Information Security Engineer

New
I
Insider OneInformation security
Work from anywhere in Turkey through our fully remote setup.Full-Time
Salary not disclosed
Apply NowOpens the employer's application page

Job Details

Languages
Excellent written and verbal communication skills in English
Required Skills
JiraRisk Management

Requirements

  • Strong knowledge of ISO 27001, ISMS processes, internal audits, and control frameworks.
  • Hands-on experience with risk identification, scoring, and mitigation tracking.
  • Experience in Business Continuity Management and disaster recovery planning.
  • Solid understanding of AWS services and cloud security governance, including IAM, logging, and baseline hardening.
  • Familiarity with the SOC 2 Type II framework and control domains.
  • Understanding of data classification, data inventory, and data protection mechanisms.
  • Experience with vendor security and third-party risk management processes.
  • Knowledge of privacy regulations such as KVKK and GDPR, including practical implementation.
  • Strong documentation and reporting skills for audits, compliance, and executive visibility.
  • Experience responding to customer security questionnaires and audits.
  • Excellent written and verbal communication skills in English.
  • Experience using ticketing systems such as Jira to manage security tasks and follow-ups.
  • Willingness to provide on-call support for security-related incidents when necessary.

Responsibilities

  • Drive implementation, maintenance, and continuous improvement of the ISO 27001 ISMS, including control maturity tracking and audit readiness.
  • Support SOC 2 Type II compliance through control implementation, evidence collection, and audit coordination.
  • Conduct and document internal audits, manage findings, and follow up on remediation plans.
  • Own the risk management program, including the risk register, scoring methodology, risk acceptance, and exception processes.
  • Provide security governance for AWS environments, including cloud security posture, access controls, and configuration baselines.
  • Maintain security policies, standards, and procedures, and deliver role-specific security awareness and training.
  • Lead third-party security assessments and support incident handling, reporting, and post-incident reviews.
  • Contribute to data protection and privacy governance, including KVKK, GDPR, DPIAs, and data lifecycle management.
  • Drive AI and LLM governance practices, including secure usage policies, data exposure controls, and risk assessments.
  • Coordinate business continuity and disaster recovery processes, including testing, documentation, and improvement.
View Full Description & ApplyYou'll be redirected to the employer's site
View details
Apply Now