Senior Manager, Digital Trust & Controls Assurance Audit; Cybersecurity SME
Listed on 2026-01-12
-
IT/Tech
Cybersecurity, Blockchain / Web3, Data Security, Information Security
Who We Are
At OKX, we believe that the future will be reshaped by crypto, and ultimately contribute to every individual's freedom. OKX is a leading crypto exchange, and the developer of OKX Wallet, giving millions access to crypto trading and decentralized crypto applications (dApps). OKX is also a trusted brand by hundreds of large institutions seeking access to crypto markets. We are safe and reliable, backed by our Proof of Reserves.
Across our multiple offices globally, we are united by our core principles:
We Before Me, Do the Right Thing, and Get Things Done. These shared values drive our culture, shape our processes, and foster a friendly, rewarding, and diverse environment for every OK-er. OKX is part of OKG, a group that brings the value of Blockchain to users around the world, through our leading products OKX, OKX Wallet, OKLink and more.
OKX is undertaking a significant global team buildout, and we are looking for an experienced and visionary Senior Manager of Cybersecurity Audit to lead this critical function. This is a unique opportunity to shape the cybersecurity audit landscape within a leading crypto organization, ensuring the highest levels of security and compliance for our global operations. You will drive strategic initiatives, and directly impact the security posture of innovative crypto products and infrastructure.
We are seeking a seasoned cybersecurity audit professional with demonstrable experience in the crypto exchange or crypto product space. The ideal candidate will possess a deep understanding of cybersecurity and audit principles applied to novel technical and control environments, with strong analytical skills. Ability to work effectively across timezones given the global nature of the organization and the audit team.
What You’ll Be Doing- Drive the execution of global Information Security audit programs, ensuring comprehensive coverage and adherence to best practices.
- Oversee IT incident validations and provide critical support for group-wide IT certifications.
- Collaborate effectively with functional and regional portfolio leads to provide expert IT security controls testing support for integrated audits.
- Develop and implement advanced audit methodologies tailored to the unique complexities of blockchain technology, crypto exchanges, and decentralized systems.
- Provide strategic guidance and insights on emerging cybersecurity risks and controls in the cryptocurrency space to senior leadership.
- Strong Critical Thinking and Problem-Solving
Skills:
Capacity to analyze complex, often novel, technical and control environments unique to crypto, identify intricate root causes of issues, and propose effective, context-specific solutions. - Fundamental Understanding of Blockchain Technology: Basic knowledge of distributed ledger technologies, consensus mechanisms (e.g., PoW, PoS), cryptography (hashing, public-key), and the lifecycle of a cryptocurrency transaction.
- Data Analytics/SQL for Deep Security Analysis: Proficiency in querying and analyzing large volumes of security logs, blockchain transaction data, wallet addresses, vulnerability scan outputs, penetration test results, and threat intelligence feeds to identify sophisticated attack patterns, anomalies, and potential illicit activities unique to crypto.
- Security Auditing and Compliance: Deep understanding of common cybersecurity frameworks (e.g., NIST CSF, ISO 27001) applied within the unique risk context of a crypto exchange. Ability to assess compliance with emerging crypto‑specific security standards and regulatory guidance.
- Vulnerability Assessment & Penetration Testing (VAPT) Interpretation & Oversight for Crypto Assets: Ability to plan, scope, interpret, and assess the remediation effectiveness of VAPTs specifically targeting blockchain infrastructure, smart contracts, exchange platforms, and wallet security.
- Incident Response & Forensics for Crypto Incidents: Expertise in incident response life cycles and forensic investigation techniques specifically tailored for crypto incidents (e.g., fund misappropriation, smart contract exploits, private key compromises, denial‑of‑service…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).