WhiteBIT

Chief Information Security Officer

$$$$
πŸ‡ΊπŸ‡¦ Ukrainian Product

We are the creators of a new fintech era!

Our mission is to revolutionize the world by making blockchain technology accessible to everyone in everyday life. WhiteBIT is a global team of more than 1,200 professionals united by a shared vision of shaping the Web3 future.

We are building our own blockchain ecosystem, ensuring maximum transparency and security for over 8 million users worldwide. Our cutting-edge solutions, rapid adaptation to market challenges, and technological excellence set us apart from traditional companies.

Our official partners include the National Football Team of Ukraine, FC Barcelona, Lifecell, FACEIT, and VISA.

The future of Web3 starts with you β€” join us as a Chief Information Security Officer!

 

Requirements:

  • Executive Track Record: 7+ years of experience in executive security leadership (CISO, VP of Security, or Director of InfoSec) within hyper-growth global Fintech enterprises, Tier-1 Crypto Exchanges, Neobanks, or high-volume Web3 platforms.
  • Hyper-Scale Expansion Experience: Proven history of maintaining enterprise-wide security continuity and deploying secure corporate frameworks during rapid global expansions, M&As, or multi-jurisdictional office rollouts.
  • Business & Product Enabler Mindset: A definitive philosophy that elite cybersecurity is a business accelerator and the absolute foundation of user trust, rather than a bureaucratic bottleneck.
  • 2026+ Deep Tech Acumen: Deep architectural understanding of decentralized networks, cryptographic primitives, smart contract vulnerabilities, cross-chain bridge risks, and the exploitation vectors of AI systems.
  • Global Team Leadership: Exceptional ability to lead, mentor, and structurally scale an existing, highly autonomous, multinational team of security engineers, AppSec specialists, and compliance experts.
  • Elite Credentials: Industry-standard certifications (e.g., CCISO, CISSP, CISM) combined with specialized blockchain security training are highly preferred.

Will be a plus:

  • Regional Frameworks: Deep familiarity with SEC/CFTC mandates, and APAC/MENA regulatory frameworks.

 

Responsibilities:

Strategic Executive Governance & Leadership

  • Global Security Strategy: Author, own, and execute the global cybersecurity roadmap aligned with the company’s commercial hyper-growth objectives.
  • Executive Alignment: Serve as the primary liaison between the General Manager, C-level executives, and the Board, translating complex cyber risks into tangible business impact and strategic ROI.
  • Financial Management: Oversee the global InfoSec department budget (including tooling, external audits, and headcount) and strategically direct capital into advanced R&D, defensive AI capabilities, and elite talent acquisition.
  • Team Growth: Build, hire, mentor, and scale a world-class cybersecurity team as the company and product portfolio expand.
  • Vendor & Supply Chain Security: Manage key vendor relationships (cloud providers, CSPM, HSM/MPC, SAST/DAST/SCA, PAM) and drive supply chain security initiatives (SBOM, dependency scanning).

High-Throughput Exchange Resilience & Global Expansion

  • Architectural Advisory (Non-Liability): Be consulted on architectural resilience, zero-downtime fault tolerance, and secure throughput as our trading platforms scale and cross-chain volume grows exponentially. Provide expert advisory to the Engineering teams without assuming operational or legal liability for the core execution.
  • Greenfield Blueprinting: Design and deploy comprehensive corporate and product security architecture frameworks from scratch for newly established global physical offices and regional entities.
  • Regulatory Licensing: Partner with Legal and Compliance teams to build a secure, audit-ready infrastructure that enables the rapid acquisition of international licenses. Turn robust security into a market entry accelerator by ensuring continuous compliance with critical frameworks (e.g., ISO 27001, SOC 2, DORA, MiCA, PCI DSS, CCSS).

Infrastructure, Cloud, & Crypto Asset Security

  • Multi-Cloud Posture: Own the multi-cloud security posture (AWS) and ensure critical cloud misconfigurations or High/Critical CVSS vulnerabilities are remediated within target SLAs.
  • Web3 Infrastructure: Oversee Web3 infrastructure security, including blockchain nodes, RPC endpoints, and validators.
  • Crypto Key Management: Oversee crypto key management architecture and operational execution (HSM, MPC, hot/cold wallet design, and key ceremonies) in compliance with W Group technical standards and shared platform architectures.
  • Network & Endpoint Protection: Drive and continuously monitor network segmentation (ZTNA), endpoint protection (EDR), and data governance controls (DLP, data residency).

Application & Product Security (Web3 & DevSecOps)

  • Product Security Culture: Maintain and champion a "Security-First" engineering ethos across cross-functional product teams, ensuring security design reviews occur at the ideation stage of every feature.
  • Pipeline Coverage: Integrate DevSecOps engineers into product teams and enforce automated SAST/DAST/SCA coverage across all CI/CD pipelines, establishing mandatory security gates before production releases.
  • Smart Contract Audits: Own the smart contract audit lifecycle, combining internal code reviews, automated scanning, and mandatory independent external audits before mainnet deployment.
  • Defensive Programs: Run enterprise-wide threat modeling updates and lead continuous global Bug Bounty & Responsible Disclosure programs with specialized Web3-specific scopes (contracts, frontend, APIs).

Identity, Access, & Incident Management

  • Lifecycle Automation: Own Identity & Access Management (IAM) strategy, including JML (joiner/mover/leaver) automation, SSO/MFA/passwordless, and identity federation for employees, contractors, and B2B partners.
  • Privileged Access Management (PAM): Enforce zero-tolerance PAM controls for privileged access to production keys, cloud admin roles, and crypto infrastructure.
  • Access Certification: Run mandatory quarterly access certifications for all critical environments and hot wallets.
  • Incident Leadership: Lead response operations for high-stakes security incidents (e.g., smart contract exploits, cloud breaches, credential compromise) using automated playbooks, coordinating closely with Engineering, Legal, and Executive leadership.

2026–2028 Future-Proofing

  • AI Security Governance (AI SecOps): Establish corporate guardrails for internal LLM agent deployments and build automated, AI-driven defensive systems capable of neutralizing autonomous attacks.
  • Post-Quantum Cryptography (PQC): Drive the R&D and implementation roadmap for migrating exchange infrastructures and cold/warm user asset vaults to post-quantum cryptographic standards.

 

Working terms

Shape the Future – Build next-gen payment solutions at the intersection of crypto and finance.

Innovate & Create – Your ideas will help businesses integrate digital assets effortlessly.

Global Impact – Be part of a team driving financial innovation worldwide, shaping the future of payments across industries and borders.

Tech-Driven Culture – Join a team of fintech and blockchain enthusiasts pushing the industry forward.

 

Work-Life Balance & Well-being:

  • Modern equipment.
  • Comfortable working conditions, and an inspiring environment to help you thrive.
  • 24 calendar days of paid leave.
  • 5 calendar days of sick leave.
  • Additional days off for national holidays.

Required domain experience

Blockchain / Crypto 3 years
Fintech 4 years

Required languages

English B2 - Upper Intermediate
Ukrainian Native
Published 17 August
25 views
Β·
2 applications
To apply for this and other jobs on Djinni login or signup.
Loading...