Job Description

About Us

Bybit is one of the world’s fastest-growing cryptocurrency exchanges, serving more than 80 million registered users globally. We provide a professional platform where crypto traders and institutions can access innovative spot and derivatives products, ultra-fast execution infrastructure, institutional-grade security, and industry-leading customer support.

Key Responsibilities

  • Own and drive compliance with Turkish regulatory requirements, including SPK (Sermaye Piyasası Kurulu) crypto exchange licensing conditions, TÜBİTAK BİLGEM security criteria and KVKK (Kişisel Verilerin Korunması Kanunu)
  • Serve as the primary security point of contact for SPK audits, TÜBİTAK external audits, penetration testing and regulatory inspections; prepare and present audit evidence and responses
  • Maintain the local security policy framework aligned with SPK, TÜBİTAK and global standards (ISO 27001, NIST CSF), including access control, network security, encryption, logging, and incident management
  • Lead local incident response as CISO-level incident commander for high-severity events
  • Oversee the security architecture for local infrastructure, cloud environments (AWS, Huawei Cloud), and customer-facing platforms
  • Oversee security controls for hot and cold wallet infrastructure supporting Turkish customer assets, Ensure key management procedures meet SPK custody requirements
  • Build and manage the local security team; define roles, hire talent, develop capabilities
  • Maintain the local information security risk register; present risk status and remediation plans to senior management and the Board
  • Act as the security representative in the Turkish entity's management meetings and regulatory discussions

Requirements

Must Have

  • 8+ years of information security experience, with at least 3 years in a CISO, Deputy CISO, or Head of Security role
  • Demonstrated experience working with Turkish financial regulators (SPK) or participating in TÜBİTAK-criteria audits
  • Strong knowledge of KVKK and its practical implementation
  • Solid understanding of cloud security, network security, and application security
  • Experience building security programs in regulated financial institutions (banking, fintech, capital markets, or crypto)
  • Excellent communication skills in both Turkish and English
  • Strong risk management mindset; ability to translate technical risk into business impact

Nice to Have

  • Direct experience at a cryptocurrency exchange or digital asset company
  • Familiarity with cryptoasset custody security, cold/hot wallet architecture, and key management
  • Certifications: CISSP, CISM, CISA, ISO 27001 Lead Auditor
  • Exposure to multi-jurisdiction compliance (EU, KZ, etc.)