Summary / TL;DR
This position is closed and no longer accepting applications. Ho Chi Minh City, Vietnam · Hybrid · Full Time We will also consider exceptional candidates based in Singapore or Kuala Lumpur. About OpenEden OpenEden operates a leading real-world asset (RWA) tokenization platform, renowned for its unmatched focus on regulatory standards and advanced financial technology. Founded in 2022, OpenEden bridges traditional and decentralized finance by providing, through its regulated entities in Bermuda and the BVI, secure, transparent, and compliant on-chain access to tokenized RWA. OpenEden is tokenizing global finance with a core focus on compliance and innovation. About the Role We are looking for an IT Operations Manager to run OpenEden's day-to-day IT operations. The role spans two connected layers. The first is the corporate layer — identity, devices, SaaS and the joiner–mover–leaver lifecycle. The second is security across our cloud infrastructure aligned with regulatory standards for Technology Risk Management and Cyber Security. This is a hands-on individual contributor role focused on the design, implementation and ongoing management of security controls. You will work closely with our DevOps and Engineering teams, report to the CTO, and partner with the CRO and CISO on risk, governance and oversight. Responsibilities Identity, access and endpoints Administer the identity provider and enforce phishing-resistant MFA across company systems Run the joiner–mover–leaver process end to end: same-day provisioning and, critically, same-day revocation across corporate systems, production access and signing authority Run periodic access reviews across corporate systems, cloud, production and multisig signers, and maintain the evidence that they happened Manage the device fleet — MDM, disk encryption, EDR, patch compliance — and report on its state rather than assume it Administer core SaaS platforms: provisioning, licences, data retention, offboarding Manage bastion access for production: account lifecycle, session logging, grant and revoke Move remaining shared accounts onto individually named accounts across the estate Cloud and infrastructure security Maintain and strengthen security controls across AWS — IAM, access, logging, network security Identify threats, vulnerabilities, misconfigurations and access risk across systems, and drive remediation through to closure Maintain secrets management standards and rotation policy, partnering with DevOps and Engineering on CI secrets and deploy keys Monitor system health, investigate security alerts, and lead incident response, including coordination with internal teams and external providers for containment, recovery and escalation Support the testing and continuous improvement of disaster recovery and resilience processes, and help maintain recovery procedures for critical systems Risk, governance and assurance Maintain and actively manage the Technology Risk Management (TRM) register: identification, tracking and remediation Act as the security gatekeeper, performing security reviews of new features, smart contract integrations and system architectures prior to launch Lead third-party and vendor risk reviews Manage security vendors day to day (MSSP, monitoring tools), ensuring effective coverage and response capability Produce and maintain the security evidence behind audits, counterparty due diligence questionnaires, and ISO 27001 / SOC 2 readiness We Are Looking For Someone Who Has 3-7 years in IT Operations, engineering or DevOps/DevSecOps, hands-on identity administration: Microsoft Suite plus an identity provider (Okta, Entra, JumpCloud) — SAML/OIDC, SCIM provisioning, conditional access, group-based entitlements. Not familiarity: you have built the provisioning rules yourself Fleet-scale MDM experience (Jamf, Kandji or Intune) — enrolment, compliance policy, remote wipe, patch enforcement Strong hands-on cloud security experience, AWS preferred — IAM, logging, networking Solid Linux and SSH fundamentals: sudo policy, key versus certificate auth, session logging, host hardening Practical scripting ability in Python or Bash, with an API-first instinct Experience working with or managing external security vendors Clear written English and genuine documentation discipline — runbooks, policies and audit evidence others can follow The judgment to escalate clearly, and the composure to hold a position with senior stakeholders when the answer has to be no Experience in startups or fast-moving environments, and comfort working in a small, collaborative team Preferred Qualifications Experience working within a regulated environment (e.g. MAS, BMA, FCA, SEC) Experience supporting ISO 27001 or SOC 2 audits from the operator side — producing evidence, not only reading policy Familiarity with centralised logging or detection tooling What We Offer A chance to directly contribute to the success and growth of one of the most reputable and regulated RWA tokenization platforms in the space, with a proven commercial track record Supportive culture that values clear communication and high-quality execution Competitive compensation Eligibility to participate in the Employee Stock Option Scheme and token incentive allocation Flexible work arrangements