IT Audit Manager

Bybit · Abu Dhabi, UAE; Hong Kong SAR; Kuala Lumpur, Malaysia · Operations

Posted 2026-07-22

Apply for this role →

We are seeking a technically strong IT Audit Manager to execute deep-dive technology audits across Bybit's global infrastructure. This is a hands-on technical auditor role — you will assess systems and infrastructure at the configuration, code, and architecture level, not just review process documentation. You will operate across cross-border teams and stakeholders, executing a global audit programme that covers centralised technology processes while testing for local regulatory and operational nuances.

Reporting to the Head of IT Audit, the ideal candidate combines strong technical depth with the ability to navigate a multi-jurisdictional, fast-moving digital asset environment.

Responsibilities

1. Technical Audit Execution

Perform hands-on technical audits of IT infrastructure, cloud environments, APIs, SDLC pipelines, network architecture, and wallet/custody systems.

Conduct configuration reviews, code-level assessments, access control testing, log analysis, and system interface validation.

Assess architecture design, security controls, and deployment pipelines against industry standards and regulatory expectations.

Evaluate compliance with technology, cybersecurity, outsourcing, and digital-asset regulations across multiple jurisdictions.

2. Global Audit Programme Delivery

Execute the global IT audit programme covering centralised processes (cloud infrastructure, network layer, SDLC, API gateway, identity management), adapting scope and testing for jurisdictional differences where applicable.

Coordinate with cross-border teams and regional stakeholders to understand local regulatory requirements, operational differences, and control variations.

3. Audit Planning & Risk Assessment

Conduct technology-risk scanning to identify emerging threats, regulatory changes, and architectural vulnerabilities across Bybit's environment.

Perform technical walkthroughs with Engineering, Security, DevOps, and Product teams to map system architectures, data flows, and control environments.

Contribute to the annual risk-based IT audit plan, prioritising coverage based on technical risk exposure and regulatory obligations.

4. Reporting & Remediation

Develop well-substantiated technical findings with clear risk statements, root-cause analysis, and actionable remediation recommendations.

Prepare concise audit reports for senior management and the Board Audit Committee.

Track remediation progress, validate fixes at a technical level, and maintain status reporting.

5. Collaboration & Industry Awareness

Collaborate with global IA colleagues ("One Team") to ensure consistent coverage and knowledge sharing across regions.

Stay current on emerging technologies, cyber threats, and regulatory developments in cryptocurrency and blockchain.

Support readiness for regulatory reviews, licensing audits, and independent assessments.

Requirements

Qualifications & Experience

Bachelor's degree in Information Systems, Computer Science, Engineering, or related field.

8+ years of IT audit experience in financial services, fintech, or cryptocurrency exchange environments, with a strong technical execution focus.

Demonstrated experience working with cross-border teams and managing stakeholder relationships across multiple jurisdictions.

Core technical experience required:

IT infrastructure & network architecture (firewalls, segmentation, DNS, load balancing, VPN, zero-trust)

Cloud platforms (AWS, Tencent Cloud) — architecture review, IAM, security group configuration, logging & monitoring

API security — authentication, authorisation, rate limiting, input validation, gateway configuration

SDLC — secure coding practices, CI/CD pipeline controls, code review, container security, change management

Preferred experience:

Digital wallet systems & crypto key management (HSM, MPC, multi-sig, cold/warm/hot wallet architecture)

Web3 technology & blockchain security (smart contract auditing, on-chain monitoring, consensus mechanisms, DeFi protocol risks)

Familiarity with digital-asset regulatory frameworks (EU MiCA, UAE VARA, Türkiye, Kazakhstan, Georgia, Indonesia, Argentina) is advantageous.

Technical Skills

Ability to read and assess system configurations, infrastructure-as-code, CI/CD pipelines, and API specifications.

Hands-on experience with cloud security tooling (CloudTrail, GuardDuty, Azure Defender, AWS Config).

Proficiency in log analysis, network traffic assessment, and security testing tools.

Experience leveraging AI tools (e.g., Claude, Clawbot) and data analytics to support audit execution is preferred.

Soft Skills

Strong analytical and problem-solving skills; able to translate technical findings into business-relevant risk language.

Effective communicator across cultures and time zones — comfortable engaging with engineering and product teams globally.

Self-directed; able to manage multiple concurrent audits independently in a globally distributed environment.

Certifications

CISA, CISM, CISSP, or CRISC preferred.

Other Requirements

High integrity, professional skepticism, and attention to detail.

Proficiency in English and Mandarin Chinese.

Location: Hong Kong, Abu Dhabi or Malaysia.

Apply for this role →

← Back to all jobs