Назад
Company hidden
15 часов назад

Information Security Officer (Crypto)

Тип работы
fulltime
Грейд
head
Английский
b2
Страна
Turkey
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Information Security Officer (Crypto): Leading Turkish regulatory security compliance and security operations for a cryptocurrency exchange with an accent on SPK, TÜBİTAK, KVKK, cloud infrastructure, and crypto custody controls. Focus on managing audits, commanding high-severity incident response, building the local security team, and translating information security risk into business impact.

Location: Istanbul, Turkey

Company

hirify.global is a global cryptocurrency exchange and digital financial platform serving users across trading, payments, wealth management, custody, institutional services, and Web3.

What you will do

  • Own compliance with Turkish regulatory requirements, including SPK crypto exchange licensing conditions, TÜBİTAK BİLGEM security criteria, and KVKK.
  • Act as the primary security contact for SPK audits, TÜBİTAK audits, penetration testing, and regulatory inspections.
  • Maintain the local security policy framework across access control, network security, encryption, logging, and incident management.
  • Lead high-severity local security incidents as the CISO-level incident commander.
  • Oversee security architecture for local infrastructure, AWS and Huawei Cloud environments, customer-facing platforms, and hot and cold wallet infrastructure.
  • Build and manage the local security team, risk register, remediation plans, and security reporting to senior management and the Board.

Requirements

  • 8+ years of information security experience, including at least 3 years as a CISO, Deputy CISO, or Head of Security.
  • Experience working with Turkish financial regulators, including SPK, or participating in TÜBİTAK-criteria audits.
  • Strong knowledge of KVKK and its practical implementation.
  • Experience with cloud, network, and application security, as well as security programs in regulated financial institutions.
  • Excellent communication skills in Turkish and English are required.
  • Strong risk management skills and the ability to translate technical risk into business impact.

Nice to have

  • Experience at a cryptocurrency exchange or digital asset company.
  • Knowledge of cryptoasset custody security, cold and hot wallet architecture, and key management.
  • CISSP, CISM, CISA, or ISO 27001 Lead Auditor certification.
  • Exposure to multi-jurisdiction compliance, including the EU and Kazakhstan.

Culture & Benefits

  • Professional development support through a Study Growth Fund.
  • Regular team-building activities, workshops, and internal events.
  • Collaboration with an international team across multiple countries.
  • Career advancement and internal mobility opportunities.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →