Get more replies from employers
Send a job-specific resume in minutes.
Medium is looking for a Head of Security in Taguig, Philippines. This position requires developing security strategies, overseeing cybersecurity systems, and compliance with regulatory frameworks. The ideal candidate has substantial experience in information security and risk management, including a strong background in the crypto and financial sectors.
The role involves leading cross-departmental security initiatives, enhancing the company's security posture, and ensuring the safety of digital assets.
Coins is the most established crypto brand in The Philippines and has gained the trust of more than 18 million users. Through the easy‑to‑use mobile app, users can buy and sell a variety of different cryptocurrencies and access a wide range of financial services.
Coins is fully regulated by the Bangko Sentral ng Pilipinas (BSP) and is the first ever crypto‑based company in Asia to hold both Virtual Currency and Electronic Money Issuer licenses from a central bank.
Develop the company's long‑term and short‑term security strategy, security roadmap, and risk appetite, aligning with business development goals and global regulatory requirements.
Establish and improve the company's security governance system, including security policies, standards, processes, and operating procedures, and promote the implementation and supervision of the entire company.
Lead the formulation of security assessment indicators, conduct regular security risk assessments, security audits, and compliance reviews, and issue security reports to the CEO and board of directors.
Coordinate cross‑departmental security work, promote the integration of security into product design, technology development, business operations, and other full business links (Shift‑Left Security).
Lead the construction and operation of the company's cyber security system, including network security, application security, endpoint security, cloud security, and blockchain security (on‑chain security, wallet security).
Manage the Security Operations Center (SOC), establish real‑time monitoring, threat detection, and emergency response mechanisms, and promptly respond to cyber attacks (such as phishing, DDoS, ransomware, data breaches, and on‑chain attacks).
Promote security technology research and application, including AI‑driven threat intelligence analysis, automated vulnerability scanning, penetration testing, and security automation and orchestration (SOAR).
Responsible for the security of the company's core systems (trading system, payment system, wallet system, user data system) to prevent system loopholes, data leaks, and malicious attacks.
Formulate and implement the company's asset security strategy, including the security management of digital assets (cold/hot wallet security, private key management, fund isolation, and anti‑theft mechanisms).
Establish and manage the company's physical security system, including office areas, computer rooms, and data centers, covering access control, video surveillance, fire protection, and anti‑theft measures.
Coordinate with third‑party security service providers (such as security guards, security technology companies) to ensure the physical security of the company's premises and assets.
Ensure the company's security work complies with global regulatory requirements related to digital currency and payment services, including FATF recommendations, MiCA, local regulatory requirements for major markets (such as Hong Kong SFC, US regulatory requirements), and data protection laws (GDPR, etc.).
Cooperate with the compliance team to complete security‑related compliance filings, audits, and inspections, and respond to regulatory inquiries and requirements.
Establish security compliance training and awareness promotion mechanisms to improve the security compliance awareness of all employees.
Develop and improve security incident emergency response plans, lead the handling of major security incidents (such as data breaches, cyber attacks, asset theft, and security compliance incidents), and minimize losses.
Conduct post‑incident reviews, root cause analysis, summarize experience, and optimize security systems and processes to prevent similar incidents from recurring.
Manage security crisis public relations, coordinate with relevant departments to release information, and maintain the company's brand reputation and user trust.
Build, manage, and develop the security team, formulate team OKRs and performance assessment systems, and cultivate a professional security talent echelon.
Guide the professional growth of team members, organize security training and technical exchanges, and improve the team's overall security capabilities.
Establish cooperative relationships with industry security organizations, security vendors, and regulatory authorities to track the latest security trends and technologies.
Collaborate with product, technology, operations, compliance, customer service, and other departments to integrate security requirements into business processes and product iterations.
Establish security cooperation mechanisms with partners (such as payment channels, liquidity providers, and custodians) to ensure the security of the entire business ecosystem.
Participate in industry security exchanges and standards formulation, and enhance the company's influence in the digital currency security field.