Information Security Officer
IT · Full-time
Istanbul, İstanbul, Turkey
About Us
Key Responsibilities
- Own and drive compliance with Turkish regulatory requirements, including SPK (Sermaye Piyasası Kurulu) crypto exchange licensing conditions, TÜBİTAK BİLGEM security criteria and KVKK (Kişisel Verilerin Korunması Kanunu)
- Serve as the primary security point of contact for SPK audits, TÜBİTAK external audits, penetration testing and regulatory inspections; prepare and present audit evidence and responses
- Maintain the local security policy framework aligned with SPK, TÜBİTAK and global standards (ISO 27001, NIST CSF), including access control, network security, encryption, logging, and incident management
- Lead local incident response as CISO-level incident commander for high-severity events
- Oversee the security architecture for local infrastructure, cloud environments (AWS, Huawei Cloud), and customer-facing platforms
- Oversee security controls for hot and cold wallet infrastructure supporting Turkish customer assets, Ensure key management procedures meet SPK custody requirements
- Build and manage the local security team; define roles, hire talent, develop capabilities
- Maintain the local information security risk register; present risk status and remediation plans to senior management and the Board
- Act as the security representative in the Turkish entity's management meetings and regulatory discussions
Requirements
Must Have
- 8+ years of information security experience, with at least 3 years in a CISO, Deputy CISO, or Head of Security role
- Demonstrated experience working with Turkish financial regulators (SPK) or participating in TÜBİTAK-criteria audits
- Strong knowledge of KVKK and its practical implementation
- Solid understanding of cloud security, network security, and application security
- Experience building security programs in regulated financial institutions (banking, fintech, capital markets, or crypto)
- Excellent communication skills in both Turkish and English
- Strong risk management mindset; ability to translate technical risk into business impact
Nice to Have
- Direct experience at a cryptocurrency exchange or digital asset company
- Familiarity with cryptoasset custody security, cold/hot wallet architecture, and key management
- Certifications: CISSP, CISM, CISA, ISO 27001 Lead Auditor
- Exposure to multi-jurisdiction compliance (EU, KZ, etc.)
Why Join Us
At Bybit, we are committed to fostering a supportive and enriching work environment.
Our benefits include:
- Study Growth Fund: We support your professional development and continuous learning.
- Internal Events: Participate in regular team-building activities, workshops, and events designed to promote collaboration and innovation.
- Global Collaboration: Be part of a diverse, international team, working alongside colleagues from around the world.
- Career Advancement: Access opportunities for growth and advancement within a rapidly expanding global company.
- Internal Mobility: Grow with us- Your long-term development is important to us. We offer internal job opportunities to help build your career path.