Information Security Engineer
New
I
Insider OneInformation security
Work from anywhere in Turkey through our fully remote setup.Full-Time
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Languages
- Excellent written and verbal communication skills in English
- Required Skills
- JiraRisk Management
Requirements
- Strong knowledge of ISO 27001, ISMS processes, internal audits, and control frameworks.
- Hands-on experience with risk identification, scoring, and mitigation tracking.
- Experience in Business Continuity Management and disaster recovery planning.
- Solid understanding of AWS services and cloud security governance, including IAM, logging, and baseline hardening.
- Familiarity with the SOC 2 Type II framework and control domains.
- Understanding of data classification, data inventory, and data protection mechanisms.
- Experience with vendor security and third-party risk management processes.
- Knowledge of privacy regulations such as KVKK and GDPR, including practical implementation.
- Strong documentation and reporting skills for audits, compliance, and executive visibility.
- Experience responding to customer security questionnaires and audits.
- Excellent written and verbal communication skills in English.
- Experience using ticketing systems such as Jira to manage security tasks and follow-ups.
- Willingness to provide on-call support for security-related incidents when necessary.
Responsibilities
- Drive implementation, maintenance, and continuous improvement of the ISO 27001 ISMS, including control maturity tracking and audit readiness.
- Support SOC 2 Type II compliance through control implementation, evidence collection, and audit coordination.
- Conduct and document internal audits, manage findings, and follow up on remediation plans.
- Own the risk management program, including the risk register, scoring methodology, risk acceptance, and exception processes.
- Provide security governance for AWS environments, including cloud security posture, access controls, and configuration baselines.
- Maintain security policies, standards, and procedures, and deliver role-specific security awareness and training.
- Lead third-party security assessments and support incident handling, reporting, and post-incident reviews.
- Contribute to data protection and privacy governance, including KVKK, GDPR, DPIAs, and data lifecycle management.
- Drive AI and LLM governance practices, including secure usage policies, data exposure controls, and risk assessments.
- Coordinate business continuity and disaster recovery processes, including testing, documentation, and improvement.
View Full Description & ApplyYou'll be redirected to the employer's site