Information Security Officer
Key Responsibilities
Own and drive compliance with Turkish regulatory requirements, including SPK (Sermaye Piyasası Kurulu) crypto exchange licensing conditions, TÜBİTAK BİLGEM security criteria and KVKK (Kişisel Verilerin Korunması Kanunu)
Serve as the primary security point of contact for SPK audits, TÜBİTAK external audits, penetration testing and regulatory inspections; prepare and present audit evidence and responses
Maintain the local security policy framework aligned with SPK, TÜBİTAK and global standards (ISO 27001, NIST CSF), including access control, network security, encryption, logging, and incident management
Lead local incident response as CISO-level incident commander for high-severity events
Oversee the security architecture for local infrastructure, cloud environments (AWS, Huawei Cloud), and customer-facing platforms
Oversee security controls for hot and cold wallet infrastructure supporting Turkish customer assets, Ensure key management procedures meet SPK custody requirements
Build and manage the local security team; define roles, hire talent, develop capabilities
Maintain the local information security risk register; present risk status and remediation plans to senior management and the Board
Act as the security representative in the Turkish entity's management meetings and regulatory discussions
Requirements
Must Have
8+ years of information security experience, with at least 3 years in a CISO, Deputy CISO, or Head of Security role
Demonstrated experience working with Turkish financial regulators (SPK) or participating in TÜBİTAK-criteria audits
Strong knowledge of KVKK and its practical implementation
Solid understanding of cloud security, network security, and application security
Experience building security programs in regulated financial institutions (banking, fintech, capital markets, or crypto)
Excellent communication skills in both Turkish and English
Strong risk management mindset; ability to translate technical risk into business impact
Nice to Have
Direct experience at a cryptocurrency exchange or digital asset company
Familiarity with cryptoasset custody security, cold/hot wallet architecture, and key management
Certifications: CISSP, CISM, CISA, ISO 27001 Lead Auditor
Exposure to multi-jurisdiction compliance (EU, KZ, etc.)