Security Compliance Manager

OKX
San Jose, California, US
Full-time

OKX Buy BTC, ETH, XRP and more on OKX, a leading crypto exchange explore Web3, invest in DeFi and NFTs. Register now and experience the future of finance.

OKX is revolutionising world systems through our cutting-edge digital asset exchange, Web3 portal and blockchain ecosystems.

We are deeply committed to shaping a fairer, more transparent and accessible society through blockchain technology and to date, we have 50+ million users, 3000+ employees and 180+ countries believing in the same vision as us.

We are safe and reliable, backed by our Proof of Reserves.

All potential applicants are encouraged to scroll through and read the complete job description before applying.

About the Opportunity

As the Security Compliance Manager, you will stay abreast of the latest developments in laws, regulations, policies, and information security standards related to Network Security, Data Security, and Data Protection.

Ensure timely updates and maintenance of the internal information security management system. Apply for information security certifications such as ISO 27001, SOC, and PCI for our products.

Advocate for and oversee the implementation of security compliance and privacy protection requirements. Promptly address and rectify any non-compliant items.

Validate and verify that the organization's security controls meet industry requirements. Conduct thorough examinations of processes, systems, policies, procedures, network diagrams, and system configurations.

Monitor business activities through collaborating with cross-functional team leaders to guarantee ongoing compliance with external certifications.

What You’ll Be Doing

Technology Audit Delivery : Lead planning and execution of operational audit programs and complex technology control assessments : Information Security, Infrastructure, Emerging Technologies (AI / ML, FinTech).

Leverage data analytics to detect risk signals and unearth insights. Communicate issues and recommendations to management.

  • Integrated Audit Delivery : Lead planning and execution of integrated audits supporting operations and technology for business functions and productions (Trust & Safety, Monetization, FinTech etc.).
  • Technology Risk Assessment : Assist in analysis and identification of emerging technology risks for OKX. Develop and maintain subject matter expertise in one or more technology domains.
  • Stakeholder Relationships : Develop and maintain collaborative working relationships with management, understand the business to provide value-added services, and establish credibility as a management consultant and internal controls resource.

Partner with engineering and product teams to advise on design and implementation of technology solutions.

Professional Development : Continually expand knowledge of the audit profession, industry, and company products through self-study, research, and continuing education efforts.

Develop innovative methodologies for auditing new technologies and services.

Quality Assurance : Ensure the overall quality and consistency of audit work, adhering to department and professional standards.

Continuously seek opportunities for audit process improvement.

What We Look For In You

  • 5 + years of relevant experience in managing ISO 27001 : 2022, SOC 2 audits, and compliance programs within a global organizational setting.
  • Demonstrate extensive knowledge and hands-on experience with cybersecurity frameworks, such as ISO 27001, PCI-DSS, SOC 2, and other relevant regulatory requirements.
  • Exhibit excellent communication skills and logical reasoning abilities.
  • Maintain a composed demeanor, showcasing a robust commitment to continuous learning and a collaborative, team-oriented mindset.
  • Display self-driven and results-oriented attributes, enjoy challenging tasks, demonstrate a genuine enthusiasm for work, and work well under pressure.

Experience :

Relevant experience in Technology Audit, Risk Management, CyberSecurity Compliance or Engineering preferably within the technology sector (Social Media, eCommerce, Fintech etc.

and / or Big4 consulting.

  • Portfolio Management : Demonstrated experience managing a portfolio of audits, with concurrent oversight and execution of multiple projects.
  • Integrated Audits : Experience managing integrated audits that address a combination of financial / operational and technology objectives.
  • Industry experience : Proven ability to work in a fast-paced environment with a product centric culture. Experience of working at a startup company or tech / fintech company is a plus.

About you :

  • Professional interests : Passion for emerging technologies, products and standards. Strong critical thinking skills combined with the ability to provide a credible technical challenge to the business.
  • Analytical skills : Proven analytical ability to assess complex technology environments against risk assessment outcomes, industry best practices, internal standards and external regulatory requirements.
  • Communication skills : Ability to write at a publication quality level in order to communicate findings and recommendations to the senior management team.
  • Global Experience : Experience working in a global organization and managing projects across different time zones (America and EMEA).

