As the top security leader of the company, the CSO is fully responsible for formulating and implementing the company's overall security strategy, building a comprehensive, systematic, and compliant security system covering digital currency exchange, payment business, and global operations. This role will lead the security team to identify, assess, and mitigate all types of security risks (cyber security, physical security, data security, operational security, compliance security), ensure the company's business complies with global security-related regulatory requirements, respond to security incidents efficiently, and maintain the company's security reputation and user trust.
Key Responsibilities
1. Security Strategy & Governance
Develop the company's long-term and short-term security strategy, security roadmap, and risk appetite, aligning with business development goals and global regulatory requirements.
Establish and improve the company's security governance system, including security policies, standards, processes, and operating procedures, and promote the implementation and supervision of the entire company.
Lead the formulation of security assessment indicators, conduct regular security risk assessments, security audits, and compliance reviews, and issue security reports to the CEO and board of directors.
Coordinate cross-departmental security work, promote the integration of security into product design, technology development, business operations, and other full business links (Shift-Left Security).
2. Cyber Security & Technical Defense
Lead the construction and operation of the company's cyber security system, including network security, application security, endpoint security, cloud security, and blockchain security (on-chain security, wallet security).
Manage the Security Operations Center (SOC), establish real-time monitoring, threat detection, and emergency response mechanisms, and promptly respond to cyber attacks (such as phishing, DDoS, ransomware, data breaches, and on-chain attacks).
Promote security technology research and application, including AI-driven threat intelligence analysis, automated vulnerability scanning, penetration testing, and security automation and orchestration (SOAR).
Responsible for the security of the company's core systems (trading system, payment system, wallet system, user data system) to prevent system loopholes, data leaks, and malicious attacks.
3. Asset & Physical Security
Formulate and implement the company's asset security strategy, including the security management of digital assets (cold/hot wallet security, private key management, fund isolation, and anti-theft mechanisms).
Establish and manage the company's physical security system, including office areas, computer rooms, and data centers, covering access control, video surveillance, fire protection, and anti-theft measures.
Coordinate with third-party security service providers (such as security guards, security technology companies) to ensure the physical security of the company's premises and assets.
4. Security Compliance & Regulatory Alignment
Ensure the company's security work complies with global regulatory requirements related to digital currency and payment services, including FATF recommendations, MiCA, local regulatory requirements for major markets (such as Hong Kong SFC, US regulatory requirements), and data protection laws (GDPR, etc.).
Cooperate with the compliance team to complete security-related compliance filings, audits, and inspections, and respond to regulatory inquiries and requirements.
Establish security compliance training and awareness promotion mechanisms to improve the security compliance awareness of all employees.
5. Security Incident Response & Crisis Management
Develop and improve security incident emergency response plans, lead the handling of major security incidents (such as data breaches, cyber attacks, asset theft, and security compliance incidents), and minimize losses.
Conduct post-incident reviews, root cause analysis, summarize experience, and optimize security systems and processes to prevent similar incidents from recurring.
Manage security crisis public relations, coordinate with relevant departments to release information, and maintain the company's brand reputation and user trust.
6. Team Building & Talent Development
Build, manage, and develop the security team, formulate team OKRs and performance assessment systems, and cultivate a professional security talent echelon.
Guide the professional growth of team members, organize security training and technical exchanges, and improve the team's overall security capabilities.
Establish cooperative relationships with industry security organizations, security vendors, and regulatory authorities to track the latest security trends and technologies.
7. Security Collaboration & Ecosystem Construction
Collaborate with product, technology, operations, compliance, customer service, and other departments to integrate security requirements into business processes and product iterations.
Establish security cooperation mechanisms with partners (such as payment channels, liquidity providers, and custodians) to ensure the security of the entire business ecosystem.
Participate in industry security exchanges and standards formulation, and enhance the company's influence in the digital currency security field.