Associate/Senior, IT Governance & Compliance
Hex Trust
About Hex Trust
Hex Trust is a fully-licensed and insured digital asset custodian. Led by veteran banking technologists and award-winning financial services experts, Hex Trust has built Hex Safe, a proprietary bank-grade platform that delivers solutions for digital asset protocols, foundations, financial institutions, and the Web3 ecosystem. Hex Trust has offices in Singapore, Hong Kong, Dubai, Italy, and Vietnam.
About the Job
As Hex Trust is growing rapidly and looking to expand its business into multiple jurisdictions, we are seeking professionals in the IT GRC (Governance, Risk, and Compliance) space to support our Information Security Team. Your role will involve assisting the company in several areas, including IT Regulatory Affairs, Security Certifications, Policy and Process Design, IT Control and Assurance, and Audit Engagement Coordination. You should have a high-level understanding of various technology functions, processes, and concepts. We expect you to possess strong communication skills, excellent stakeholder management capabilities, and the ability to deliver results with high precision.
Responsibilities
- Develop IT policies, standards, and procedures in accordance with industry best practices, relevant technologies, regulatory requirements, and standards.
- Act as the point of contact for IT Regulatory Affairs and Client Due Diligence Questionnaires.
- Review and revamp existing IT policies to ensure alignment with industry best practices and standards. Lead SOC 2 and ISO accreditations, obtaining and maintaining various IT and security compliance certifications.
- Evaluate and manage capabilities that enable the organization to reliably achieve its objectives, address uncertainty, and act with integrity, making the organization more responsive and efficient overall.
- Manage audit findings remediation to mitigate risks.
- Coordinate external assessment requests related to industry standards and regulatory requirements.
- Act as the primary responsible party to drive and ensure policy compliance.
- Perform and manage regular information security and control assessments to ensure compliance with information security policies and standards.
- Identify and address information security risks and requirements to protect the organization from adversity, surprises, and weaknesses.