About this role
Binance
Binance is a leading global blockchain ecosystem behind the world’s largest cryptocurrency exchange by trading volume and registered users. Binance offerings range from trading and finance to education, research, payments, institutional services, Web3 features, and more. We leverage the power of digital assets and blockchain to build an inclusive financial ecosystem to advance the freedom of money and improve financial access for people around the world.
We are seeking an experienced and strategic Chief Information Security Officer (CISO) to lead our cybersecurity, operational resilience, and regulatory compliance initiatives across Indonesia. This role will ensure adherence to Indonesian financial and data protection regulations — including OJK (Otoritas Jasa Keuangan) cybersecurity regulations, Bappebti crypto-asset rules, the Personal Data Protection (PDP) Law (Law No. 27 of 2022), and relevant Bank Indonesia guidelines — while aligning with Binance's global security framework.
The ideal candidate will have deep expertise in cybersecurity governance, IT risk management, incident response, and a proven track record in aligning with Indonesian and international regulatory frameworks. This is a hands-on leadership role requiring both strategic vision and operational execution.
Responsibilities
-
Strategic Leadership
-
Define and execute the Indonesian cybersecurity and operational resilience strategy aligned with local regulatory requirements and global Binance business objectives.
-
Act as the primary advisor to executive leadership and the board on information security risks and regulatory obligations in Indonesia.
-
Represent Binance in engagements with Indonesian regulators — including OJK, Bappebti, Bank Indonesia, and the Ministry of Communication and Information Technology (Kominfo) — on cybersecurity, data protection, and operational resilience matters.
-
Lead the implementation of cybersecurity programs aligned with OJK Regulation on Cyber Security Management (POJK on Cyber Security), Bappebti crypto-asset regulations, and PDP Law requirements.
-
Regulatory Compliance
Lead the design and implementation of security frameworks and controls aligned with:
-
OJK Cyber Security Management regulations and governance guidelines
-
Bappebti regulations on crypto-asset trading and exchange operations
-
PDP Law (UU PDP) — Indonesia's Personal Data Protection Law
-
Bank Indonesia payment systems and electronic money regulations (as applicable)
-
Kominfo regulations on electronic systems and data protection (PSE framework)
-
Develop and maintain policies, procedures, and documentation to ensure ongoing compliance with Indonesian regulations and international standards.
-
Ensure timely regulatory reporting, breach notifications (including PDP Law's 72-hour notification requirement), and response to regulatory inquiries and audits.
-
Liaise with Indonesian regulatory bodies and ensure proactive engagement on emerging cybersecurity requirements.
-
Risk & Incident Management
-
Oversee risk assessments, security architecture reviews, and cyber risk reporting at the regional level.
-
Implement and maintain incident detection and response capabilities in line with Indonesian regulatory requirements, ensuring proper reporting timelines and impact assessments.
-
Coordinate response to major cyber incidents affecting Indonesian operations, including mandatory breach notifications to OJK/Bappebti/Kominfo as required.
-
Establish and lead the Computer Security Incident Response Team (CSIRT) for Indonesian operations.
-
Third-Party & Supply Chain Risk
-
Ensure third-party ICT service providers meet contractual and regulatory standards, including oversight of cloud service providers and concentration risk assessments.
-
Collaborate with procurement and legal teams to review contracts, conduct due diligence, and manage exit strategies in compliance with PDP Law data transfer and processor obligations.
-
Manage third party integrations risk to ensure alignment with security standards and SLAs.
-
Cybersecurity Operations
-
Guide the security operations function in Indonesia, including vulnerability management, monitoring, and threat intelligence.
-
Partner with global SOC, Security Governance, and IT teams to align threat detection and response capabilities.
-
Drive cyber threat & vulnerability management/penetration tests as per the regulatory framework.
-
Implement robust resilience best practices to ensure that Binance products remain best in class.
-
Cybersecurity Governance
-
Lead Security Risk Management with all stakeholders as per the Security Risk Framework.
-
Accountable to the regulatory authority for all Security and IT Governance matters in Indonesia.
-
Maintain and develop security governance practices including regulatory, board and committee reporting.
-
Work as part of the three lines of defense model to ensure funds, data and systems are secure.
-
Ensure all security obligations for governance, regulatory and compliance matters are delivered.
-
Assist the delivery of internal and external audits related to Technology and Security.
-
IT security risk management for new projects and/or any integration with third-party vendors.
-
Manage the local security team and contribute to continual improvement of the global department.
-
Security incident management, including prompt reporting to senior management and other teams.
-
Facilitate continual alignment to regulatory compliance obligations and international standards.
Requirements
- Fluency in English and Bahasa Indonesia; currently based in Jakarta or willing to relocate.
- Held an approved person's role within a regulated financial institution in Indonesia (preferred).
- Track record of international company