Chief Information Security Officer

Bybit

United States

On-site

USD 191,000 - 344,000

Full time

8 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Growth Fund
Internal Events
Global Collaboration
Career Advancement
Internal Mobility

Job summary

Bybit is seeking a senior Information Security leader to guide cybersecurity strategy and governance from Hong Kong. You will report to the CTO, drive security architecture, policy, and controls across networks, apps, and endpoints, and oversee incident response and continuity planning.

The role requires 10+ years in cybersecurity/risk, with 3–5 years in senior leadership within financial services or digital assets. Mandarin is a strong plus for local collaboration.

Qualifications

  • Requires a university degree in cybersecurity, CS, IT or related technical field.
  • Active, recognized cybersecurity certifications (CISSP/CISM/CISA/CRISC) required.
  • 10+ years in cybersecurity/risk, with 3–5 years in senior leadership in financial services/fintech/digital assets.

Responsibilities

  • Serve as the primary cybersecurity anchor for Spark within Bybit’s HK operations.
  • Lead pre-launch independent cybersecurity assessments and remediation before go-live.
  • Architect and govern a comprehensive cybersecurity framework aligned with ISO/IEC 27001 and SFC guidelines.
  • Develop, test, and maintain Cyber Incident Response Plans and DR/BCP; run tabletop exercises.
  • Oversee continuous monitoring, penetration testing, vulnerability scanning, and Zero-Trust adoption.

Skills

English fluency
Mandarin a plus

Education

Bachelor's degree in Cybersecurity/CS/IT
Master’s degree preferred
CISSP/CISM/CISA/CRISC
CCSP/OSCP/blockchain security certs
10+ years cybersecurity/IT risk
3–5 years in senior leadership in finance/fintech/digital assets

Job description

About Us

Established in 2018, Bybit is one of the world’s leading cryptocurrency exchanges and digital financial platforms, serving over 80 million users across more than 200 countries and regions. Powered by world-class technology and a user-first mindset, Bybit delivers a seamless ecosystem across trading, payments, wealth management, custody, institutional services, and Web3 — connecting users to the future of digital finance.

Our core values define how we build. We listen, care and improve to create products and experiences that put users first. Backed by a global team of ambitious builders, problem-solvers, and innovators, we foster a high-performance and fast-moving environment where talent is empowered to drive real impact at the global scale. Supported by 24/7 multilingual customer service and a strong commitment to innovation, we are shaping the future of finance through technology, collaboration, and bold execution.

Today, Bybit is recognized as one of the most trusted and transparent platforms in the digital asset industry, continuing to expand its global presence while building the infrastructure for the next generation of financial services.

Responsibilities
  • Regulatory Support & MIC-IT Enablement: Serve as the primary cybersecurity anchor for Spark. Work intimately with the ROs and MIC-IT to design, implement, and evidence the cybersecurity framework, ensuring senior management possesses full visibility and control over cyber risks as expected by the SFC.
  • Pre-Launch & Independent Assessments: Take total ownership of preparing for, facilitating, and successfully passing the SFC-mandated pre-launch independent cybersecurity assessments. Remediate any findings swiftly and effectively prior to go-live.
  • Cybersecurity Framework & Operations: Architect, deploy, and govern Spark’s comprehensive cybersecurity framework. Ensure strict alignment with ISO/IEC 27001, SFC guidelines, and industry best practices for network, application, and endpoint security.
  • Incident Readiness & Response: Develop, test, and maintain robust Cyber Incident Response Plans (CIRP) and Disaster Recovery/Business Continuity Plans (DR/BCP). Lead tabletop exercises and ensure the organization is perpetually ready to detect, contain, and eradicate threats.
  • Ongoing Cyber Controls: Establish a continuous monitoring environment. Oversee regular penetration testing, vulnerability scanning, threat intelligence gathering, and the implementation of Zero-Trust architecture across Spark’s infrastructure.
Leadership & Cross-Functional Collaboration
  • Strategic Alignment: Report directly to the CTO while operating with the independence necessary to challenge technical architectures from a security and risk perspective.
  • Security Culture: Champion a security-first culture across the engineering, product, and operations teams at Spark. Develop and execute ongoing security awareness training for all employees.
  • Vendor Risk Management: Oversee the security evaluation of third-party vendors, SaaS providers, and blockchain analytics platforms, ensuring external integrations do not compromise Spark’s internal security posture.
  • Local Presence & Communication: Serve as the on-the-ground security leader in Hong Kong. Communicate complex security risks in clear, business-centric terms to the Board, C-suite, and regulators.
  • Communication: Exceptional verbal and written communication skills in English (fluency in Mandarin is a strong plus given the Hong Kong location).
Educational & Professional Qualifications
  • Academic Background: Holds a relevant university degree (Bachelor’s required, Master’s preferred) in Cybersecurity, Computer Science, Information Technology, or a related highly technical discipline.
  • Industry Certifications: Must possess active, industry-recognized professional cybersecurity certifications such as CISSP, CISM, CISA, or CRISC.
  • Specialized Credentials (Optional but Preferred): Additional certifications in cloud security (e.g., CCSP), offensive security (e.g., OSCP), or blockchain/smart contract security demonstrate a strong advantage.
  • Extensive Security Tenure: 10+ years of dedicated experience in cybersecurity, risk management, or IT audit, with at least 3-5 years in a senior leadership or Head of InfoSec capacity within the financial services sector (TradFi, FinTech, or Digital Assets).
  • SFC VASP/VATP Expertise: Demonstrates sufficient, highly relevant experience directly navigating Hong Kong SFC VASP / VATP (Type 1 & Type 7) license applications from a cybersecurity perspective.
  • Digital Asset Security: Deep, hands-on operational experience with the unique threat vectors of the crypto industry. Proven expertise in securing Hot/Cold/Warm wallet infrastructures, Multi-Party Computation (MPC), Hardware Security Modules (HSMs), and node network security.
Why Join Us

