Okx
OpenDeputy Chief Information Security Officer (CISO), US
- Location
- New York, United States; San Jose, California, United States
- Posted
- Aug 6, 2026
- Last seen
- Aug 20, 2026
About the role
Who We Are
At OKX, we believe that the future will be reshaped by crypto, and ultimately contribute to every individual's freedom. OKX is a leading crypto exchange, and the developer of OKX Wallet, giving millions access to crypto trading and decentralized crypto applications (dApps). OKX is also a trusted brand by hundreds of large institutions seeking access to crypto markets. We are safe and reliable, backed by our Proof of Reserves. Across our multiple offices globally, we are united by our core principles: We Before Me , Do the Right Thing , and Get Things Done . These shared values drive our culture, shape our processes, and foster a friendly, rewarding, and diverse environment for every OK-er.
About the opportunity
We're looking for a security leader for the Americas who's equally comfortable in front of a regulator, inside a risk assessment, or reviewing a piece of technical architecture as part of a lean team. You'll start as Deputy CISO, Americas, with a path to taking on the full Regional CISO role as you build track record in the seat. How quickly that happens is up to you.
This isn't a role for someone who wants to operate purely at policy level, nor for a deep specialist engineer who wants to be configuring tools. It's for someone who can move between both worlds: fluent enough in the technical detail to challenge the Engineers or spot a gap in an architecture review, but credible enough in governance to own a regulatory conversation or a board pack. This is a lean team, so we're not looking for someone to sit back and build a big team under them, this is a direct delivery role. More than anything, we want someone hungry to learn, genuinely curious, and comfortable solving problems they haven't solved before — that matters more to us than ticking every experience box.
What you'll be doing
• Leading on audit defence, risk assessments, and technical architecture reviews across the Americas estate — this is a working role, not an oversight one.
• Own the Americas security risk and compliance programme: policy, controls, risk register, regulatory engagement, and reporting.
• Manage the US GRC lead directly, and work closely with the US SecOps team lead on operational risk and incident response.
• Build relationships with Legal, Compliance, Risk and Internal Audit, and represent security in Americas leadership forums.
• Prepare for and take an increasing share of regulator and licensing engagement, building toward owning it outright.
• Spot what's missing before it becomes a problem, raise an issue, build an action plan and drive it through to delivery.
What we look for
• A security professional with solid GRC and risk grounding, ideally from a regulated industry — TradFi (bank, broker-dealer, payments) or regulated crypto is a strong plus, though direct crypto experience isn't
