Information Security Officer

About Us

Established in 2018, Bybit is one of the world’s leading cryptocurrency exchanges and digital financial platforms, serving over 80 million users across more than 200 countries and regions. Powered by world-class technology and a user-first mindset, Bybit delivers a seamless ecosystem across trading, payments, wealth management, custody, institutional services, and Web3 — connecting users to the future of digital finance.
Our core values define how we build. We listen, care and improve to create products and experiences that put users first. Backed by a global team of ambitious builders, problem-solvers, and innovators, we foster a high-performance and fast-moving environment where talent is empowered to drive real impact at the global scale. Supported by 24/7 multilingual customer service and a strong commitment to innovation, we are shaping the future of finance through technology, collaboration, and bold execution.
Today, Bybit is recognized as one of the most trusted and transparent platforms in the digital asset industry, continuing to expand its global presence while building the infrastructure for the next generation of financial services.

Key Responsibilities

  • Own and drive compliance with Turkish regulatory requirements, including SPK (Sermaye Piyasası Kurulu) crypto exchange licensing conditions, TÜBİTAK BİLGEM security criteria and KVKK (Kişisel Verilerin Korunması Kanunu)
  • Serve as the primary security point of contact for SPK audits, TÜBİTAK external audits, penetration testing and regulatory inspections; prepare and present audit evidence and responses
  • Maintain the local security policy framework aligned with SPK, TÜBİTAK and global standards (ISO 27001, NIST CSF), including access control, network security, encryption, logging, and incident management
  • Lead local incident response as CISO-level incident commander for high-severity events
  • Oversee the security architecture for local infrastructure, cloud environments (AWS, Huawei Cloud), and customer-facing platforms
  • Oversee security controls for hot and cold wallet infrastructure supporting Turkish customer assets, Ensure key management procedures meet SPK custody requirements
  • Build and manage the local security team; define roles, hire talent, develop capabilities
  • Maintain the local information security risk register; present risk status and remediation plans to senior management and the Board
  • Act as the security representative in the Turkish entity's management meetings and regulatory discussions

Requirements

Must Have

  • 8+ years of information security experience, with at least 3 years in a CISO, Deputy CISO, or Head of Security role
  • Demonstrated experience working with Turkish financial regulators (SPK) or participating in TÜBİTAK-criteria audits
  • Strong knowledge of KVKK and its practical implementation
  • Solid understanding of cloud security, network security, and application security
  • Experience building security programs in regulated financial institutions (banking, fintech, capital markets, or crypto)
  • Excellent communication skills in both Turkish and English
  • Strong risk management mindset; ability to translate technical risk into business impact

Nice to Have

  • Direct experience at a cryptocurrency exchange or digital asset company
  • Familiarity with cryptoasset custody security, cold/hot wallet architecture, and key management
  • Certifications: CISSP, CISM, CISA, ISO 27001 Lead Auditor
  • Exposure to multi-jurisdiction compliance (EU, KZ, etc.)

Why Join Us
At Bybit, we are committed to fostering a supportive and enriching work environment.
Our benefits include:
- Study Growth Fund: We support your professional development and continuous learning.
- Internal Events: Participate in regular team-building activities, workshops, and events designed to promote collaboration and innovation.
- Global Collaboration: Be part of a diverse, international team, working alongside colleagues from around the world.
- Career Advancement: Access opportunities for growth and advancement within a rapidly expanding global company.
- Internal Mobility: Grow with us- Your long-term development is important to us. We offer internal job opportunities to help build your career path.

What this application asks

greenhouse

First Name, Last Name, Email, Phone, Resume/CV, Cover Letter

  • Preferred First Name optional
  • Are you legally authorized to work in the country where this role is based? choose one
  • What is your current location (City & Country)? optional
  • What is your earliest available start date? optional
  • What is your current employment status? choose one
  • What is your highest level of education? choose one
  • Have you owned and driven compliance with Turkish regulatory requirements, including SPK (Sermaye Piyasası Kurulu) crypto exchange licensing conditions, TÜBİTAK BİLGEM security criteria and KVKK (Kişisel Verilerin Korunması Kanunu), If yes, please elaborate. written answer
  • Have you served as the primary security point of contact for SPK audits, TÜBİTAK external audits, penetration testing and regulatory inspections; prepare and present audit evidence and responses? If yes, please elaborate. written answer
  • Have you maintained the local security policy framework aligned with SPK, TÜBİTAK and global standards (ISO 27001, NIST CSF), including access control, network security, encryption, logging, and incident management? If yes, please elaborate further. written answer
  • What is your current base salary per month? (with currency)
  • What is your expected base salary per month? (with currency)
  • What is your notice period?
  • Please confirm that the information provided is true and complete. choose one

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available