Jobs › Singapore › Technology and Security Risk Director
Technology and Security Risk Director
OKX is hiring for the job of Technology and Security Risk Director, Singapore (On-site). This is a Risk job in the governance, risk, and compliance field. Review the full details below and apply directly with OKX.
ace-line old-record-id- ace-line old-record-id- ace-line old-record-id- ace-line old-record-id- ace-line old-record-id- ace-line old-record-id- ace-line old-record-id- ace-line old-record-id- ace-line old-record-id- ace-line old-record-id- ace-line old-record-id- Who We Are
ace-line old-record-id- At OKX, we believe that the future will be reshaped by crypto, and ultimately contribute to every individual s freedom.
ace-line old-record-id- OKX is a leading crypto exchange, and the developer of OKX Wallet, giving millions access to crypto trading and decentralized crypto applications (dApps). OKX is also a trusted brand by hundreds of large institutions seeking access to crypto markets. We are safe and reliable, backed by our Proof of Reserves.
ace-line old-record-id- Across our multiple offices globally, we are united by our core principles: We Before Me, Do the Right Thing, and Get Things Done. These shared values drive our culture, shape our processes, and foster a friendly, rewarding, and diverse environment for every OK-er.
ace-line old-record-id- OKX is part of OKG, a group that brings the value of Blockchain to users around the world, through our leading products OKX, OKX Wallet, OKLink and more.
ace-line old-record-id-
ace-line old-record-id- About the Opportunity
ace-line old-record-id- We are seeking a highly motivated Technology and Security Risk Manager within the Second Line of Defence (2LOD). You will be responsible for continuously refining and scaling the Technology and Security oversight program, guiding first-line of defence (1LOD) execution, and providing independent risk challenge.
ace-line old-record-id- You will be a key member of OKX s Risk team, helping to shape and scale the firm’s 2LOD Security and Data Risk programs. You’ll work closely with stakeholders including Engineering, Product, Risk, Compliance and Internal Audit.
ace-line old-record-id- You will play a key role in developing and implementing a comprehensive Technology and Security Risk Management program. This includes 2LOD oversight of technology defects, issues, and incidents, Risk and Control Self-Assessments (RCSA), key risk indicators (KRIs) and reporting.
ace-line old-record-id- The ideal candidate has a strong understanding of Technology Risk (including Technology Resilience, Change Management, SDLC, CI/CD pipeline, and software quality assurance) and Cybersecurity (covering internal and external threat vectors, control weaknesses, and organisational cyber hygiene). We are looking for a candidate with a strong drive for improvement and career growth.
ace-line old-record-id- What You’ll Be Doing
ace-line old-record-id- Collaborate with internal stakeholders across the company to proactively identify, escalate, assess, and mitigate Technology and Security risks, ensuring adherence to the Technology Risk Policy.
ace-line old-record-id-JdzVdUfNyoaKYGxAjmJlCpbjgpd Providing oversight of Technology and Security Risk incidents and issues, and partnering with 1LOD stakeholders to enhance related processes and ensure effective oversight
ace-line old-record-id- Lead the Technology Risk and Control Self-Assessment (RCSA) process from a 2LOD perspective, ensuring adherence to the ERM RCSA methodology, and providing effective challenge and oversight of 1LOD Security risks and controls.
ace-line old-record-id- Support the Security Key Risk Indicators (KRIs) definition, monitoring, and reporting.
ace-line old-record-id- Supporting the implementation and ongoing enhancement of Governance, Risk, and Compliance (GRC) systems to enable effective risk oversight
ace-line old-record-id- Advocate and support the implementation of Risk Management frameworks for technology stakeholders, serving as a trusted advisor for the first line.
ace-line old-record-id- Stay up to date on emerging trends and regulations in the digital asset space, proactively identifying and addressing new risk considerations.
ace-line old-record-id- What We Look For In You
ace-line old-record-id- 8+ years in information security, with a strong security architecture or technical security background; fintech, crypto or cloud-native experience preferred.
ace-line old-record-id- Practical experience designing, implementing or reviewing cloud, IAM, cryptographic, network or application security controls.
ace-line old-record-id- Experience in risk oversight, or readiness to transition, with the technical judgement to challenge controls and recommend proportionate improvements.
ace-line old-record-id- Ability to threat-model systems and assess technical evidence, including architecture diagrams, IAM policies, logging configurations and dependencies.
ace-line old-record-id- Working knowledge of cloud resilience, multi-region/AZ failover, RTO/RPO and disaster recovery testing.
ace-line old-record-id- Familiarity with NIST CSF, ISO 27001, SOC 2 and relevant privacy requirements, including GDPR and PDPA, and their application to technical controls.
