Job Description
About Libeara
Libeara is rebuilding capital markets on-chain through its compliance-first approach to tokenising real-world assets. The company is backed by SC Ventures, the innovation arm of Standard Chartered, whose mission is to rewire the DNA of banking.
To date, Libeara's infrastructure has supported the tokenisation of more than US$1 billion in regulated assets — including the world's highest-rated tokenised US Treasury fund and Asia's first tokenised retail money market fund. With multi-chain interoperability and institutional-grade security and governance, Libeara is scaling access to real-world assets the right way: transparent, regulated, and on-chain.
Please visit https://libeara.com to find out more about our company.
Role
We're looking for an Information Security Officer to support the implementation and ongoing development of our information and cybersecurity programme. Reporting to the Chief Information Security Officer (CISO), you will help protect the organisation's technology environment, products, systemsand data, while supporting the delivery of secure and resilient services to our clients.
This is a hands-on role covering cloud and infrastructure security, application and product security, identity and access management, vulnerability and incident management, third-party security risk, and security assurance and certifications, including SOC 2 and ISO 27001. You will work closely with Engineering, Product, Technology, Legal, Risk and Compliance to translate security risks and requirements into practical controls and remediation actions.
Responsibilities
Information Security and Risk Management
- Support the CISO in implementing the organisation's cybersecurity strategy, roadmap, policies and security control framework
- Conduct security risk assessments, monitor emerging threats and vulnerabilities, and drive identified remediation actions through to completion
- Lead the day-to-day delivery of security assurance and certification programmes, including SOC 2 and ISO 27001, and coordinate control assessments, audit readiness and remediation
- Support compliance with applicable financial services regulatory and cybersecurity requirements, and maintain appropriate security risk, control and reporting records
- Conduct third-party security assessments, support client security due diligence, and deliver cybersecurity awareness and training across the organisation
Security Operations and Incident Management
- Oversee and operate security controls across cloud infrastructure, endpoints, networks, identity and access management, privileged access and other technology environments
- Manage vulnerability assessments, penetration testing and remediation, and monitor and investigate security events and vulnerabilities
- Maintain and test cybersecurity incident response procedures, and coordinate the investigation, containment, remediation, and post-incident review of security incidents
- Work closely with the System Administrator, providing day-to-day guidance on secure configurations, patching, endpoint security, access controls and other security priorities
Application and Product Security
- Partner with Engineering and Product to embed security throughout the design, development, testing and deployment of products and platforms
- Drive Secure Software Development Lifecycle (Secure SDLC), DevSecOps and security-by-design practices across the technology development lifecycle
- Assess security risks across applications, cloud infrastructure, APIs, containerisation, blockchain and other emerging technologies, and work with Engineering to remediate identified vulnerabilities
Requirements
- Degree in Information Technology, Computer Science, Engineering, Cybersecurity or a related discipline, with relevant certifications such as CISSP, CISM, CISA or CCSP preferred
- 7–10 years of information security or cybersecurity experience, preferably within financial services, fintech or another highly regulated environment
- Strong hands-on experience across cloud and application security, Secure SDLC, vulnerability management, identity and access management, security monitoring and incident response
- Strong knowledge of security frameworks and standards, including ISO 27001, SOC 2 and NIST, with experience supporting security audits, certifications and regulatory requirements
- Strong stakeholder management and communication skills, with experience guiding technical team members; experience in blockchain, digital assets or distributed ledger technology is a significant advantage



