Skip to content

Open nowPosted 6 days ago

Senior Security Engineer — Privacy & Data Security

bitdeer147 open roles

Where
Penang, Malaysia
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Security Engineer — Privacy & Data Securitybitdeer · Penang, Malaysia
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on bitdeer's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.0%30 days
This job: posted 6 days ago

The posting

About Bitdeer:

Bitdeer is a world-leading technology company for Bitcoin mining and AI cloud.

Bitdeer is committed to providing comprehensive Bitcoin mining solutions for its customers. Apart from designing industry-leading ASIC chips and manufacturing mining rigs, the Group handles complex processes involved in computing across the value chain. This includes equipment procurement, transport logistics, datacenter design and construction, equipment management, and network and facility operations. Bitdeer also offers advanced cloud capabilities to customers with a high demand for artificial intelligence.

Headquartered in Singapore, Bitdeer operates globally with a diversified 3 GW energy portfolio, and deploys Bitcoin mining and HPC datacenters in the United States, Bhutan, Norway, Canada, Malaysia, and Ethiopia.

About the team

Build AI Cloud’s global data security and privacy compliance capability to support worldwide delivery of the GPU cloud under GDPR and equivalent frameworks. This role is the bridge between regulatory requirements and infrastructure controls: translating GDPR (especially Art. 28 / 32 / 25) into runnable technical controls on the platform, and producing evidence submittable to customer due diligence and third-party audits. The role sits in the Security Team and works closely with Group Risk & Compliance and Legal.

What you will be responsible for:

  • Encryption & key management: design and implement encryption at rest / in transit, KMS / HSM, BYOK / HYOK, and key lifecycle & rotation, supporting multi-tenancy and data residency.
  • Data discovery & classification: establish PII discovery, classification, and data flow mapping across compute, storage, and logs.
  • Data protection controls: implement DLP, pseudonymization / tokenization, least-privilege access control, and data residency architecture including an EU region.
  • Data subject rights implementation: build capabilities to locate, export, and delete personal data (DSAR), covering logs and backups, and reconcile retention vs. deletion conflicts.
  • Privacy by Design: embed Art. 25 data protection by design and default into product and platform design, including data minimization in telemetry / logs.
  • Cross-border transfer technical measures: design technical supplementary measures under Schrems II for SG↔EU data transfers (e.g., key escrow so the processor cannot access plaintext).
  • Regulation-to-control translation & evidence production: translate key GDPR articles into runnable technical controls; author technical & organizational measures for DPAs (TOMs / SCC Annex II); continuously produce and archive compliance evidence (encryption policies, key rotation, access reviews, pen-test reports) and map controls to SOC 2 / ISO 27001 / ISO 27701 so one piece of evidence serves multiple frameworks.
  • Customer due diligence support: respond to customer security & privacy due diligence on behalf of the Security Team; complete and maintain TOMs and security questionnaires; partner with Legal, the DPO, Group Risk & Compliance, and the infrastructure security sub-team.

How you will stand out:

  • Hands-on data security engineering: 5–8 years in security / data security with hands-on delivery of encryption, KMS / HSM, and cloud security (not policy-only).
  • Privacy engineering: familiar with data flow mapping, DSAR technical implementation, data minimization and de-identification; understands privacy-by-design.
  • Regulation-to-control mapping: able to read key GDPR articles and turn them into TOMs; familiar with SCC Annex II structure and DPA security annex drafting.
  • Cloud / K8s foundation: understands K8s multi-tenant isolation and cloud platform data flows; able to read and integrate with the existing security stack.
  • End-to-end experience: at least one hands-on (not observer) end-to-end GDPR / DPA or equivalent privacy compliance implementation.
  • Documentation & communication: high-quality written documentation; able to converse with legal, engineers, auditors, and customers.
  • GPU / AIDC domain knowledge: understanding of GPU cloud data flows and cross-border architecture.
  • Compliance frameworks: SOC 2 / ISO 27001 / ISO 27701 implementation or audit liaison experience.
  • Automation: automated compliance evidence collection, policy-as-code experience.
  • Certifications (priority): CIPT (preferred) > CIPP/E > ISO 27701 LI/LA; CIPM / CDPSE are pluses but not mandatory.
  • Language: Mandarin for day-to-day collaboration within the Security Team; English for technical documentation, DPA annexes, and customer due diligence.

What you will experience working with us:

  • A culture that values authenticity and diversity of thoughts and backgrounds;
  • An inclusive and respectable environment with open workspaces and exciting start-up spirit;
  • Fast-growing company with the chance to network with industrial pioneers and enthusiasts;
  • Ability to contribute directly and make an impact on the future of the digital asset industry;
  • Involvement in new projects, developing processes/systems;
  • Personal accountability, autonomy, fast growth, and learning opportunities;
  • Attractive welfare benefits and developmental opportunities such as training and mentoring.

--------------------------------------------------------------------

Bitdeer is committed to providing equal employment opportunities in accordance with country, state, and local laws. Bitdeer does not discriminate against employees or applicants based on conditions such as race, colour, gender identity and/or expression, sexual orientation, marital and/or parental status, religion, political opinion, nationality, ethnic background or social origin, social status, disability, age, indigenous status, and union.

#LI-ST1

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against bitdeer's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on bitdeer's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    bitdeer's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.