Data Security & Compliance Operations Intern
Gate
SingaporeInternship12 Aug 2026
About this internship
About Gate
Founded in 2013, Gate is one of the world’s earliest and most trusted cryptocurrency exchanges, currently serving over 54 million users globally. We have thousands of employees across key global markets, with most of the team working fully remotely.
We are building the financial infrastructure of the next era of the internet. Gate is not just a trading platform; it is a set of tools that helps more people truly participate in global financial markets. If you have genuine interest in finance itself, Gate is a place where that interest can turn into real product impact.
What you'll own
Support information security and compliance inquiries across regional entities and prepare initial responses and supporting materials.
Track ISO 27001, PCI DSS, SOC 2 and other compliance projects, including owners, deadlines, progress, evidence gaps, and blockers.
Collect and organize audit evidence, policies, procedures, technical documentation, and system screenshots, ensuring completeness and accuracy.
Review English audit requests, attend English meetings, and follow up on meeting notes and action items.
Maintain compliance trackers and prepare weekly updates on key risks, gaps, overdue items, and next steps.
What we're looking
forMust-haves
Current bachelor’s or master’s student, available at least 4 days/week for 3+ months.
Basic knowledge of ISO 27001, PCI DSS, SOC 2, audit requirements, controls, and evidence.
Internship experience in information security, compliance, audit, risk management, or related fields preferred.
Good English skills, with the ability to review audit materials and participate in English meetings.
Detail-oriented, organized, and proficient with documentation and spreadsheet tools.
Strong sense of confidentiality and responsibility.
strong-to-haves
Background in Information Security, Computer Science, Audit, Risk Management, Law, or related fields.
Experience with compliance audits, evidence collection, control mapping, or remediation tracking.
Knowledge of access control, vulnerability management, log monitoring, endpoint security, or vendor management.