Back to search
Data & AnalyticsHybrid

Senior Analyst, Digital Trust and Resilience (Security Governance)

Crypto.com · Hybrid

Apply
Last checked by MeritLog September 21, 2026Source: LeverSource version: lever-postings-v1

MeritLog read this listing from Crypto.com's Lever job board and last checked it on September 21, 2026.

Source: the employer's Lever job board. Open the original listing for current details.

Job details

Work model
Hybrid
Salary
Not listed by source
Location
Hong Kong

Hiring context

How this role compares at Crypto.com

Crypto.com has 63 live roles in MeritLog’s catalog across 10 job families, and 11 of them are in data & analytics. 28 of those listings publish a pay range, a disclosure rate of 44%.

Crypto.com concentrates this hiring in:

Counted across the job boards MeritLog tracks, at the time this page was served. Pay comparisons use only listings that publish a complete range in the same currency and period.

Job description

About the Role As our Digital Trust and Resilience Senior Analyst, you will lead and perform technology risk assessment and security compliance activities central to our global operations. You will coordinate annual IT internal and external audit programs, including ISO and SOC 2 certifications across our key markets. These certifications are critical to accelerating customer onboarding and streamlining annual regulatory audits worldwide. You will also run mandatory employee security awareness training globally, and drive the automation of evidence collection to improve efficiency. In this role, you will identify compliance gaps, support remediations, and provide technical guidance across all business units. AI is fundamental to how we work. In this position, you will help us build AI automations, workflows, and agents to boost the efficiency of Digital Trust & Resilience operations. You do not need to be an AI researcher. You just need to understand compliance risks and have a drive to learn and apply AI tools. Responsibilities: • Coordinate and perform annual IT internal audits and external audits for ISO and SOC 2 certifications across global markets, ensuring certifications are maintained to support customer and partner onboarding and regulatory audit readiness • Run global, regulator-mandated employee security awareness and compliance training campaigns, including tracking, reporting, and continuous improvement • Automate evidence collection and compliance workflows to drive efficiency gains and scale operations in response to growing regulatory demands • Participate in internal security and privacy assessments, external audits, compliance certifications, and risk management activities • Provide complete and accurate responses to internal and third-party enquiries on security compliance • Perform periodic technical, organizational, and third-party risk and control assessments, and manage remediation activities to completion • Design and maintain control frameworks required to comply with international standards and local regulations across all operating jurisdictions • Identify and drive process improvements to streamline global security compliance operations and protect team capacity Requirements & Qualifications: • At least 2-5 years of experience in information security, privacy, IT audit, or IT risk management • Demonstrated experience conducting IT internal and/or external audits, including ISO 27001, ISO 27701, ISO 22301, ISO 42001, SOC 1, SOC 2, PCI-DSS, SOX, cloud technologies, and data protection or equivalent certifications and regulations • Experience running compliance training programs and reporting for a global workforce • Hands-on experience with evidence collection automation or compliance workflow AI tooling is a strong advantage • Experience working with external auditors and/or regulators Preferred: • Proficiency in English with the ability to engage overseas counterparts and auditors • Experience in information security and privacy management in virtual assets, fintech, artificial intelligence (AI), online services, and global platform services • Relevant certifications, such as CISSP, CRISC, CISM, CISA, ISO 27001 LA, CIPT, CIPP/E, or CIPP/US • Knowledge of global regulatory frameworks and demonstrated experience managing regulator relationships across jurisdictions, including GDPR, DORA, CFTC, MiCA, HKMA, and HK SFC. • Experience establishing information security and privacy frameworks to meet local regulatory requirements • Strong communication skills with the ability to translate complex technical issues for non-technical business stakeholders • Interest and understanding of Blockchain and AI technologies • Collaborative team player with a positive attitude, detail-oriented mindset, and commitment to continuous learning Our Security Team At Crypto.com, our dedication to user security is led by our highly experienced Security Team. Comprising an international roster of seasoned cybersecurity experts, our team leads the company's Security, Privacy, and Security Compliance endeavors.   The team includes holders of international patents for technologies integrated in our security architecture. Under the stewardship of a distinguished CISO recognized by the Forbes Technology Council and among the Global Top 100 CISOs, our team has consistently championed industry standards, acquiring certifications like ISO27001, ISO27701, ISO22301, ISO42001, PCI:DSS 3.2.1 (Level 1), NIST Tier 4, and SOC 2 Type II, in addition to the MPI License from Singapore MAS. Our Chief Information Security Officer reports directly to the CEO, underscoring the prioritization of security in our organization's hierarchy.   Our Security Team not only places great emphasis on credentials and expertise but also deeply values hands-on experience, rapid cognition, and dynamic learning. The challenges in the world of crypto are ever-evolving, and as such, our team prides itself on quick adaptability and robust teamwork, ensuring that we stay ahead of potential threats and always safeguard our user base.   #LI-CY2

Keep exploring

More Data & Analytics roles

Search all jobs

Privacy choices

Analytics and advertising stay off unless you allow them. Private data stays out.

Read the privacy notice