Incident Response & Prevention Manager

Status
Jakarta, Indonesia
Full time
Hybrid
Compensation is not specified
Role
Security Engineer
Description

The Cybersecurity and Data Privacy team operates within the office of the CISO, under the leadership of Chief Information Security Officer, Jason Lau, who brings over 23 years of cybersecurity expertise. This team encompasses various functions such as Blockchain Security, Operational Security, and Security Governance and Compliance. The team fosters a growth mindset and humility to support individual potential within the company.

The team upholds a Security and Data Privacy Compliance-first approach that is fundamental to the organization. With the team's efforts, the company became the first Crypto company worldwide to achieve ISO27001, ISO27701, ISO22301, and PCI:DSS 3.2.1 (Level 1) certifications. The certifications have been meticulously validated by international audit firm SGS and ranked as "Adaptive (Tier 4)" – the highest level possible under the US National Institute of Standards and Technology (NIST) Cybersecurity Framework, the latest NIST Privacy Framework, SOC2, and other regional certifications like the Data Protection Trust Mark.

As a part of the CIRIFT team, you will manage and respond to cybersecurity incidents through all phases of the cycle - from Preparation to Identification, Containment, Eradication, Recovery, and Lessons Learned in coordination with global incident responders.

In this role, you will utilize your expertise in cyber defense, digital forensics, log analysis, intrusion analysis, and related skills to address security incidents across endpoints, network, and cloud infrastructure. Your responsibilities will include implementing prevention, detection, response, and remediation activities using tools such as NGFW, EDR, IDS/IPS, EDR, DLP, among others. Additionally, you will leverage your communication and collaboration skills effectively in multicultural and global environments with diverse stakeholders.

Responsibilities

  • Report to a Senior Manager to support all phases of the incident response lifecycle.
  • Participate in various incident prevention projects aimed at enhancing the security posture.

Preparation

  • Gain an understanding of different regulatory and compliance requirements.
  • Engage in self-assessment exercises to ensure the efficiency of incident response processes.
  • Develop incident response runbooks, playbooks, and SOPs aligning with regulatory standards.
  • Evaluate the incident response readiness across different layers - people, process, technology.

Detection & Analysis

  • Respond to cybersecurity incidents escalated from various channels, including the 24/7 SOC team.
  • Address cybersecurity incidents while complying with local regulatory requirements.
  • Assess the risk, impact, and scope of identified security threats.
  • Conduct in-depth incident analysis using various data sources to investigate security-related logs against threats and IOCs.

Containment, Eradication, and Recovery

  • Communicate with stakeholders to offer guidance on containing and eliminating security incidents.
  • Contribute to root cause analysis using forensic tools to identify sources of compromise or malicious activities.
  • Document and present investigative findings for significant events and other incidents.

Post-Incident Activities

  • Conduct lessons learned meetings with stakeholders.
  • Lead follow-up activities and document the incident in the case management system, providing incident reports promptly.
  • Remain prepared to engage in security incidents as required.

Requirements

  • 5+ years of experience in the Cybersecurity industry.
  • Solid technical and analytical skills.
  • Proficient in cyber security incident response processes.
  • Hands-on experience in performing incident response activities.
  • Ability to script in Bash, PowerShell, Python, Go, etc., to aid in incident response across various platforms.
  • Familiarity with cybersecurity tools like NGFW, EDR, IDS/IPS, DLP, SIEM, and other log management platforms.
  • Knowledge of frameworks such as MITRE ATT&CK and Cyber Kill Chain.
  • Enthusiasm for exploring new technologies and enhancing team capabilities.
  • Security-related certifications such as Azure, AWS, CISSP, GCIH, GCIA, GCFA, GNFA, GREM, or equivalent are advantageous.
  • Understanding of regulatory and compliance requirements like GDPR, MAS, PSD2 is a plus.
  • Fast learner with a proactive attitude and a willingness to be hands-on.
  • Strong team player with a collaborative approach.

The company offers competitive salary packages, medical insurance benefits, attractive annual leave entitlements, work flexibility options, internal mobility programs, and more. Crypto.com is an equal opportunities employer committed to cultivating a diverse and inclusive work environment where opportunities are provided transparently to all candidates.

Personal data submitted by applicants will be used exclusively for recruitment purposes. Only shortlisted candidates will be contacted.

Skills Required
Avatar
Сrypto.com
Company size
Not specified
Location
United States
Description
Not specified
Status

More Full-time Jobs

Show more

Risk manager - Crypto

New York, USA
New York, USA
Full time
Remote
About Gopher AI
At Gopher AI, we’re building a decentralized data layer for the AI-driven future — a protocol where transparency, verifiable data, and human alignment truly matter.
Our mission: make data trustless, provable, and usable across AI, DeFi, and on-chain applications.
We’re growing fast — and now looking for a Risk Manager who understands not just traditional risk, but on-chain dynamics, token economics, and crypto-native behavior.
 
