Senior Analyst, Digital Trust and Resilience

Crypto.com

Hong Kong

On-site

HKD 600,000 - 900,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Crypto.com is seeking a Senior Analyst to lead IT audits, security compliance, and risk programs across global markets. You will coordinate ISO and SOC 2 programs, run employee security awareness training, and drive automation of evidence collection.

You’ll engage with regulators and external auditors to maintain robust controls. The role requires experience in information security, privacy, and IT risk management, with strong communication skills and a keen interest in AI and blockchain

Qualifications

  • At least 2-5 years of experience in information security, privacy, IT audit, or IT risk management.
  • Experience conducting IT internal and external audits including ISO 27001, ISO 27701, ISO 22301, ISO 42001, SOC 1, SOC 2, PCI-DSS, SOX, cloud technologies, and data protection regulations.
  • Experience running compliance training programs and reporting for a global workforce.
  • Hands-on experience with evidence collection automation or compliance workflow AI tooling is a strong advantage.
  • Experience working with external auditors and regulators.
  • Proficiency in English with the ability to engage overseas counterparts and auditors.
  • Experience in information security and privacy management in virtual assets, fintech, AI, online services, and global platform services.
  • Certifications such as CISSP, CRISC, CISM, CISA, ISO 27001 LA, CIPT, CIPP/E, or CIPP/US.
  • Knowledge of global regulatory frameworks and regulator relationships across jurisdictions, including GDPR, DORA, CFTC, MiCA, HKMA, and HK SFC.
  • Experience establishing information security and privacy frameworks to meet local regulatory requirements.
  • Strong communication skills with the ability to translate complex technical issues for non-technical business stakeholders.
  • Interest and understanding of Blockchain and AI technologies.
  • Collaborative team player with a detail-oriented mindset and commitment to continuous learning.

Responsibilities

  • Coordinate and perform annual IT internal audits and external audits for ISO and SOC 2 certifications across global markets.
  • Run global, regulator-mandated employee security awareness and compliance training campaigns, including tracking and reporting.
  • Automate evidence collection and compliance workflows to scale operations and improve efficiency.
  • Participate in internal security and privacy assessments, external audits, and risk management activities.
  • Provide complete responses to internal and third-party enquiries on security compliance.
  • Perform periodic risk and control assessments and manage remediation to completion.
  • Design and maintain control frameworks to meet international standards and local regulations.
  • Identify and drive process improvements to streamline global security compliance operations.

Skills

IT audit
Information security
Risk management
Privacy compliance
Cloud security
Auditing standards
Regulatory compliance
Communication

Education

Bachelor's degree in IT or related field

Tools

AI tooling

Job description

Senior Analyst, Digital Trust and Resilience

About the Role
As our Digital Trust and Resilience Senior Analyst, you will lead and perform technology risk assessment and security compliance activities central to our global operations. You will coordinate annual IT internal and external audit programs, including ISO and SOC 2 certifications across our key markets. These certifications are critical to accelerating customer onboarding and streamlining annual regulatory audits worldwide. You will also run mandatory employee security awareness training globally, and drive the automation of evidence collection to improve efficiency. In this role, you will identify compliance gaps, support remediations, and provide technical guidance across all business units.
AI is fundamental to how we work. In this position, you will help us build AI automations, workflows, and agents to boost the efficiency of Digital Trust & Resilience operations. You do not need to be an AI researcher. You just need to understand compliance risks and have a drive to learn and apply AI tools.

