Bitdeer
Bitdeer~8h ago
New

Senior Security Engineer — Privacy & Data Security

MalaysiaMalaysia·George Townsenior
EngineeringSecurity Engineer
3 views0 saves0 applied

Quick Summary

Key Responsibilities

Encryption & key management: design and implement encryption at rest / in transit, KMS / HSM, BYOK / HYOK, and key lifecycle & rotation, supporting multi-tenancy and data residency.

Requirements Summary

translating GDPR (especially Art. 28 / 32 / 25) into runnable technical controls on the platform, and producing evidence submittable to customer due diligence and third-party audits.

Technical Tools
EngineeringSecurity Engineer

Bitdeer is a world-leading technology company for Bitcoin mining and AI cloud.

Bitdeer is committed to providing comprehensive Bitcoin mining solutions for its customers. Apart from designing industry-leading ASIC chips and manufacturing mining rigs, the Group handles complex processes involved in computing across the value chain. This includes equipment procurement, transport logistics, datacenter design and construction, equipment management, and network and facility operations. Bitdeer also offers advanced cloud capabilities to customers with a high demand for artificial intelligence.

Headquartered in Singapore, Bitdeer operates globally with a diversified 3 GW energy portfolio, and deploys Bitcoin mining and HPC datacenters in the United States, Bhutan, Norway, Canada, Malaysia, and Ethiopia.

Build AI Cloud’s global data security and privacy compliance capability to support worldwide delivery of the GPU cloud under GDPR and equivalent frameworks. This role is the bridge between regulatory requirements and infrastructure controls: translating GDPR (especially Art. 28 / 32 / 25) into runnable technical controls on the platform, and producing evidence submittable to customer due diligence and third-party audits. The role sits in the Security Team and works closely with Group Risk & Compliance and Legal.

Responsibilities

~2 min read
  • →Encryption & key management: design and implement encryption at rest / in transit, KMS / HSM, BYOK / HYOK, and key lifecycle & rotation, supporting multi-tenancy and data residency.
  • →Data discovery & classification: establish PII discovery, classification, and data flow mapping across compute, storage, and logs.
  • →Data protection controls: implement DLP, pseudonymization / tokenization, least-privilege access control, and data residency architecture including an EU region.
  • →Data subject rights implementation: build capabilities to locate, export, and delete personal data (DSAR), covering logs and backups, and reconcile retention vs. deletion conflicts.
  • →Privacy by Design: embed Art. 25 data protection by design and default into product and platform design, including data minimization in telemetry / logs.
  • →Cross-border transfer technical measures: design technical supplementary measures under Schrems II for SG↔EU data transfers (e.g., key escrow so the processor cannot access plaintext).
  • →Regulation-to-control translation & evidence production: translate key GDPR articles into runnable technical controls; author technical & organizational measures for DPAs (TOMs / SCC Annex II); continuously produce and archive compliance evidence (encryption policies, key rotation, access reviews, pen-test reports) and map controls to SOC 2 / ISO 27001 / ISO 27701 so one piece of evidence serves multiple frameworks.
  • →Customer due diligence support: respond to customer security & privacy due diligence on behalf of the Security Team; complete and maintain TOMs and security questionnaires; partner with Legal, the DPO, Group Risk & Compliance, and the infrastructure security sub-team.
  • →A culture that values authenticity and diversity of thoughts and backgrounds;
  • →An inclusive and respectable environment with open workspaces and exciting start-up spirit;
  • →Fast-growing company with the chance to network with industrial pioneers and enthusiasts;
  • →Ability to contribute directly and make an impact on the future of the digital asset industry;
  • →Involvement in new projects, developing processes/systems;
  • →Personal accountability, autonomy, fast growth, and learning opportunities;
  • →Attractive welfare benefits and developmental opportunities such as training and mentoring.

--------------------------------------------------------------------

Bitdeer is committed to providing equal employment opportunities in accordance with country, state, and local laws. Bitdeer does not discriminate against employees or applicants based on conditions such as race, colour, gender identity and/or expression, sexual orientation, marital and/or parental status, religion, political opinion, nationality, ethnic background or social origin, social status, disability, age, indigenous status, and union.


#LI-ST1

  • Hands-on data security engineering: 5–8 years in security / data security with hands-on delivery of encryption, KMS / HSM, and cloud security (not policy-only).
  • Privacy engineering: familiar with data flow mapping, DSAR technical implementation, data minimization and de-identification; understands privacy-by-design.
  • Regulation-to-control mapping: able to read key GDPR articles and turn them into TOMs; familiar with SCC Annex II structure and DPA security annex drafting.
  • Cloud / K8s foundation: understands K8s multi-tenant isolation and cloud platform data flows; able to read and integrate with the existing security stack.
  • End-to-end experience: at least one hands-on (not observer) end-to-end GDPR / DPA or equivalent privacy compliance implementation.
  • Documentation & communication: high-quality written documentation; able to converse with legal, engineers, auditors, and customers.
  • GPU / AIDC domain knowledge: understanding of GPU cloud data flows and cross-border architecture.
  • Compliance frameworks: SOC 2 / ISO 27001 / ISO 27701 implementation or audit liaison experience.
  • Automation: automated compliance evidence collection, policy-as-code experience.
  • Certifications (priority): CIPT (preferred) > CIPP/E > ISO 27701 LI/LA; CIPM / CDPSE are pluses but not mandatory.
  • Language: Mandarin for day-to-day collaboration within the Security Team; English for technical documentation, DPA annexes, and customer due diligence.

Location & Eligibility

Where is the job
George Town, Malaysia
On-site at the office
Who can apply
Open to applicants worldwide

Listing Details

First seen
September 28, 2026
Last seen
September 28, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
66%
Scored at
September 28, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

BitdeerSenior Security Engineer — Privacy & Data Security