Chief Security Officer
All-in-one Philippine e-wallet and cryptocurrency exchange combining crypto trading with payments, bills, QR checkout, mobile load, and remittances.
Funding history
About Coins.ph
Coins.ph is a regulated digital-asset and payments platform operating under the Coins.ph brand. Its services include buying, selling, and holding cryptocurrency; peso wallets; bill payments; mobile load; QR payments; money transfers; and remittances. The current user agreement identifies Betur, Inc. and DCPay Philippines, Inc. as the entities doing business as coins.ph.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
Serve as the company's top security leader by developing and implementing a comprehensive security strategy and compliant security system across digital currency exchange, payment, and global operations. Lead risk management, cybersecurity, physical security, digital asset security, regulatory compliance, incident response, crisis management, and security team development.
Requirements
- 10+ years of information security and risk management experience.
- 5+ years of CSO or equivalent senior security management experience in compliant digital currency exchanges, payment institutions, or financial technology companies.
- Deep understanding of digital currency trading and payment business models and security risks.
- Expertise in cybersecurity, network security, application security, data security, blockchain security, and digital asset security management.
- Familiarity with FATF, MiCA, SFC, and other global regulatory frameworks.
- Experience with security compliance audits and regulatory inspections.
- Experience in security incident response, crisis management, and security system construction.
- Understanding of SOC, SIEM, vulnerability scanning, penetration testing, encryption, and wallet security technologies.
- Strong compliance and risk-control awareness.
- Excellent leadership, team management, cross-departmental coordination, and resource integration capabilities.
- Excellent oral and written communication skills in Chinese and English.
- Bachelor's degree or higher in a relevant field.
- CISSP, CISM, CISA, CRISC, or ACAMS certification preferred.
- Experience with licensing and compliance operations for digital currency exchanges and payment institutions preferred.
- Experience in on-chain security, DeFi risk control, digital asset custody security, and AML preferred.
- Experience leading major cybersecurity incidents in the crypto industry preferred.
- Familiarity with current cybersecurity technologies and threat trends preferred.
Responsibilities
- Develop the company's long-term and short-term security strategy, security roadmap, and risk appetite.
- Establish and improve the company's security governance system, including policies, standards, processes, and procedures.
- Lead security assessments, risk assessments, audits, and compliance reviews.
- Coordinate cross-departmental security work and integrate security into product design and business operations.
- Lead the construction and operation of network, application, endpoint, cloud, and blockchain security systems.
- Manage the Security Operations Center and establish real-time monitoring, threat detection, and emergency response mechanisms.
- Promote AI-driven threat intelligence, vulnerability scanning, penetration testing, and security automation.
- Secure trading, payment, wallet, and user data systems.
- Implement digital asset security measures including cold and hot wallet security and private key management.
- Establish and manage physical security systems for offices, computer rooms, and data centers.
- Coordinate with third-party security service providers.
- Ensure compliance with global digital currency, payment, and data protection regulations.
- Support compliance filings, audits, inspections, and regulatory responses.
- Establish security compliance training and awareness programs.
- Lead major security incident response, post-incident reviews, and root cause analysis.
- Manage security crisis public relations and maintain brand reputation and user trust.
- Build, manage, and develop the security team, including OKRs and performance systems.
- Develop team members through training and technical exchanges.
- Build relationships with security organizations, vendors, and regulators.
- Collaborate with product, technology, operations, compliance, and customer service teams.
- Establish security cooperation mechanisms with payment channels, liquidity providers, and custodians.
- Participate in industry security exchanges and standards formulation.
