Graduate Hire 2024/25 - Security Engineer (Technology Governance, Governance support)

Hong Kong, Hong Kong SAR

Applications have closed

OKX

Buy BTC, ETH, XRP and more on OKX, a leading crypto exchange – explore Web3, invest in DeFi and NFTs. Register now and experience the future of finance.

View all jobs at OKX

OKX will be prioritising applicants who have a current right to work in Hong Kong, and do not require OKX's sponsorship of a visa.   If you are interested in more than one Supernova role, please apply to your first preference. We will still consider you for all opportunities.  

Who We Are

At OKX, we believe our future is reshaped with technology. Founded in 2017, OKX is one of the world’s leading cryptocurrency spot and derivatives exchanges. OKX innovatively adopted blockchain technology to reshape the financial ecosystem by offering some of the most diverse and sophisticated products, solutions, and trading tools on the market. Trusted by more than 20 million users in over 180 regions globally, OKX strives to provide an engaging platform that empowers every individual to explore the world of crypto. In addition to its world-class DeFi exchange, OKX serves its users with OKX Insights, a research arm that is at the cutting edge of the latest trends in the cryptocurrency industry. With its extensive range of crypto products and services, and unwavering commitment to innovation, OKX vision is a world of financial access backed by blockchain and the power of decentralized finance.   We invest in our people as much as we invest in technology. We are united by our engaging culture, here we win as a team, embrace changes, and do the right thing. We are committed to creating a friendly, rewarding and diverse environment for OKers. It doesn’t matter where you come from, here everyone feels valued, respected and has the same opportunities to develop and thrive — we want to bring out the best in you.  

About OKX Graduate Program (Supernova)

The Supernova Program is a 3-year Career Accelerator Program that aims to fast-track, high performing graduates into technical experts and future leaders mainly in the fields of Product Engineering, Product Management, and Product Design. We firmly believe in the power of the new era. Join us to achieve your narrative around crypto. As a graduate Security Engineer, you will put in your utmost efforts to ensure security and compliance of the OKX platform with millions of daily active users. You will work cross-functionally with design, product, and other engineering teams to identify and assess security and compliance risks, design and develop advanced security and compliance mechanisms and products, including based on requirements identified in collaboration with risk, compliance or legal teams. This is an opportunity to learn the full security and compliance life cycle of crypto and Web3 platforms and work along with a rapidly growing technology governance team ensuring the leading industry best practices on security and compliance are implemented.  

What You’ll Be Doing

  • Designing, developing, and maintaining the organization's information security management system across all domains, including but not limited to infrastructure management, application management, data management.
  • Designing security and compliance controls to meet the requirements of best practices in application security, infrastructure security as well as regulatory compliance, and to coordinate with engineers to implement them.
  • Conducting security and control gap assessments, risk assessments and audits.
  • Developing and maintaining high-quality technical, security and organizational documentation, including policies, standard operating procedures, standards and guidelines.
  • Upholding security and technology best practices. Improving efficiency in cross-office/time zone collaboration.
  • Collaborate with team members and functional stakeholders to meet control requirements to demonstrate organizational security compliance.
  • Communicate and bridge the gap between external regulatory or audit requirements and internal stakeholder operations.
 

What We Look For In You

  • Bachelors in Computer Science, Information Systems, Technology, Engineering, or related technical disciplines.
  • Solid knowledge of information security principles, control design, and implementation.
  • Holistic risk assessment skills to break down complex infrastructural and procedural issues to its basic principles for effective and controllable solutions.
  • Compliance first mindset. Ability to lead by example for internal and external stakeholders. Highlight organizational best practices and embrace our We Before Me principle.
  • Analytical with a positive problem-solving mindset, a proactive team player who embodies a growth mindset, flexible, and comfortable in navigating ambiguity with a global mindset. Able to manage multiple concurrent projects of different workloads, timelines and deadlines.
  • Eager to develop in an organization with rapidly maturing technology and security posture.
  • Proficiency in speaking, reading and writing in both English and Mandarin.
 

Nice to Haves

  • Knowledgeable in the relevant tech stack skillset for the respective specialization - relational databases, OS, networking, encryption and cryptography, identity and access management, change management / SDLC, cloud service architecture.
  • Familiarity with the cloud-based Linux environment. Knowledgeable in distributed architecture. Understanding of kubernetes or container orchestration architecture.
  • Familiarity with Java/Python/Go, and with daily developing tools such as npm, gulp, webpack, git.
  • Alibaba Cloud and AWS knowledge and certifications are a strong plus.
  • Familiarity with information security risk management and compliance frameworks and reporting standards (i.e. ISO 27001, NIST CSF, SOC 2 Common Criteria, CSA STAR).
  • Familiarity with security and IT risk certifications from recognized bodies such as ISACA, ISC2, CompTIA, CSA (e.g.: CISA, CISSP, CCSP, CCSK) is a strong plus.
  • Proficiency in Cantonese.
 

Perks & Benefits

  • Competitive total compensation package
  • L&D programs and Education subsidy for employees' growth and development
  • Various team building programs and company events
  • Wellness and meal allowances
  • Comprehensive healthcare schemes for employees and dependants
  • More that we love to tell you along the process!

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  4  1  0

Tags: Application security Audits AWS Blockchain CCSK CCSP CISA CISSP Cloud Compliance CompTIA Computer Science Crypto Cryptography Encryption Finance Governance IAM ISACA ISO 27001 Java Kubernetes Linux NIST Python RDBMS Risk assessment Risk management SDLC SOC SOC 2

Perks/benefits: Career development Competitive pay Startup environment Team events Wellness

Region: Asia/Pacific
Country: Hong Kong

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.