Overview
Head Of Security (VATP) Jobs in Hong Kong, Hong Kong SAR at DFX Labs
Title: Head Of Security (VATP)
Company: DFX Labs
Location: Hong Kong, Hong Kong SAR
Job Overview: Head of Security will be responsible for leading the security team and continue to fortify the security framework for the virtual asset exchange. Define and implement security policies, security measures, monitoring/alerts, workflows, and collaborate across teams to protect virtual assets, sensitive data, ensure compliance, counter potential security threats and educate internal staff and external clients to promote security awareness.
Job Description:
· Establish and maintain corporate security policies tailored to the specific needs of the virtual asset exchange.
· Manage security incidents, ensure controls are in place to mitigate risks and communicate to senior management and relevant stakeholders
· Collaborate and guide the internal IT teams, service providers, and business stakeholders to enhance defense against cyber-attacks and internal threats.
· Embed cybersecurity throughout SDLC cycle with threat modelling, security requirements, secure coding standards, code reviews, security testing, ensuring security-by-design principles application.
· Enforce zero-trust principles with continuous verification, segmentation, least-privilege access, encrypted communications, eliminating implicit trust across network and application layers.
· Oversee regular security reviews and assessments, focus on the protection of virtual assets, client data and security of internal and external facing systems.
· Proactively initiate risk analysis to identify and mitigate specific security risks to virtual assets and trading systems.
· Promote security best practices for the virtual asset exchange, such as security awareness training, organizing simulated phishing campaigns, and emergency drills.
Requirements:
· At least 10 years of experience in IT security or technical risk management, ideally with a background in virtual assets service provider or fintech.
· Bachelor’s degree in Information Security, Cybersecurity, Data Privacy, Information Technology or related fields.
· Strong communication skills, able to effectively interact with senior management, auditors, regulators and non-technical personnel.
· Familiarity with security and data privacy standards such as ISO27001, ISO27701, NIST, GDPR, as well as security practices related to digital currency.
· Familiarity with Hong Kong regulations and laws related to cybersecurity, data privacy, data protection, AML/KYC would be a plus.
· Relevant security certifications such as OSCE3, OSCP, CISSP, CISM, CISA, CBSP.
· Familiarity in block chain technology, cryptocurrencies, crypto-targeting APT tactics using MITRE ATT&CK framework and corresponding testing detection is a plus.
· Proficient in written and spoken English and Chinese (Mandarin and Cantonese).
We offer a competitive remuneration package, generous annual leave entitlement, medical insurance and a premium working environment for our top talents. We encourage you to apply for this opportunity now. Only shortlisted candidates will be contacted for an interview.
Please apply via LinkedIn OR send your profile to "[email protected]" for considerations. Only shortlisted candidate will be contacted for interviews. Thank you.