About the OpportunityThis is not a traditional GRC hire. The Tech Governance Office is looking for someone who combines the governance judgment of a seasoned compliance professional with the drive of a forward-deployed engineer - someone who closes gaps by shipping solutions, navigates ambiguity without hand-holding, and operates with the urgency of a startup and the rigor of a regulated financial institution.
You will own complex cross-functional work streams independently - coordinating across Engineering, Legal, Product, and Finance - while managing external auditors and regulators. Strong written and verbal communication in both English and Mandarin is a meaningful advantage in this role. AI tooling is not optional; it is how you work.
Who You Are- Self-directed driver - You run cross-functional work streams without being managed. Ambiguity is a starting point, not a blocker.
- AI-native operator - You already use AI to do more, faster - and you raise the floor for the teams around you.
- Clear communicator - You earn trust across regulators, auditors, and C-suite through precision and consistency - in any room.
Culture FitPace
Standards
Startup velocity - Decisions move fast. Priorities shift. You ship, iterate, and adapt - without waiting for perfect conditions or top-down direction.
Financial institution rigor - Audit trails matter. Regulators scrutinize. The bar for accuracy, documentation, and accountability is institutional-grade - always.
> The tension between these two is not a bug - it is the job. We are looking for someone who holds both without compromise.
What You'll Be Doing- Independently lead audit remediation programs - assess gaps, develop structured plans, and drive verified closure across engineering, product, legal, and operations without escalation dependency.
- Own cross-functional governance work streams - set milestones, coordinate accountability, and remove blockers across departments with limited management oversight.
- Conduct IT security and architecture governance reviews - assess whether systems and processes meet applicable standards, and issue findings with clear ownership and remediation timelines.
- Build and maintain the policy estate - draft, refine, and operationalize IT governance policies and procedures; translate regulatory requirements into implementation-ready guidance for first-line teams.
- Lead regulator and auditor engagement - serve as the primary coordination interface for external audit and regulatory correspondence, representing the Tech Governance Office with credibility and precision.
- Deploy AI to accelerate compliance operations - prototype and scale AI-assisted workflows for evidence collection, control monitoring, audit response, and policy generation; drive team-wide adoption.
- Deliver Tech Governance-level reporting - produce governance dashboards and executive briefs on remediation status, risk exposure, and regulatory posture, independently and to publication standard.
- Track the regulatory horizon - monitor evolving requirements across active jurisdictions, translate changes into prioritized internal action, and brief senior leadership proactively.
What We Look For In You AI Adoption & Application - Must Have- Active daily use of AI tools to accelerate compliance and governance work - demonstrated practice with measurable output impact, not theoretical awareness.
- Ability to identify, build, and scale AI-assisted workflows within a Tech Governance office context - evidence automation, policy generation, audit response, or control monitoring.
- Working knowledge of AI governance and risk - sufficient to contribute to internal AI oversight frameworks and assess AI-related compliance obligations.
Independent Cross-Functional Leadership - Must Have- Demonstrated ability to own and drive complex, multi-stakeholder work streams independently - setting direction, coordinating accountability, and delivering outcomes without management escalation.
- Track record of influencing without authority across engineering, legal, finance, and operations in a fast-moving environment.
- Comfortable operating under ambiguity and shifting priorities while maintaining institutional-grade standards for accuracy and documentation.
Experience- 8+ years in IT audit, risk management, compliance, or security governance
- 3+ years leading governance programs at a large-scale internet, financial services, or crypto firm
- Exposure to IPO-readiness or high-scrutiny regulatory examination programs preferred
Frameworks & Standards- ISO 27001, SOC 1/2, PCI-DSS, COBIT, NIST - deep working knowledge
- GDPR and APAC data protection regimes
- Crypto and blockchain-specific compliance risk awareness a strong asset
Engineering Sensibility- Able to read and interpret code, architecture diagrams, and technical design documents without engineer-translation dependency
- Familiarity with cloud environments (Alibaba Cloud, AWS, GCP) and associated security tooling
Communication- Executive-level written and verbal communication in English - board-ready governance briefs, regulator responses, and Tech Governance-level reporting produced independently
- Proficiency in Mandarin (written and verbal) is a strong advantage for APAC regulatory and stakeholder engagement
Preferred Qualifications- Professional security or governance certification: CISA • CISSP • CRISC • CISM • CCISO • Agentic AI
- Experience building AI-powered compliance tooling - audit automation, continuous control monitoring, or policy-to-control mapping
- Prior involvement in SOX ITGC, SEC Reg S-K Item 106, or equivalent listing-authority tech governance programs
- Crypto-native compliance exposure - Proof of Reserves, SAB 121, Travel Rule, AML/CFT program governance
- Active regulatory footprint across MAS, VARA, FCA, HKMA/SFC, or equivalent
Why This RoleOKX operates across 50+ jurisdictions with live regulatory programs. The Tech Governance Office is building infrastructure-grade compliance capability - not checkbox compliance. This is a rare opportunity to shape how that work gets done: independently, at pace, and with AI at the centre of the method.
Perks & Benefits - Competitive total compensation package
- L&D programs and Education subsidy for employees' growth and development
- Various team building programs and company events
- Wellness and meal allowances
- Comprehensive healthcare schemes for employees and dependents
- More that we love to tell you along the process!
The base salary range for this position is $223,611 to $268,333. The salary offered depends on a variety of factors, including job-related knowledge, skills, experience, and market location. In addition to the salary, a performance bonus and long-term incentives may be provided as part of the compensation package, as well as a full range of medical, financial, and/or other benefits, dependent on the position offered. Applicants should apply via OKX internal or external careers site.