
Tech Governance - Security Compliance & Governance Engineer
at OKX
Posted 13 hours ago
No clicks
- Compensation
- Not specified
- City
- Country
- Not specified
Currency: Not specified
**Tech Governance - Security Compliance & Governance Engineer** leads our enterprise-wide security initiatives, driving secure infrastructure by managing complex compliance processes. **Familiar with GRC tools** like RSA Archer and Napalm, possess **10+ years** of relevant experience, and **proven ability** to improve security posture. **Anticipate and mitigate risks** in **multi-cloud environments** and **collaborate across teams**.
Who We Are
About the Opportunity
Who You Are
- Self-directed driver — You run cross-functional workstreams without being managed. Ambiguity is a starting point, not a blocker.
- AI-native operator — You already use AI to do more, faster — and you raise the floor for the teams around you.
- Clear communicator — You earn trust across regulators, auditors, and C-suite through precision and consistency — in any room.
Culture Fit
| Pace | Standards |
| Startup velocity — Decisions move fast. Priorities shift. You ship, iterate, and adapt — without waiting for perfect conditions or top-down direction. | Financial institution rigour — Audit trails matter. Regulators scrutinise. The bar for accuracy, documentation, and accountability is institutional-grade — always. |
What You’ll Be Doing
- Independently lead audit remediation programmes — assess gaps, develop structured plans, and drive verified closure across engineering, product, legal, and operations without escalation dependency.
- Own cross-functional governance workstreams — set milestones, coordinate accountability, and remove blockers across departments with limited management oversight.
- Conduct IT security and architecture governance reviews — assess whether systems and processes meet applicable standards, and issue findings with clear ownership and remediation timelines.
- Build and maintain the policy estate — draft, refine, and operationalise IT governance policies and procedures; translate regulatory requirements into implementation-ready guidance for first-line teams.
- Lead regulator and auditor engagement — serve as the primary coordination interface for external audit and regulatory correspondence, representing the Tech Governance Office with credibility and precision.
- Deploy AI to accelerate compliance operations — prototype and scale AI-assisted workflows for evidence collection, control monitoring, audit response, and policy generation; drive team-wide adoption.
- Deliver Tech Governance-level reporting — produce governance dashboards and executive briefs on remediation status, risk exposure, and regulatory posture, independently and to publication standard.
- Track the regulatory horizon — monitor evolving requirements across active jurisdictions, translate changes into prioritised internal action, and brief senior leadership proactively.
What We Look For In You
AI Adoption & Application — Must Have
- Active daily use of AI tools to accelerate compliance and governance work — demonstrated practice with measurable output impact, not theoretical awareness.
- Ability to identify, build, and scale AI-assisted workflows within a Tech Governance office context — evidence automation, policy generation, audit response, or control monitoring.
- Working knowledge of AI governance and risk — sufficient to contribute to internal AI oversight frameworks and assess AI-related compliance obligations.
Independent Cross-Functional Leadership — Must Have
- Demonstrated ability to own and drive complex, multi-stakeholder workstreams independently — setting direction, coordinating accountability, and delivering outcomes without management escalation.
- Track record of influencing without authority across engineering, legal, finance, and operations in a fast-moving environment.
- Comfortable operating under ambiguity and shifting priorities while maintaining institutional-grade standards for accuracy and documentation.
Experience
- 8+ years in IT audit, risk management, compliance, or security governance
- 3+ years leading governance programmes at a large-scale internet, financial services, or crypto firm
- Exposure to IPO-readiness or high-scrutiny regulatory examination programmes preferred
Frameworks & Standards
- ISO 27001, SOC 1/2, PCI-DSS, COBIT, NIST — deep working knowledge
- GDPR and APAC data protection regimes
- Crypto and blockchain-specific compliance risk awareness a strong asset
Engineering Sensibility
- Able to read and interpret code, architecture diagrams, and technical design documents without engineer-translation dependency
- Familiarity with cloud environments (Alibaba Cloud, AWS, GCP) and associated security tooling
Communication
- Executive-level written and verbal communication in English — board-ready governance briefs, regulator responses, and Tech Governance-level reporting produced independently
- Proficiency in Mandarin (written and verbal) is a strong advantage for APAC regulatory and stakeholder engagement
Preferred Qualifications
- Professional security or governance certification: CISA · CISSP · CRISC · CISM · CCISO · Agentic AI
- Experience building AI-powered compliance tooling — audit automation, continuous control monitoring, or policy-to-control mapping
- Prior involvement in SOX ITGC, SEC Reg S-K Item 106, or equivalent listing-authority tech governance programmes
- Crypto-native compliance exposure — Proof of Reserves, SAB 121, Travel Rule, AML/CFT programme governance
- Active regulatory footprint across MAS, VARA, FCA, HKMA/SFC, or equivalent
Why This Role
Perks & Benefits
- Competitive total compensation package
- L&D programs and Education subsidy for employees' growth and development
- Various team building programs and company events
- Wellness and meal allowances
- Comprehensive healthcare schemes for employees and dependants
- More that we love to tell you along the process!
