About the company
About OKX OKX is a leading crypto trading app, and a Web3 ecosystem. Trusted by more than 20 million global customers in over 180 international markets, OKX is known for being the fastest and most reliable crypto trading app of choice for investors and professional traders globally. Our Singapore office is a Product and Engineering hub and we are in the progress of expanding our teams in Singapore for the continuous growth of our global business. We build and maintain core trading platform with millions of daily active users. Design, Product and Engineering teams work cross-functionally to identify customer needs, and ship high-quality new features through fast iterations.
Job Summary
Main Responsibilities:
šSecurity Risk Identification and Assessment: šEvaluate the access control mechanisms of enterprise systems from a technical perspective, identifying instances of excessive permissions or control defects. šReview cloud platform configurations and security group policies to identify potential security vulnerabilities and design flaws. šAssess technical protective measures during the transfer process of key enterprise data, identifying data leakage risk points. šInspect the security configurations of various technical platforms and tools to identify gaps in security policy implementation. šEvaluate the effectiveness of endpoint protection technologies, identifying areas where security protection is lacking. šTechnical Governance Plan Design: šDesign technical remediation plans and best practices based on identified issues. šDevelop technical optimization pathways for enterprise permission systems based on the principle of least privilege. šFormulate technical control strategies for data protection to ensure sensitive data is adequately protected at all stages. šDesign security auditing and monitoring schemes to ensure risk points are identified and addressed promptly. šAssess the applicability of various security technologies and tools, recommending solutions that meet enterprise needs. šRemediation Promotion and Verification: šWork closely with technical teams to effectively implement security remediation measures. šDesign and conduct technical verification tests to confirm that remediation measures achieve the desired effects. šEstablish a tracking mechanism for security technological improvements, monitoring the progress and effectiveness of remediations. šRegularly review remediated projects to ensure their long-term effectiveness. šSummarize the results of security governance to form a report on technological security improvements.
Qualifications:
šEducation and Experience: šBachelorās degree or higher in Computer Science, Information Security, or a related technical field. šAt least 5 years of experience in security technology or security operations, with clear experience in security governance. šFamiliarity with the IT environments and security architectures of large enterprises. šTechnical Skills: šA solid foundation in security technologies, understanding common security threats and defense mechanisms. šFamiliarity with cloud security architectures and control mechanisms, with experience using mainstream cloud platforms such as AWS/Alibaba Cloud. šUnderstanding of identity authentication and authorization technologies (such as RBAC, OAuth) and their application in enterprise environments. šKnowledge of data security controls, understanding the workings of DLP, encryption, and other technologies.
The crypto industry is evolving rapidly, offering new opportunities in blockchain, web3, and remote crypto roles ā donāt miss your chance to be part of it.