Senior Analyst, Digital Trust and Resilience
** About Crypto.com**
The Crypto.com Security Team, led by seasoned cybersecurity experts, is dedicated to ensuring user security through its efforts in Security, Privacy, and Security Compliance. The team holds international patents for technologies integrated into the security architecture, guided by a distinguished CISO who is a Forbes Technology Council member and globally recognized within the Top 100 CISOs. The team upholds industry standards with certifications including ISO27001, ISO27701, ISO22301, ISO42001, PCI:DSS 3.2.1 (Level 1), NIST Tier 4, and SOC 2 Type II, as well as the MPI License from Singapore MAS. Reporting directly to the CEO, the Chief Information Security Officer highlights the central importance of security within the organization.
The Security Team values expertise, hands-on experience, rapid cognition, and continuous learning in response to the evolving challenges within the crypto space. Emphasizing adaptability and teamwork, the team remains proactive in staying ahead of potential threats and safeguarding users.
We seek a candidate experienced in ISO certifications, SOC 2 audits, and successful execution of security awareness training campaigns.
Role Overview:
As the Digital Trust and Resilience Senior Analyst, you will play a key role in conducting technology risk assessments and security compliance activities globally. Responsibilities include overseeing annual IT internal and external audit programs, managing ISO and SOC 2 certifications in key markets, conducting security awareness training on a global scale, and optimizing evidence collection processes for efficiency gains. The position involves identifying compliance gaps, facilitating remediations, and providing technical guidance across the organization while contributing to the development of AI automations to enhance operational efficiency within Digital Trust & Resilience.
Responsibilities:
- Coordinate and execute annual IT internal and external audits for ISO and SOC 2 certifications across global markets, ensuring compliance supports customer onboarding and regulatory audits.
- Lead global employee security awareness and compliance training programs, focusing on tracking, reporting, and ongoing enhancements.
- Automate evidence collection and compliance workflows to drive operational efficiency and scalability in response to regulatory requirements.
- Engage in internal security and privacy assessments, external audits, compliance certifications, and risk management activities.
- Provide thorough and accurate responses to inquiries from internal and external parties regarding security compliance.
- Conduct periodic technical, organizational, and third-party risk evaluations, managing remediation activities.
- Establish and maintain control frameworks to meet international standards and local regulations in all operating jurisdictions.
- Identify and drive process improvements to streamline security compliance operations and manage team capacities effectively.
Requirements & Qualifications:
- 3-5 years of experience in information security, privacy, IT audit, or IT risk management.
- Proficiency in conducting IT internal and/or external audits, including various certifications and regulations such as ISO 27001, ISO 27701, ISO 22301, SOC 1, SOC 2, PCI-DSS, SOX, etc.
- Experience coordinating compliance training programs globally and generating comprehensive reports.
- Hands-on experience with automation tools for evidence collection or compliance workflows is advantageous.
- Previous interaction with external auditors and regulators is ideal.
Preferred:
- Strong English proficiency for engaging with overseas counterparts and auditors.
- Experience in managing information security and privacy within virtual assets, fintech, AI, online services, and global platforms.
- Relevant certifications such as CISSP, CRISC, CISM, CISA, ISO 27001 LA, CIPT, CIPP/E, or CIPP/US.
- Knowledge of global regulatory frameworks and managing regulator relationships across various jurisdictions.
- Previous work in establishing information security and privacy frameworks to meet local regulatory standards.
- Excellent communication skills for translating technical concepts to non-technical stakeholders.
- Interest and familiarity with Blockchain and AI technologies.
- Collaborative team player with attention to detail and a commitment to ongoing learning opportunities.