At Bybit, we are committed to fostering a supportive and enriching work environment.

Our benefits include:

  • Study Growth Fund: We support your professional development and continuous learning.
  • Internal Events: Participate in regular team-building activities, workshops, and events designed to promote collaboration and innovation.
  • Global Collaboration: Be part of a diverse, international team, working alongside colleagues from around the world.
  • Career Advancement: Access opportunities for growth and advancement within a rapidly expanding global company.
  • Internal Mobility: Grow with us- Your long-term development is important to us. We offer internal job opportunities to help build your career path.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

[EU] Product Manager – Institutional Services
[EU] Product Manager – Institutional Services

Bybit • Town of Vienna (WI)

On-site
USD 110,000 - 160,000
Growth Fund
Internal Events
Global Collaboration
+2
Senior AML Specialist, KYB (Lithuania)
Senior AML Specialist, KYB (Lithuania)

Bybit • United States

On-site
USD 70,000 - 110,000
Study Growth Fund
Internal Events
Global Collaboration
+2
[EU] ICT Incident Manager
[EU] ICT Incident Manager

Bybit • Town of Vienna (WI)

On-site
USD 68,000 - 103,000
Growth Fund
Internal Events
Global Collaboration
+2
Senior AML Specialist, KYB (Austria)
Senior AML Specialist, KYB (Austria)

Bybit • Vienna (VA)

On-site
USD 80,000 - 120,000
Growth Fund
Internal Events
Global Collaboration
+2
AML Expert, Process Excellence
AML Expert, Process Excellence

Bybit • United States

On-site
USD 120,000 - 190,000
Study Growth Fund
Internal Events
Global Collaboration
+2
Senior AML Specialist, QA
Senior AML Specialist, QA

Bybit • United States

On-site
USD 110,000 - 160,000
Growth Fund
Internal Events
Global Collaboration
+2
[EU] Product Manager – Trading
[EU] Product Manager – Trading

Bybit • Town of Vienna (WI)

On-site
USD 120,000 - 180,000
Study Growth Fund
Internal Events
Global Collaboration
+2
[EU] EU Internal Audit Expert
[EU] EU Internal Audit Expert

Bybit • Town of Vienna (WI)

On-site
USD 104,000 - 151,000
Study Growth Fund
Internal Events
Global Collaboration
+2
Senior Security Application Engineer New York, United States 30 Sept 2026
Senior Security Application Engineer New York, United States 30 Sept 2026

TempoAtlas • New York (NY)

On-site
USD 200,000 - 235,000
Health insurance
Equity / Stock options
Annual bonus
+1
Senior Security Application Engineer
Senior Security Application Engineer

BitGo • New York (NY)

On-site
USD 200,000 - 235,000
Competitive base salary
Stock options
Health insurance
+6