At a Glance
- Tasks: Lead security audits, enforce policies, and manage compliance in the crypto industry.
- Company: Join OKX, a top crypto exchange reshaping finance with innovative solutions.
- Benefits: Enjoy flexible training budgets, team-building events, and comprehensive healthcare schemes.
- Why this job: Be part of a vibrant community driving change in finance and technology.
- Qualifications: 5+ years in cybersecurity or GRC; certifications like CISSP are a plus.
- Other info: We value diverse backgrounds and support your growth within our dynamic team.
The predicted salary is between 43200 - 72000 £ per year.
At OKX, we believe that the future will be reshaped by crypto, and ultimately contribute to every individual\’s freedom. OKX is a leading crypto exchange, and the developer of OKX Wallet, giving millions access to crypto trading and decentralized crypto applications (dApps). OKX is also a trusted brand by hundreds of large institutions seeking access to crypto markets. We are safe and reliable, backed by our Proof of Reserves. Across our multiple offices globally, we are united by our core principles: We Before Me , Do the Right Thing , and Get Things Done . These shared values drive our culture, shape our processes, and foster a friendly, rewarding, and diverse environment for every OK-er. About the Opportunity Are you ready to make your mark in the dynamic world of cryptocurrency and web3? Join our global team as a Security GRC Manager and become a pivotal player in an industry that\’s shaping the future of finance and technology. As a leader in cryptocurrency exchange and web3 solutions, we operate on a global scale, continuously expanding into new markets and forging strategic partnerships with high-profile brands like McLaren F1, Manchester City Football Club, and top-tier athletes across snowboarding and golf. In this exciting role, you\’ll spearhead external audits, craft and enforce policies, conduct compliance checks, and oversee risk and control self-assessments. Your expertise will be instrumental in managing issues, ensuring risk is within appetite and providing support to our regional CISOs, while also reporting into our global security function. You\’ll be at the forefront of our efforts to maintain the highest standards of security and compliance in a rapidly evolving landscape. Everything we do is guided by our 3 Core Values: We before me, Do the right thing, and Get things done. At our core, we are driven by innovation, collaboration and a passion for pushing boundaries. We believe in investing in our team\’s growth, which is why everyone has an allocated training budget and the freedom to design their own training programme. We\’re not just a company; we\’re a vibrant community with a cool brand and a fun, dynamic work environment. Here, you\’ll find the perfect blend of cutting-edge technology, world-class partnerships and a culture that celebrates creativity and excellence. Join us, and be part of something truly extraordinary. Transform the way the world thinks about finance and technology, and take your career to new heights. What You’ll Be Doing As a Security GRC Manager, you will play a crucial role in ensuring the security and compliance of our global operations. Your responsibilities will include: Staying Informed: Keeping up to date with the latest developments in laws, regulations, policies and information security standards related to Cyber Security, Data Security and Data Protection. ISMS Maintenance: Ensuring timely updates and maintenance of our internal Information Security Management System (ISMS). Validating and verifying that the organisation\’s security controls meet industry requirements. Certifications: Lead planning and execution of information security certifications for our products, including ISO 27001, SOC 2 and PCI. Compliance Advocacy: Advocating for and overseeing the implementation of security compliance and privacy protection requirements, ensuring overall quality and consistency. Issue Resolution: Promptly addressing and rectifying any non-compliant items. Conducting thorough reviews of processes, systems, policies, procedures, architectures and controls frameworks, identifying the associated issues and tracking them to remediation. Stakeholder Relationships: Develop and maintain collaborative working relationships with management, understand the business to provide value-added services and establish credibility as an internal consultant and controls effectiveness resource. Partner with engineering and product teams to advise on security requirements at design and implementation stages. What We Look For In You About you: Proactive Attitude: You\’re a self-starter who takes initiative and drives projects to completion. Excellent Communicator: You excel at communicating complex ideas clearly and effectively, both verbally and in writing. Collaboration & Relationship-Building Skills: You thrive in a team environment, working collaboratively with colleagues across various functions and regions. You understand and respect different perspectives and are able to build strong relationships. Problem-Solving Mindset: You approach challenges with creativity and a positive attitude, always looking for solutions. Attention to Detail: You have a keen eye for detail, ensuring thoroughness and accuracy in your work. Adaptability: You\’re flexible and open to change, able to