Your Mission
You’ll be the brain behind risk strategy across Gopher’s ecosystem — balancing decentralization with resilience.
From smart contract exposure to liquidity risk and treasury management — your job is to make sure every piece of the system is solid, compliant, and forward-looking.
 
What You’ll Do
Design and maintain comprehensive risk frameworks tailored to Web3 systems (protocol, liquidity, counterparty, smart contract).
Monitor and analyze on-chain activity, market volatility, and ecosystem health to identify emerging threats.
Work closely with treasury, quant, and governance teams to ensure risk-adjusted strategies.
Establish and document risk policies and mitigation plans (both operational and token-economic).
Contribute to internal audits, compliance with applicable jurisdictions, and protocol transparency.
Engage with community and DAO contributors to maintain open risk communication
 
You’re a Great Fit If You
Have 3–5+ years in risk management, quantitative finance, or DeFi / crypto projects.
Know your way around DeFi protocols, liquidity pools, staking, on-chain analytics tools (Dune, Nansen, Arkham, etc.).
Understand tokenomics, smart contract audit principles, and treasury diversification strategies.
Feel at home reading Etherscan, analyzing TVL, and tracking wallet flows.
Communicate clearly, document well, and think both strategically and hands-on.
(Bonus) Have contributed to DAOs or Web3 protocols before — or maybe you’ve been a degen with a spreadsheet.
 
Why Join Gopher AI
🌍 100% remote, async-first culture
🧠 Work at the intersection of AI x Web3 — future of verifiable data
💸 Competitive crypto-based compensation + token incentives
⚡ High ownership, zero bureaucracy — you build, you ship, you own
🕶️ Join a small team of builders who actually ship things on-chain
Payment in Crypto

Localization Ops & Growth Specialist - Spanish (Argentina)

Buenos Aires, Argentina
Buenos Aires, Argentina
Full time
Remote
BingX is a leading cryptocurrency exchange, serving over 20 million users worldwide. Responsibilities: We’re looking for a marketing and PR professional to localize brand strategy, content, and campaigns for a specific language region. Responsibilities include monitoring local market trends, aligning with HQ teams, creating culturally relevant PR content, supporting promotional launches, coordinating local events and logistics, managing client communications, and contributing to SEO, advertising, and workflow optimization. Requirements: experience in localization, marketing, or PR, with a strong understanding of local culture, media, and social platforms. Background in offline event execution and logistics is preferred. Must be skilled in PR writing, campaign optimization, and cross-team coordination. Proactive, detail-oriented, and capable of managing partnerships and business negotiations. Knowledge of the Spanish-speaking Web3 ecosystem is a plus. Fluency in English and Spanish is required; Chinese is a bonus.
Payment in Crypto
1,000-2,000
Monthly
See details

AI + Blockchain Research Engineer

New York, USA
New York, USA
Full time
Remote
Gopher AI is where decentralized systems meet frontier AI. We’re not here to hype — we’re here to solve problems and push tech forward. We’re looking for a Research Engineer who:Lives at the edge of AI models, decentralized infra, smart contracts.Wants to experiment, prototype, and publish.Is motivated by real innovation, not just token pumps. 👉 Why you’ll love it:Work on cutting-edge problems in Web3 + AI.Collaborate with a team that values intellectual freedom & curiosity.Have a say in the technical direction from day one.If your idea of fun is hacking on LLMs one day and smart contracts the next, let’s build together.
Payment in Crypto
14,000-16,000
Monthly
See details

Blockchain Expert

Indore, India
Indore, India
Full time
Remote
My project is about building a USDT-like token (ERC20/TRC20/BEP20) with: Peer to Peer transfers & Trade Escrow-based trading Real liquidity (not flashed) Liquidity optimization (max tokens with minimum backing) Please share: Your past DeFi/Blockchain projects How you handle liquidity optimization
2,083-2,917
Monthly
See details

Localization Ops & Growth Specialist - Russian

Moscow, Russia
Moscow, Russia
Full time
Remote
BingX is a leading cryptocurrency exchange, serving over 20 million users worldwide. Responsibilities: We’re looking for a marketing and PR professional to localize brand strategy, content, and campaigns for a specific language region. Responsibilities include monitoring local market trends, aligning with HQ teams, creating culturally relevant PR content, supporting promotional launches, coordinating local events and logistics, managing client communications, and contributing to SEO, advertising, and workflow optimization. Requirements: experience in localization, marketing, or PR, with a strong understanding of local culture, media, and social platforms. Background in offline event execution and logistics is preferred. Must be skilled in PR writing, campaign optimization, and cross-team coordination. Proactive, detail-oriented, and capable of managing partnerships and business negotiations. Knowledge of the Spanish-speaking Web3 ecosystem is a plus. Fluency in English and Russian is required; Chinese is a bonus.
Payment in Crypto