← All jobs
CR

Digital Trust and Resilience Engineer (Security Governance)

Type
Full-time
Work setup
On-site
Experience
Mid
Posted
1 day ago

What security roles in crypto pay

64 salaries · our own data
median $202k$145k$268k

Most security roles in crypto pay between $145k and $268k, with a median of $202k.

As a Digital Trust and Resilience Engineer at Crypto.com, you lead and perform technology risk assessment and security compliance activities central to global operations. You coordinate annual IT internal and external audit programs, including ISO and SOC 2 certifications across key markets, run mandatory employee security awareness training globally, and drive the automation of evidence collection to improve efficiency. You identify compliance gaps, support remediations, and provide technical guidance across all business units. AI is fundamental to how you work in this role: you help build AI automations, workflows, and agents to boost the efficiency of Digital Trust and Resilience operations.

What you'll do

  • Coordinate and perform annual IT internal audits and external audits for ISO and SOC 2 certifications across global markets, ensuring certifications are maintained to support customer and partner onboarding and regulatory audit readiness
  • Run global, regulator-mandated employee security awareness and compliance training campaigns, including tracking, reporting, and continuous improvement
  • Automate evidence collection and compliance workflows to drive efficiency gains and scale operations in response to growing regulatory demands
  • Participate in internal security and privacy assessments, external audits, compliance certifications, and risk management activities
  • Provide complete and accurate responses to internal and third-party enquiries on security compliance
  • Perform periodic technical, organizational, and third-party risk and control assessments, and manage remediation activities to completion
  • Design and maintain control frameworks required to comply with international standards and local regulations across all operating jurisdictions
  • Identify and drive process improvements to streamline global security compliance operations and protect team capacity

What you bring

  • 2 to 5 years of experience in information security, privacy, IT audit, or IT risk management
  • Demonstrated experience conducting IT internal and/or external audits, including ISO 27001, ISO 27701, ISO 22301, ISO 42001, SOC 1, SOC 2, PCI-DSS, SOX, cloud technologies, and data protection or equivalent certifications and regulations
  • Experience running compliance training programs and reporting for a global workforce
  • Experience working with external auditors and/or regulators

Nice to have

  • Hands-on experience with evidence collection automation or compliance workflow AI tooling
  • Proficiency in English with the ability to engage overseas counterparts and auditors
  • Experience in information security and privacy management in virtual assets, fintech, artificial intelligence, online services, and global platform services
  • Relevant certifications such as CISSP, CRISC, CISM, CISA, ISO 27001 LA, CIPT, CIPP/E, or CIPP/US
  • Knowledge of global regulatory frameworks and demonstrated experience managing regulator relationships across jurisdictions, including GDPR, DORA, CFTC, MiCA, HKMA, and HK SFC
  • Experience establishing information security and privacy frameworks to meet local regulatory requirements
  • Strong communication skills with the ability to translate complex technical issues for non-technical business stakeholders
  • Interest and understanding of blockchain and AI technologies

About Crypto.com

Crypto.com's Security Team comprises an international roster of seasoned cybersecurity experts leading the company's Security, Privacy, and Security Compliance endeavors. The team holds international patents for technologies integrated in the security architecture and has acquired certifications including ISO 27001, ISO 27701, ISO 22301, ISO 42001, PCI:DSS 3.2.1 Level 1, NIST Tier 4, and SOC 2 Type II, in addition to the MPI License from Singapore MAS. The Chief Information Security Officer reports directly to the CEO, underscoring the prioritization of security in the organization.

Digital Trust and Resilience Engineer (Security Governance) | CryptoJobsHQ