Information Security Officer

Bybit · Istanbul, Turkey · Engineering

Posted 2026-07-07

Apply for this role →

Key Responsibilities

Own and drive compliance with Turkish regulatory requirements, including SPK (Sermaye Piyasası Kurulu) crypto exchange licensing conditions, TÜBİTAK BİLGEM security criteria and KVKK (Kişisel Verilerin Korunması Kanunu)

Serve as the primary security point of contact for SPK audits, TÜBİTAK external audits, penetration testing and regulatory inspections; prepare and present audit evidence and responses

Maintain the local security policy framework aligned with SPK, TÜBİTAK and global standards (ISO 27001, NIST CSF), including access control, network security, encryption, logging, and incident management

Lead local incident response as CISO-level incident commander for high-severity events

Oversee the security architecture for local infrastructure, cloud environments (AWS, Huawei Cloud), and customer-facing platforms

Oversee security controls for hot and cold wallet infrastructure supporting Turkish customer assets, Ensure key management procedures meet SPK custody requirements

Build and manage the local security team; define roles, hire talent, develop capabilities

Maintain the local information security risk register; present risk status and remediation plans to senior management and the Board

Act as the security representative in the Turkish entity's management meetings and regulatory discussions

Requirements

Must Have

8+ years of information security experience, with at least 3 years in a CISO, Deputy CISO, or Head of Security role

Demonstrated experience working with Turkish financial regulators (SPK) or participating in TÜBİTAK-criteria audits

Strong knowledge of KVKK and its practical implementation

Solid understanding of cloud security, network security, and application security

Experience building security programs in regulated financial institutions (banking, fintech, capital markets, or crypto)

Excellent communication skills in both Turkish and English

Strong risk management mindset; ability to translate technical risk into business impact

Nice to Have

Direct experience at a cryptocurrency exchange or digital asset company

Familiarity with cryptoasset custody security, cold/hot wallet architecture, and key management

Certifications: CISSP, CISM, CISA, ISO 27001 Lead Auditor

Exposure to multi-jurisdiction compliance (EU, KZ, etc.)

Apply for this role →

← Back to all jobs