ace-line old-record-id- Ability to independently assess and test controls, evaluate incidents and drive remediation with engineering and security teams; GRC platform experience desirable.
ace-line old-record-id- Clear written and verbal communication, translating technical findings into prioritised actions for business stakeholders and governance committees.
ace-line old-record-id- Strong stakeholder management skills, providing constructive challenge and collaborating across functions and geographies.
ace-line old-record-id- A proactive, adaptable approach, with confidence taking ownership and improving practices in a fast-paced environment.
ace-line old-record-id- A relevant degree or equivalent practical experience; CISSP, CCSP, cloud security/architecture, CISA or CISM qualifications desirable.
ace-line old-record-id- Perks and Benefits
ace-line old-record-id- Competitive total compensation package
ace-line old-record-id- L and D programs and Education subsidy for employees growth and development
ace-line old-record-id- Various team building programs and company events
ace-line old-record-id- Wellness and meal allowances
ace-line old-record-id- Comprehensive healthcare schemes for employees and dependants
ace-line old-record-id- More that we love to tell you along the process!
span span span Notice:
span span All official span text-with-abbreviation text-with-abbreviation-bottomline OKX span vacancies are published on this website. span span While roles may appear on selected third-party platforms from time to time, information on other sites may be inaccurate or outdated. strong span span If in doubt, please apply directly through our official careers website.
span span Information collected and processed as part of the recruitment process of any job application you choose to submit is subject to span text-with-abbreviation text-with-abbreviation-bottomline OKX span s a rich-text-anchor __anchor-intercept-flag__ text-content-link Candidate Privacy Notice span span.
Certifications this role asks for
Studying for one of these? Try the free CISA practice questions or the free CISM practice questions in our academy. No signup, no cost.
Location and market context
This job is based in Singapore on-site. Local candidates benefit from being close to OKX's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.
About risk management jobs
Risk jobs own the methodology for identifying, assessing, and escalating enterprise, operational, and technology risk. Second-line teams set risk appetite and challenge the first line. Jobs like this one are typically evaluated against frameworks such as enterprise and operational risk frameworks, NIST AI RMF, and risk-appetite and escalation practices.
How to position yourself for this risk management job
Strong candidates emphasize risk assessment methodology, appetite and escalation, cross-functional partnership, and clear reporting to senior leadership and the board. In your resume and outreach, tie your experience to how OKX would apply enterprise and operational risk frameworks, NIST AI RMF, and risk-appetite and escalation practices, and lead with concrete outcomes rather than duties.
Similar GRC jobs
- Product Manager / Director, Trading Risk (Parameter Management & Price Protection) · OKX · Singapore
- Senior Manager, Merchant Risk Operations, APAC [Relocation to Singapore] · Airwallex · Singapore, SG
- CRO - Credit Risk Officer-(Wealth Management) - Associate · Deutsche Bank · Singapore, One Raffles Quay
- Senior Manager, Merchant Risk Operations, APAC · Airwallex · Singapore, SG
- Chief Risk Office – Market Risk Manager (Metals) – VP · Deutsche Bank · Singapore, One Raffles Quay
- User Safety & Risk Operations Analyst - Global Response (Weekend Shift) · Openai · Singapore
- Head of Strategic Risk Programs, New Markets · Stripe · Singapore
- Senior Security Risk Engineer · Gitlab · Canada · Remote
More jobs at OKX
- Senior Fraud Risk Manager · OKX · New York
- Head of Risk - Türkiye · OKX · Istanbul, Türkiye
- Deputy Head of Compliance – Malta · OKX · EMEA
- Compliance Analyst · OKX · Istanbul, Türkiye
- Senior Audit Manager, Apac · OKX · Singapore
- Senior Compliance Analyst · OKX · São Paulo, Brazil
More GRC jobs in Singapore
- Data Governance Analyst | Banking · Capco · Singapore
- Data Governance Specialist | Banking · Capco · Singapore
- Senior Product Manager, AI Risk & Onboarding · Airwallex · Singapore, SG
- Senior Manager, Strategy & Operations, Regulatory & Compliance · Airwallex · Singapore, SG
- Senior AI Engineer (Risk & Payments) · Airwallex · Singapore, SG
- C&AFC – Private Bank Compliance – Vice President · Deutsche Bank · Singapore, One Raffles Quay
Hiring for Risk?
Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.
Post a job Pricing from $99 · About GRC Careers · Hiring toolkit
Want to be next in a job like this?
Jobs like Technology and Security Risk Director in Singapore open regularly. Be first to know, privately. No current employer ever sees you looking.
Employer, or see something wrong with this posting? Report this posting and we will review it promptly.