACSeniorBankingPaymentsFintechAuditorLoan OfficerReportingRisk ManagementGCPGovernanceDocumentation
NiumNium - Manager – Internal Audit4mo ago
·Chennai - Hybrid·Equity
In OfficeAPACSeniorBankingCybersecurityFintechAuditorReportingTeam ManagementRisk ManagementCPAGovernance
AlpacaAlpaca - Head of Information Security2mo ago
·Remote - Japan·$27k - $27k/year + Equity
RemoteAPACDirectorFintechCybersecurityHead of Information SecurityAuditorRisk ManagementReportingBrexCircomGovernance
M0M0 - Head of Security & Risk1w ago
·Remote - USA·Equity
RemoteNADirectorCryptocurrencyFintechHead of SecurityAuditorB2BTechnical WritingProgram ManagementReportingAWSAzureGCPDocumentationDue DiligenceCircomRisk Management
PlaudPlaud - Security Engineer, Infra & Operations - Singapore1mo ago
·Singapore·Equity
In OfficeAPACSeniorCloud ComputingArtificial IntelligenceSecurity EngineerAuditorAWSGCPTerraformGovernanceReporting
KrakenKraken - SOX Auditor1mo ago
·Remote - Ireland, United Kingdom, Canada·$104k - $104k/year
RemoteEMEASeniorCryptocurrencyFintechAuditorCPAReportingTeam LeadershipChange ManagementGCP
NethermindNethermind - Zero Knowledge/Cryptography Auditor4mo ago
·Remote - Singapore
RemoteAPACJuniorCryptocurrencyCybersecurityAuditorNoirZero-KnowledgeCircomRustPerformance Reviews
salmon-groupsalmon-group - GRC Manager (PCI-DSS Focus)1w ago
·European Union·$324k - $324k/year
In OfficeEMEASeniorBankingFintechGeneral ManagerAuditorDocumentationAWSJiraConfluenceReportingCircomGovernance

Browse more by category

Show 56 moreCISOShow 132 moreAuditorShow 5,632 moreDocumentationShow 8,372 moreReportingShow 3,747 moreAWSShow 1,526 moreGCPShow 7 moreAlibaba CloudShow 1,044 moreRisk ManagementShow 270 moreMandarinShow 63 moreCircom
Privacy·Terms··Contact·FAQ·Wagey on X