Chief Information Security Officer (Turkey)
Indexed description
About Us
Bybit is one of the world’s fastest-growing cryptocurrency exchanges, serving more than 80 million registered users globally. We provide a professional platform where crypto traders and institutions can access innovative spot and derivatives products, ultra-fast execution infrastructure, institutional-grade security, and industry-leading customer support.
Key Responsibilities
- Own and drive compliance with Turkish regulatory requirements, including SPK (Sermaye Piyasası Kurulu) crypto exchange licensing conditions, TÜBİTAK BİLGEM security criteria and KVKK (Kişisel Verilerin Korunması Kanunu)
- Serve as the primary security point of contact for SPK audits, TÜBİTAK external audits, penetration testing and regulatory inspections; prepare and present audit evidence and responses
- Maintain the local security policy framework aligned with SPK, TÜBİTAK and global standards (ISO 27001, NIST CSF), including access control, network security, encryption, logging, and incident management
- Lead local incident response as CISO-level incident commander for high-severity events
- Oversee the security architecture for local infrastructure, cloud environments (AWS, Huawei Cloud), and customer-facing platforms
- Oversee security controls for hot and cold wallet infrastructure supporting Turkish customer assets, Ensure key management procedures meet SPK custody requirements
- Build and manage the local security team; define roles, hire talent, develop capabilities
- Maintain the local information security risk register; present risk status and remediation plans to senior management and the Board
- Act as the security representative in the Turkish entity's management meetings and regulatory discussions
Requirements
Must Have
- 8+ years of information security experience, with at least 3 years in a CISO, Deputy CISO, or Head of Security role
- Demonstrated experience working with Turkish financial regulators (SPK) or participating in TÜBİTAK-criteria audits
- Strong knowledge of KVKK and its practical implementation
- Solid understanding of cloud security, network security, and application security
- Experience building security programs in regulated financial institutions (banking, fintech, capital markets, or crypto)
- Excellent communication skills in both Turkish and English
- Strong risk management mindset; ability to translate technical risk into business impact
Nice to Have
- Direct experience at a cryptocurrency exchange or digital asset company
- Familiarity with cryptoasset custody security, cold/hot wallet architecture, and key management
- Certifications: CISSP, CISM, CISA, ISO 27001 Lead Auditor
- Exposure to multi-jurisdiction compliance (EU, KZ, etc.)
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search