Chief Technology Officer — uSmart Capital
Broker-Dealer | Regulatory Examination & Technology Audit Accountability
1. Overview
uSmart Capital is seeking a Chief Technology Officer to own the technology function of a FINRA member firm registered with the SEC. This role is defined as much by regulatory accountability as by engineering leadership.
In a U.S. broker-dealer, technology is not merely subject to regulation — technology is the compliance record. Order handling, books and records, CAT reporting, pre-trade risk controls, communications retention, and customer data protection all live in systems the CTO owns. When FINRA issues an 8210 request, when the SEC Division of Examinations opens a cycle exam, when the independent accountant tests IT general controls, or when a deficiency letter lands, the CTO is the person who must produce the evidence, explain the control, and close the gap.
We are looking for someone who has done this — not someone who will learn it here.
2. Core Responsibilities
Regulatory Examination & Response
- Act as the firm's principal technology interface to FINRA, the SEC, and other U.S. regulators; own preparation for and response to cycle examinations, for-cause exams, sweep letters, and Rule 8210 information requests
- Own the technology side of regulatory production: data extraction, completeness and accuracy attestation, chain of custody, privilege coordination with Legal, and the ability to reproduce historical system state on demand
- Own technology response to deficiency letters, exam findings, and any undertakings — including root cause, remediation plan with committed dates, interim compensating controls, and closure evidence
- Own regulatory incident notification workflows for system disruptions, cybersecurity events, and customer data incidents, including Regulation S-P customer notification timelines and any applicable Form 8-K or Reg SCI obligations
- Maintain a regulatory change pipeline covering SEC rulemaking, FINRA Regulatory Notices, and CAT technical specification updates; assess technical impact and deliver ahead of compliance dates
Books, Records & Reporting Integrity
- Own the technical architecture for SEC Rules 17a-3 and 17a-4 compliance: retention periods, non-rewriteable/non-erasable storage or the audit-trail alternative, indexing, legal hold, and the ability to furnish records promptly in examinable form
- Own the required undertakings and third-party arrangements associated with electronic recordkeeping (including designated executive officer and third-party access undertakings where applicable)
- Own the technical reliability and accuracy of CAT (Consolidated Audit Trail) reporting: linkage, clock synchronization, error rate management, repair workflows, CAIS data protection, and reconciliation against internal order records
- Own communications capture and archiving across all approved channels — email, chat, mobile, and client-facing messaging — and the technical controls that detect and prevent off-channel communications, an area of sustained enforcement focus
- Ensure systems feeding net capital, customer reserve, and FOCUS reporting are controlled, reconciled, and auditable end to end, in partnership with the FinOp
Trading & Market Access Controls
- Own the technical implementation and evidencing of SEC Rule 15c3-5 market access controls: pre-trade credit and capital thresholds, erroneous order controls, regulatory filter logic, kill switches, and documented annual review of control effectiveness
- Own surveillance, order audit, and trade reconstruction capability sufficient to answer regulator questions about any order, any day
- Own resilience and performance of order routing, execution, and market data infrastructure, including time synchronization to required tolerances
Audit & Independent Assurance
- Own the firm's readiness for the annual audit by the PCAOB-registered independent accountant, including ITGC testing (access, change management, operations) and any compliance/exemption report support
- Own internal audit and independent testing of technology controls under FINRA Rules 3110 and 3120, and supply the technology inputs supporting annual supervisory control and CEO certification processes
- Maintain a documented, evidence-backed IT control framework mapped to applicable rules and to a recognized standard (NIST CSF, SOC 2, ISO 27001) — with control owners, testing cadence, and retained evidence
- Commission and act on penetration testing, red teaming, code review, cloud configuration assessment, and third-party risk reviews; track findings to closure with risk-accepted exceptions formally approved
- Report technology risk, examination status, audit findings, and remediation progress to the CEO, the Board, and relevant committees
Cybersecurity, Privacy & Vendor Governance
- Own the information security program and incident response program required under Regulation S-P (safeguards and disposal), including the 2024 incident response and customer notification requirements
- Own Regulation S-ID identity theft red flags detection controls and customer authentication architecture
- Own third-party and outsourcing governance consistent with FINRA's vendor management expectations: due diligence, contractual audit rights, SOC report review, concentration risk, offshore access controls, and exit planning
- Own data governance across jurisdictions, including controls over access to U.S. customer data by non-U.S. affiliates and personnel
- Where applicable, own compliance with state-level requirements such as NYDFS Part 500 and state data breach statutes
Platform, Resilience & Delivery
- Own architecture and reliability strategy for the trading platform: high availability, disaster recovery, multi-region design, and low-latency performance
- Own business continuity and DR under FINRA Rule 4370: documented plan, annual review, tested failover with evidenced results, and emergency contact reporting
- Lead major incident command (P0/P1), postmortems, regulatory notification, and tracked remediation
- Set technical direction for cloud (AWS ), Kubernetes maturity, observability (Zabbix ), core components (MySQL), and network/perimeter security (Cisco)
- Own capacity planning and stress testing for market-wide volatility events, with documented and repeatable methodology
Leadership
- Build and mentor engineering, SRE/infrastructure, security, and DevOps teams; define hiring standards and succession plans that eliminate key-person dependency
- Own technology budget and vendor spend, and defend both at Board level
- Partner with Compliance, Legal, Risk, Operations, and the business so that regulatory obligations and product roadmap advance together
3. Qualifications
- Bachelor's degree or above in Computer Science, Engineering, or a related field
- 5+ years in technology, with 3+ years leading technology organizations at a U.S. registered broker-dealer, exchange, ATS, or comparable regulated financial institution
- Demonstrated experience owning the technology side of FINRA and/or SEC examinations — responding to 8210 requests, producing data under regulatory deadlines, and closing deficiency findings
- Working command of the rules that shape broker-dealer technology: SEC Rules 17a-3/17a-4, 15c3-5, Regulation S-P and S-ID, CAT reporting obligations, FINRA Rules 3110/3120/4370/4511, and communications retention requirements
- Experience supporting annual independent audits and ITGC testing; familiarity with SOC 2, NIST CSF, or ISO 27001 control frameworks
- Strong hands-on architecture credibility: AWS (EC2, VPC, ELB/ALB, RDS), Kubernetes in production, MySQL HA and tuning, Nginx and high-throughput systems, observability stacks, networking fundamentals
- Ability to satisfy FINRA fit-and-proper standards; willingness to obtain applicable principal registrations (e.g., Series 7/24) if the role's supervisory scope requires
- Experience with low-latency trading, order routing, or market data infrastructure strongly preferred
- Professional fluency in English; Chinese (Mandarin) strongly preferred for group collaboration