About the company
Coins is the most established crypto brand in The Philippines and has gained the trust of more than 18 million users. Through the easy-to-use mobile app, users can buy and sell a variety of different cryptocurrencies and access a wide range of financial services. Coins is fully regulated by the Bangko Sentral ng Pilipinas (BSP) and is the first ever crypto-based company in Asia to hold both Virtual Currency and Electronic Money Issuer licenses from a central bank.
Job Summary
What you will do
šDefine, manage and update company's information security policies, standards, and processes in coordination with different business functions to protect infrastructure, business-critical data and customer information šEnsure policies are consistently applied across company and monitor adherence to the defined governance principles to ensure expected value is delivered šServe as a SME on information security regulations and advise employees and management on information security requirement and recommendations šPlan and deliver security awareness trainings and other awareness activities to the companyās employees šDevelop and enhance relationships with Business and Technology stakeholders to understand current challenges and establish a GRC framework to manage risk and compliance levels šCoordinate and execute IT / IS risk assessments and reviews, providing risk-based recommendation and track the implementation of risk mitigation to completion šWork with Tech team to develop and test IT business contingency and disaster recovery plans šLiaise directly with Compliance and various backend Technology teams on regulator inspection, regulatory reporting, external audit, security certificate programs, and internal audit projects to assure compliance with financial regulations šCoordinate and perform compliance activities and checks šConduct and manage external security due diligence checks and 3rd security risk management program that covers onboarding to off boarding šCommunicate and report to management, present security risks and recommendations in Risk šManagement Committees (RMC) šManage and track the company overall security program, projects and KPIs against the defined security roadmap and framework
Preferred qualifications:
šBS/MS in Computer Science / Cybersecurity with 5 years and above relevant experience in cyber security or information technology risk management in the banking / financial industry šProven experience in running security compliance programmes šExperience maintaining information security standards and regulations such as NIST CSF, PCI DSS, ISO27001, GDPR, Philippines BSP, MAS TRM and other regulations šExcellent relationship building and communication skills with the ability to engage people from diverse cultures and different levels šStrong stakeholder management skills, with regional experiences to leverage on regional knowledge and resources šExcellent planning and organizational skills with an ability to meet tight deadlines šGood knowledge of cloud computing, networking, OS and its security aspects šProficient in English and Mandarin is a must to communicate with stakeholders from within the organisation šCISSP, CISA, CRISC certifications will be an added advantage