Information Security Engineer
I
Insider OneB2B SaaS
Work from anywhere in TurkeyFull-TimeMiddle
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Languages
- English
- Required Skills
- AWSJiraRisk Management
Requirements
- Strong knowledge of ISO 27001, ISMS processes, internal audits, and control frameworks.
- Hands-on experience with risk management practices, including identification, scoring, and mitigation tracking.
- Experience in Business Continuity Management (BCM) and disaster recovery planning.
- Solid understanding of AWS services and cloud security governance (IAM, logging, hardening).
- Familiarity with SOC 2 Type II framework and control domains.
- Understanding of data security concepts (classification, inventory, protection).
- Experience with vendor security and third-party risk management.
- Knowledge of privacy regulations such as KVKK and GDPR.
- Strong documentation and reporting skills for audits and compliance.
- Experience responding to customer security questionnaires and audits.
- Excellent written and verbal communication skills in English.
Responsibilities
- Drive the implementation, maintenance, and continuous improvement of the ISO 27001 Information Security Management System (ISMS).
- Support SOC 2 Type II compliance efforts, including control implementation and audit coordination.
- Conduct internal audits, manage findings, and follow up on remediation plans.
- Own and evolve the company-wide risk management program, including risk register and scoring methodology.
- Provide governance and security oversight for AWS environments.
- Lead third-party/vendor security assessments and monitoring.
- Support security incident handling and post-incident reviews.
- Contribute to data protection and privacy governance (KVKK, GDPR).
- Drive AI/LLM governance practices and secure usage policies.
- Coordinate business continuity and disaster recovery (BCP/DR) processes.
View Full Description & ApplyYou'll be redirected to the employer's site