SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Bybit, a leading global cryptocurrency exchange and digital financial platform serving over 80 million users across 200+ countries, is seeking a Chief Information Security Officer to lead cybersecurity strategy for Spark, a new regulated digital asset platform in Hong Kong.
You will serve as the primary cybersecurity anchor for Spark's launch and operations, reporting directly to the CTO while maintaining independence to challenge technical architectures from a security and risk perspective. This is a high-impact role requiring deep expertise in both traditional financial services security and digital asset-specific threat vectors.
Key Responsibilities:
- Lead regulatory support and MIC-IT enablement, designing and implementing Spark's cybersecurity framework to meet SFC expectations with full visibility and control over cyber risks
- Own preparation for and successful passage of SFC-mandated pre-launch independent cybersecurity assessments, remediating findings swiftly
- Architect and govern a comprehensive cybersecurity framework aligned with ISO/IEC 27001, SFC guidelines, and industry best practices across network, application, and endpoint security
- Develop, test, and maintain Cyber Incident Response Plans (CIRP) and Disaster Recovery/Business Continuity Plans (DR/BCP); lead tabletop exercises
- Establish continuous monitoring environment with regular penetration testing, vulnerability scanning, threat intelligence, and Zero-Trust architecture implementation
- Champion security-first culture across engineering, product, and operations teams; develop security awareness training
- Oversee third-party vendor and SaaS security evaluations to ensure external integrations do not compromise internal security posture
- Serve as on-the-ground security leader in Hong Kong, communicating complex security risks in business-centric terms to Board, C-suite, and regulators
- Demonstrate exceptional verbal and written communication skills in English; Mandarin fluency is a strong plus
Requirements:
- Bachelor's degree required (Master's preferred) in Cybersecurity, Computer Science, Information Technology, or related highly technical discipline
- Active, industry-recognized professional cybersecurity certifications: CISSP, CISM, CISA, or CRISC (mandatory)
- 10+ years dedicated experience in cybersecurity, risk management, or IT audit
- 3-5 years in senior leadership or Head of InfoSec capacity within financial services sector (TradFi, FinTech, or Digital Assets)
- Demonstrated, highly relevant experience navigating Hong Kong SFC VASP/VATP (Type 1 & Type 7) license applications from cybersecurity perspective
- Deep, hands-on operational experience with crypto industry threat vectors: Hot/Cold/Warm wallet infrastructures, Multi-Party Computation (MPC), Hardware Security Modules (HSMs), and node network security
- Optional but preferred: Additional certifications in cloud security (CCSP), offensive security (OSCP), or blockchain/smart contract security