pivot quickly in a fast-paced, dynamic environment. Commitment to Learning: You are dedicated to personal and professional growth, taking advantage of training opportunities. Integrity and Trustworthiness: You uphold the highest standards of integrity and transparency in your work. Experience: Relevant Work Experience: Minimum of 5 years experience in information security, cyber security, technology risk, or a related field, preferably with a focus on governance, risk and compliance (GRC). Certifications: Professional certifications such as CISSP, CISM, CISA, or equivalent are advantageous, but not essential. Regulatory Knowledge: Demonstrated experience with industry standards and frameworks such as ISO 27001, SOC, PCI-DSS, GDPR and other relevant regulations is desirable. Audit and Assessment: Proven track record of conducting or defending successful security audits, compliance assessments and risk management activities. Technical Expertise: Hands-on experience with information security management systems, controls frameworks and risk & control self assessments, particularly in cloud environments as we are a cloud-native business. Policy Development: Experience in writing and maintaining information security policies, procedures and documentation. While these experiences and qualifications are highly desirable, we understand that no candidate will fulfill every requirement. If you have a strong foundation in cyber security and GRC, along with a passion for learning and collaboration, we encourage you to apply. We value diverse backgrounds and perspectives, and we\’re committed to supporting your growth and development within our team. L&D programs and Education subsidy for employees\’ growth and development. Various team building programs and company events. Comprehensive healthcare schemes for employees and dependents Apply for this job #J-18808-Ljbffr
Security GRC Manager employer: OKX
Contact Detail:
OKX Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Security GRC Manager
✨Tip Number 1
Familiarise yourself with the latest trends and regulations in cybersecurity and data protection. This will not only help you in interviews but also demonstrate your proactive attitude and commitment to staying informed, which is highly valued by OKX.
✨Tip Number 2
Network with professionals in the cryptocurrency and cybersecurity fields. Attend relevant conferences or webinars to connect with industry experts and gain insights that could set you apart during the hiring process.
✨Tip Number 3
Showcase your problem-solving mindset by preparing examples of how you've tackled compliance challenges in previous roles. Be ready to discuss specific situations where your creativity led to effective solutions.
✨Tip Number 4
Research OKX's core values and think about how your personal values align with theirs. Be prepared to discuss how you embody these principles in your work, as cultural fit is crucial for them.
We think you need these skills to ace Security GRC Manager
Some tips for your application 🫡
Tailor Your CV: Make sure to customise your CV to highlight relevant experience in information security, cyber security, and governance, risk, and compliance (GRC). Use keywords from the job description to demonstrate that you meet the specific requirements of the Security GRC Manager role.
Craft a Compelling Cover Letter: Write a cover letter that showcases your proactive attitude and problem-solving mindset. Mention specific examples of how you've successfully managed compliance issues or led security audits in the past, aligning your experiences with OKX's core values.
Highlight Relevant Certifications: If you have certifications like CISSP, CISM, or CISA, be sure to mention them prominently in your application. Even if they are not essential, they can set you apart from other candidates and show your commitment to the field.
Showcase Your Communication Skills: Since excellent communication is key for this role, provide examples in your application that demonstrate your ability to convey complex ideas clearly. This could be through previous roles where you collaborated with cross-functional teams or presented findings to stakeholders.
How to prepare for a job interview at OKX
✨Understand the Company Culture
Before your interview, take some time to research OKX's core values: 'We Before Me', 'Do the Right Thing', and 'Get Things Done'. Be prepared to discuss how your personal values align with theirs and provide examples of how you've embodied these principles in your previous roles.
✨Showcase Your Technical Expertise
As a Security GRC Manager, you'll need to demonstrate your knowledge of information security standards and frameworks like ISO 27001 and SOC. Be ready to discuss your hands-on experience with these systems and how you've successfully implemented them in past positions.
✨Prepare for Scenario-Based Questions
Expect questions that assess your problem-solving skills and ability to handle compliance issues. Prepare specific examples from your experience where you identified risks, implemented controls, or resolved non-compliance situations effectively.
✨Highlight Your Communication Skills
Effective communication is key in this role. Be prepared to explain complex security concepts in simple terms, as you'll need to collaborate with various teams. Practice articulating your thoughts clearly and concisely, both verbally and in writing.