Logo

Security Governance Specialist

OKX
Hong Kong
Full time

Overview

Department

IT

Job type

Full time

Compensation

Salary not specified

Location

Hong Kong, East Asia

Company size

Mature [ 50+ employess ]

Resume Assistance

See how well your resume matches this job role with our AI-powered score. By uploading your resume, you agree to our Terms of Service

Ready to apply?

You're one step away - it takes less than a minute to upload your resume

The Security Governance Specialist will enhance the organization's technology and security posture by serving as the primary interface between business and engineering teams. This role focuses on uplifting security controls and ensuring compliance with regulatory requirements.

Requirements

  • Bachelor’s degree in Information Security, Computer Science, Risk Management, or a related field
  • 7+ years of relevant experience in cybersecurity, tech risk management, compliance, and security governance.
  • Strong knowledge of regulatory frameworks and standards such as ISO 27001, NIST CSF, PCI-DSS, SOC1/2, and CCSS.
  • Familiarity with data protection laws and regulations (e.g., GDPR) and compliance challenges posed by emerging technologies.
  • Proven ability to manage large-scale security control implementation or compliance remediation projects, and track progress effectively.
  • Excellent project management skills for handling multiple complex remediation plans simultaneously.
  • One or more certifications such as CISSP, CISA, CISM, CRISC, or CCSS are highly desirable.
  • Knowledge of cloud platforms like Alibaba Cloud, AWS, and GCP, including their security-related services.
  • Adaptability to work in rapidly evolving technological and regulatory environments.
  • Fluent in both Chinese and English with excellent oral and written communication skills.
  • Outstanding communication skills for engaging with auditors, regulators, and cross-functional teams across all organizational levels.
  • Responsibilities

  • Develop and maintain IT governance-related policies and procedures, ensuring alignment with industry standards and regulatory requirements.
  • Monitor and evaluate the organization’s security compliance status, proposing actionable improvements.
  • Collaborate with business units, engineering teams, risk, compliance, and other stakeholders to implement governance measures and enable secure technical processes.
  • Conduct security maturity self-assessments and risk assessments to identify gaps and drive remediation efforts.
  • Ensure compliance with regulatory requirements across jurisdictions through gap analyses and advisory support.
  • Create dashboards and reports for leadership on governance effectiveness, security metrics, and key updates.
  • Stay informed on industry trends to refine governance strategies and enhance security maturity.
  • Drive continuous improvement in governance processes by collaborating with cross-functional teams.
  • Benefits

  • Competitive total compensation package.
  • L&D programs and Education subsidy for employees' growth and development.
  • Various team building programs and company events.
  • Wellness and meal allowances.
  • Comprehensive healthcare schemes for employees and dependants.
  • © All rights reserved.