Nice to Haves

  • Experience in ISO management systems, SOC audits, and PCI certification is preferred.
  • Possess an understanding of the California Consumer Privacy Act (CCPA) and Technology Risk Management Guidelines.
  • Relevant industry certifications such as CISM, CISA, CISSP are preferred.
  • Experience in compliance for virtual currency trading platforms, particularly in obtaining licenses in the United States, Europe, Hong Kong, Singapore, or Dubai.

Highlights of Perks and Benefits

  • Competitive total compensation package
  • L&D programs and Education subsidy for employees' growth and development
  • Various team building programs and company events

OKX Statement

The base salary range for this position is $198,765 to $238,518. The salary offered depends on a variety of factors, including job-related knowledge, skills, experience, and market location.

In addition to the salary, a performance bonus and long-term incentives may be provided as part of the compensation package, as well as a full range of medical, financial, and / or other benefits, dependent on the position offered.

OKX is committed to equal employment opportunities regardless of race, color, genetic information, creed, religion, sex, sexual orientation, gender identity, lawful alien status, national origin, age, marital status, and non-job related physical or mental disability, or protected veteran status.

Pursuant to the San Francisco Fair Chance Ordinance, we will consider employment-qualified applicants with arrest and conviction records.

J-18808-Ljbffr

12 days ago
Related jobs
Promoted
TikTok
Mountain View, California

As a Technical Security and Compliance Engineering Program Manager, you will be the technical compliance partner who will proactively drive implementation of compliance requirements in relation to strategic planning, new feature release and technology architecture modifications for cross-functional ...

Promoted
Zededa
San Jose, California

Security and Compliance Manager. ZEDEDA is seeking an experienced and highly motivated Security and Compliance Manager to join our team. In this role, you will be responsible for developing, managing, and implementing security and compliance policies and procedures. Develop, execute, and maintain se...

Promoted
OKX
San Jose, California

As the Security Compliance Manager, you will stay abreast of the latest developments in laws, regulations, policies, and information security standards related to Network Security, Data Security, and Data Protection. Advocate for and oversee the implementation of security compliance and privacy prot...

Promoted
Cybertec, Inc
San Jose, California

Experience with FEDRAMP, NIST, Zero Trust Architecture, SecOps, SaaS, and Cloud Computing Compliance. ...

Promoted
Tesla
Fremont, California

Tesla is looking for an IT Security and Compliance Manager to join our Global Risk and Compliance team. Vehicle Cybersecurity Compliance:Maintain meticulous compliance with vehicle cybersecurity regulations (UNECE 155/156, ISO 21434). You will help run the risk and compliance efforts to design, eval...

ZEDEDA
San Jose, California

Develop, execute, and maintain security policies and procedures for compliance. Cyber Security, Information Security, or related field experience. Experience managing security compliance audits of cloud environments is a plus. Reviewing the security practices of different products and ensuring compl...

TikTok
San Jose, California

The Security Governance, Risk, and Compliance team is responsible for working closely with cross-functional partners to manage security risks to ensure we meet all industry cybersecurity compliance standards and government regulations through developing governing policies, implementing the security ...

ICE Consulting
Milpitas, California
Remote

The SOC & Compliance Manager will oversee incident response, threat monitoring, security operations, and ensure adherence to regulatory and industry compliance standards. Security Operations Center (SOC) and ensure compliance with relevant regulations, industry standards, and security frameworks...

ICE Consulting
Milpitas, California

The SOC & Compliance Manager will oversee incident response, threat monitoring, security operations, and ensure adherence to regulatory and industry compliance standards. Security Operations Center (SOC) and ensure compliance with relevant regulations, industry standards, and security frameworks. Th...

TikTok
Mountain View, California

You will join our Technical Security Compliance team within our Tech and Product team; the team plays a pivotal role in enabling our organization to adhere to regulatory, compliance and security requirements, building and maintaining robust compliance practices, and facilitating change effectively. ...