Responsibilities:

Coordinate and perform annual IT internal audits and external audits for ISO and SOC 2 certifications across global markets, ensuring certifications are maintained to support customer and partner onboarding and regulatory audit readiness

Run global, regulator-mandated employee security awareness and compliance training campaigns, including tracking, reporting, and continuous improvement

Automate evidence collection and compliance workflows to drive efficiency gains and scale operations in response to growing regulatory demands

Participate in internal security and privacy assessments, external audits, compliance certifications, and risk management activities

Provide complete and accurate responses to internal and third-party enquiries on security compliance

Perform periodic technical, organizational, and third-party risk and control assessments, and manage remediation activities to completion

Design and maintain control frameworks required to comply with international standards and local regulations across all operating jurisdictions

Identify and drive process improvements to streamline global security compliance operations and protect team capacity

Requirements & Qualifications:

At least 2-5 years of experience in information security, privacy, IT audit, or IT risk management

Demonstrated experience conducting IT internal and/or external audits, including ISO 27001, ISO 27701, ISO 22301, ISO 42001, SOC 1, SOC 2, PCI-DSS, SOX, cloud technologies, and data protection or equivalent certifications and regulations

Experience running compliance training programs and reporting for a global workforce

Hands-on experience with evidence collection automation or compliance workflow AI tooling is a strong advantage

Experience working with external auditors and/or regulators

Preferred:

Proficiency in English with the ability to engage overseas counterparts and auditors

Experience in information security and privacy management in virtual assets, fintech, artificial intelligence (AI), online services, and global platform services

Relevant certifications, such as CISSP, CRISC, CISM, CISA, ISO 27001 LA, CIPT, CIPP/E, or CIPP/US

Knowledge of global regulatory frameworks and demonstrated experience managing regulator relationships across jurisdictions, including GDPR, DORA, CFTC, MiCA, HKMA, and HK SFC.

Experience establishing information security and privacy frameworks to meet local regulatory requirements

Strong communication skills with the ability to translate complex technical issues for non-technical business stakeholders

Interest and understanding of Blockchain and AI technologies

Collaborative team player with a positive attitude, detail-oriented mindset, and commitment to continuous learning

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Analyst, Digital Trust and Resilience (Security Governance)
Senior Analyst, Digital Trust and Resilience (Security Governance)

P2P • Hong Kong

On-site
HKD 550,000 - 900,000
Digital Trust and Resilience Engineer (Security Governance)
Digital Trust and Resilience Engineer (Security Governance)

P2P • Hong Kong

On-site
HKD 941,000 - 1,412,000
Cybersecurity and Information Security Analyst
Cybersecurity and Information Security Analyst

Not Another Headhunting Company • Hong Kong

On-site
HKD 420,000 - 780,000
Digital Trust & Resilience Analyst - AI-Driven Compliance
Digital Trust & Resilience Analyst - AI-Driven Compliance

P2P • Hong Kong

On-site
HKD 550,000 - 900,000
Global Digital Trust & Compliance Lead - Audits & AI
Global Digital Trust & Compliance Lead - Audits & AI

Crypto.com • Hong Kong

On-site
HKD 600,000 - 900,000
Global Security Compliance Engineer — ISO/SOC2 & AI Automation
Global Security Compliance Engineer — ISO/SOC2 & AI Automation

P2P • Hong Kong

On-site
HKD 941,000 - 1,412,000
Compliance & Information Security Specialist | World-class AI product
Compliance & Information Security Specialist | World-class AI product

Osmium Consulting Group Limited • Hong Kong

On-site
HKD 420,000 - 540,000
Senior System Assurance Expert – Global Fintech | HKD 1.2m – 1.4m + Bonus
Senior System Assurance Expert – Global Fintech | HKD 1.2m – 1.4m + Bonus

DJRecruit Asia • Hong Kong

On-site
HKD 1,200,000 - 1,400,000
Security & Privacy Compliance Senior Manager - Latin America, Middle East & Africa-Hong Kong
Security & Privacy Compliance Senior Manager - Latin America, Middle East & Africa-Hong Kong

Alibaba Cloud • Hong Kong

On-site
HKD 900,000 - 1,300,000
Technology Risk & Compliance
Technology Risk & Compliance

Moore Stephens Hong Kong • Hong Kong

On-site
HKD 520,000 - 860,000
Competitive compensation