Chief Information Security Officer

Bybit · Hong Kong SAR · Engineering

Posted 2026-09-25

Apply for this role →

Responsibilities

Regulatory Support & MIC-IT Enablement: Serve as the primary cybersecurity anchor for Spark. Work intimately with the ROs and MIC-IT to design, implement, and evidence the cybersecurity framework, ensuring senior management possesses full visibility and control over cyber risks as expected by the SFC.

Pre-Launch & Independent Assessments: Take total ownership of preparing for, facilitating, and successfully passing the SFC-mandated pre-launch independent cybersecurity assessments. Remediate any findings swiftly and effectively prior to go-live.

Cybersecurity Framework & Operations: Architect, deploy, and govern Spark’s comprehensive cybersecurity framework. Ensure strict alignment with ISO/IEC 27001, SFC guidelines, and industry best practices for network, application, and endpoint security.

Incident Readiness & Response: Develop, test, and maintain robust Cyber Incident Response Plans (CIRP) and Disaster Recovery/Business Continuity Plans (DR/BCP). Lead tabletop exercises and ensure the organization is perpetually ready to detect, contain, and eradicate threats.

Ongoing Cyber Controls: Establish a continuous monitoring environment. Oversee regular penetration testing, vulnerability scanning, threat intelligence gathering, and the implementation of Zero-Trust architecture across Spark’s infrastructure.

Leadership & Cross-Functional Collaboration

Strategic Alignment: Report directly to the CTO while operating with the independence necessary to challenge technical architectures from a security and risk perspective.

Security Culture: Champion a security-first culture across the engineering, product, and operations teams at Spark. Develop and execute ongoing security awareness training for all employees.

Vendor Risk Management: Oversee the security evaluation of third-party vendors, SaaS providers, and blockchain analytics platforms, ensuring external integrations do not compromise Spark’s internal security posture.

Local Presence & Communication: Serve as the on-the-ground security leader in Hong Kong. Communicate complex security risks in clear, business-centric terms to the Board, C-suite, and regulators.

Communication: Exceptional verbal and written communication skills in English (fluency in Mandarin is a strong plus given the Hong Kong location).

Educational & Professional Qualifications

Academic Background: Holds a relevant university degree (Bachelor’s required, Master’s preferred) in Cybersecurity, Computer Science, Information Technology, or a related highly technical discipline.

Industry Certifications: Must possesses active, industry-recognized professional cybersecurity certifications such as CISSP, CISM, CISA, or CRISC.

Specialized Credentials (Optional but Preferred): Additional certifications in cloud security (e.g., CCSP), offensive security (e.g., OSCP), or blockchain/smart contract security demonstrate a strong advantage.

Extensive Security Tenure: 10+ years of dedicated experience in cybersecurity, risk management, or IT audit, with at least 3-5 years in a senior leadership or Head of InfoSec capacity within the financial services sector (TradFi, FinTech, or Digital Assets).

SFC VASP/VATP Expertise: Demonstrates sufficient, highly relevant experience directly navigating Hong Kong SFC VASP / VATP (Type 1 & Type 7) license applications from a cybersecurity perspective.

Digital Asset Security: Deep, hands-on operational experience with the unique threat vectors of the crypto industry. Proven expertise in securing Hot/Cold/Warm wallet infrastructures, Multi-Party Computation (MPC), Hardware Security Modules (HSMs), and node network security.

Apply for this role →

← Back to all jobs