Chief Information Security Officer
AI Summary
Leads cybersecurity strategy and operations for Spark, a digital asset platform, ensuring regulatory alignment with SFC and ISO 27001 standards while managing incident response, vendor risk, and security culture.
About this role
About Us
Responsibilities
-
Regulatory Support & MIC-IT Enablement: Serve as the primary cybersecurity anchor for Spark. Work intimately with the ROs and MIC-IT to design, implement, and evidence the cybersecurity framework, ensuring senior management possesses full visibility and control over cyber risks as expected by the SFC.
-
Pre-Launch & Independent Assessments: Take total ownership of preparing for, facilitating, and successfully passing the SFC-mandated pre-launch independent cybersecurity assessments. Remediate any findings swiftly and effectively prior to go-live.
-
Cybersecurity Framework & Operations: Architect, deploy, and govern Spark’s comprehensive cybersecurity framework. Ensure strict alignment with ISO/IEC 27001, SFC guidelines, and industry best practices for network, application, and endpoint security.
-
Incident Readiness & Response: Develop, test, and maintain robust Cyber Incident Response Plans (CIRP) and Disaster Recovery/Business Continuity Plans (DR/BCP). Lead tabletop exercises and ensure the organization is perpetually ready to detect, contain, and eradicate threats.
-
Ongoing Cyber Controls: Establish a continuous monitoring environment. Oversee regular penetration testing, vulnerability scanning, threat intelligence gathering, and the implementation of Zero-Trust architecture across Spark’s infrastructure.
Leadership & Cross-Functional Collaboration
-
Strategic Alignment: Report directly to the CTO while operating with the independence necessary to challenge technical architectures from a security and risk perspective.
-
Security Culture: Champion a security-first culture across the engineering, product, and operations teams at Spark. Develop and execute ongoing security awareness training for all employees.
-
Vendor Risk Management: Oversee the security evaluation of third-party vendors, SaaS providers, and blockchain analytics platforms, ensuring external integrations do not compromise Spark’s internal security posture.
-
Local Presence & Communication: Serve as the on-the-ground security leader in Hong Kong. Communicate complex security risks in clear, business-centric terms to the Board, C-suite, and regulators.
-
Communication: Exceptional verbal and written communication skills in English (fluency in Mandarin is a strong plus given the Hong Kong location).
Educational & Professional Qualifications
-
Academic Background: Holds a relevant university degree (Bachelor’s required, Master’s preferred) in Cybersecurity, Computer Science, Information Technology, or a related highly technical discipline.
-
Industry Certifications: Must possesses active, industry-recognized professional cybersecurity certifications such as CISSP, CISM, CISA, or CRISC.
-
Specialized Credentials (Optional but Preferred): Additional certifications in cloud security (e.g., CCSP), offensive security (e.g., OSCP), or blockchain/smart contract security demonstrate a strong advantage.
-
Extensive Security Tenure: 10+ years of dedicated experience in cybersecurity, risk management, or IT audit, with at least 3-5 years in a senior leadership or Head of InfoSec capacity within the financial services sector (TradFi, FinTech, or Digital Assets).
-
SFC VASP/VATP Expertise: Demonstrates sufficient, highly relevant experience directly navigating Hong Kong SFC VASP / VATP (Type 1 & Type 7) license applications from a cybersecurity perspective.
-
Digital Asset Security: Deep, hands-on operational experience with the unique threat vectors of the crypto industry. Proven expertise in securing Hot/Cold/Warm wallet infrastructures, Multi-Party Computation (MPC), Hardware Security Modules (HSMs), and node network security.
Why Join Us
At Bybit, we are committed to fostering a supportive and enriching work environment.
Our benefits include:
- Study Growth Fund: We support your professional development and continuous learning.
- Internal Events: Participate in regular team-building activities, workshops, and events designed to promote collaboration and innovation.
- Global Collaboration: Be part of a diverse, international team, working alongside colleagues from around the world.
- Career Advancement: Access opportunities for growth and advancement within a rapidly expanding global company.
- Internal Mobility: Grow with us- Your long-term development is important to us. We offer internal job opportunities to help build your career path.
Skills
Explore related jobs
More jobs at bybit
Backend Development EngineerKuala Lumpur, Malaysia
Senior AML Specialist, Name Screening & Travel RuleKuala Lumpur, Malaysia
Senior AML Specialist, InvestigationsKuala Lumpur, Malaysia
Lead AML Product SpecialistAbu Dhabi, UAE
AML Expert, Process ExcellenceVilnius, Lithuania
Senior AML Specialist, Transaction MonitoringKuala Lumpur, Malaysia
Similar CCSP jobs
Jobs in Hong Kong
Loan Closing AssociateDelta Capita · Hong Kong, Hong Kong
Regional Payroll SpecialistBjak · Hong Kong
(Senior) Brand Managernahc.io · Hong Kong
Senior Technology Risk Analyst / LeadLalamove · Hong Kong SAR
Senior Network and Security Analyst / LeadLalamove · Hong Kong SAR- Senior/Staff Engineer - Web3 - Onchain DataOKX · Hong Kong, Hong Kong SAR
Browse these categories
Market data for this role
All reports →- SeriesRole reportsOne role family at a time: how many openings, what changed this week, who is hiring, what it pays.
- SeriesSalary reportsWhat employers publish in job postings, by level and workplace. Not self-reported pay.
- Market overviewState of tech hiring, September 2026: up 4.8%Tech hiring rose 4.8% month over month in September 2026, with 411,122 new listings. Customer support and account executive roles led the growth.