- Drive implementation, maintenance, and continuous improvement of the ISO 27001 ISMS, including control maturity tracking and audit readiness.
- Support SOC 2 Type II compliance through control implementation, evidence collection, and audit coordination.
- Conduct and document internal audits, manage findings, and follow up on remediation plans.
- Own the risk management program, including the risk register, scoring methodology, risk acceptance, and exception processes.
- Provide security governance for AWS environments, including cloud security posture, access controls, and configuration baselines.
- Maintain security policies, standards, and procedures, and deliver role-specific security awareness and training.
- Lead third-party security assessments and support incident handling, reporting, and post-incident reviews.
- Contribute to data protection and privacy governance, including KVKK, GDPR, DPIAs, and data lifecycle management.
- Drive AI and LLM governance practices, including secure usage policies, data exposure controls, and risk assessments.
- Coordinate business continuity and disaster recovery processes, including testing, documentation, and improvement.