IT Audit Manager
We are seeking a technically strong IT Audit Manager to execute deep-dive technology audits across Bybit's global infrastructure. This is a hands-on technical auditor role — you will assess systems and infrastructure at the configuration, code, and architecture level, not just review process documentation. You will operate across cross-border teams and stakeholders, executing a global audit programme that covers centralised technology processes while testing for local regulatory and operational nuances.
Reporting to the Head of IT Audit, the ideal candidate combines strong technical depth with the ability to navigate a multi-jurisdictional, fast-moving digital asset environment.
Responsibilities
1. Technical Audit Execution
Perform hands-on technical audits of IT infrastructure, cloud environments, APIs, SDLC pipelines, network architecture, and wallet/custody systems.
Conduct configuration reviews, code-level assessments, access control testing, log analysis, and system interface validation.
Assess architecture design, security controls, and deployment pipelines against industry standards and regulatory expectations.
Evaluate compliance with technology, cybersecurity, outsourcing, and digital-asset regulations across multiple jurisdictions.
2. Global Audit Programme Delivery
Execute the global IT audit programme covering centralised processes (cloud infrastructure, network layer, SDLC, API gateway, identity management), adapting scope and testing for jurisdictional differences where applicable.
Coordinate with cross-border teams and regional stakeholders to understand local regulatory requirements, operational differences, and control variations.
3. Audit Planning & Risk Assessment
Conduct technology-risk scanning to identify emerging threats, regulatory changes, and architectural vulnerabilities across Bybit's environment.
Perform technical walkthroughs with Engineering, Security, DevOps, and Product teams to map system architectures, data flows, and control environments.
Contribute to the annual risk-based IT audit plan, prioritising coverage based on technical risk exposure and regulatory obligations.
4. Reporting & Remediation
Develop well-substantiated technical findings with clear risk statements, root-cause analysis, and actionable remediation recommendations.
Prepare concise audit reports for senior management and the Board Audit Committee.
Track remediation progress, validate fixes at a technical level, and maintain status reporting.
5. Collaboration & Industry Awareness
Collaborate with global IA colleagues ("One Team") to ensure consistent coverage and knowledge sharing across regions.
Stay current on emerging technologies, cyber threats, and regulatory developments in cryptocurrency and blockchain.
Support readiness for regulatory reviews, licensing audits, and independent assessments.
Requirements
Qualifications & Experience
Bachelor's degree in Information Systems, Computer Science, Engineering, or related field.
8+ years of IT audit experience in financial services, fintech, or cryptocurrency exchange environments, with a strong technical execution focus.
Demonstrated experience working with cross-border teams and managing stakeholder relationships across multiple jurisdictions.
Core technical experience required:
IT infrastructure & network architecture (firewalls, segmentation, DNS, load balancing, VPN, zero-trust)
Cloud platforms (AWS, Tencent Cloud) — architecture review, IAM, security group configuration, logging & monitoring
API security — authentication, authorisation, rate limiting, input validation, gateway configuration
SDLC — secure coding practices, CI/CD pipeline controls, code review, container security, change management
Preferred experience:
Digital wallet systems & crypto key management (HSM, MPC, multi-sig, cold/warm/hot wallet architecture)
Web3 technology & blockchain security (smart contract auditing, on-chain monitoring, consensus mechanisms, DeFi protocol risks)
Familiarity with digital-asset regulatory frameworks (EU MiCA, UAE VARA, Türkiye, Kazakhstan, Georgia, Indonesia, Argentina) is advantageous.
Technical Skills
Ability to read and assess system configurations, infrastructure-as-code, CI/CD pipelines, and API specifications.
Hands-on experience with cloud security tooling (CloudTrail, GuardDuty, Azure Defender, AWS Config).
Proficiency in log analysis, network traffic assessment, and security testing tools.
Experience leveraging AI tools (e.g., Claude, Clawbot) and data analytics to support audit execution is preferred.
Soft Skills
Strong analytical and problem-solving skills; able to translate technical findings into business-relevant risk language.
Effective communicator across cultures and time zones — comfortable engaging with engineering and product teams globally.
Self-directed; able to manage multiple concurrent audits independently in a globally distributed environment.
Certifications
CISA, CISM, CISSP, or CRISC preferred.
Other Requirements
High integrity, professional skepticism, and attention to detail.
Proficiency in English and Mandarin Chinese.
Location: Hong Kong, Abu Dhabi or Malaysia.