
Information Security Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Turkey.
• Lead the implementation, maintenance, and ongoing enhancement of the ISO 27001 Information Security Management System.
• Assist with SOC 2 Type II compliance efforts, which include control implementation, evidence gathering, and audit coordination.
• Perform and document internal audits, oversee findings, and monitor remediation plans.
• Take ownership of and advance the company-wide risk management program.
• Provide governance and security oversight for AWS environments.
• Work in collaboration with Red Team and Blue Team to prioritize and resolve technical security issues.
• Maintain, revise, and enforce security policies, standards, and procedures.
• Design and implement role-specific security awareness and training initiatives.
• Lead security assessments of third-party vendors and ensure continuous monitoring.
• Assist with handling security incidents, reporting, and conducting post-incident reviews.
• Contribute to KVKK and GDPR data protection and privacy governance, including DPIA processes and data lifecycle management.
• Promote AI/LLM governance practices, including policies for secure usage and risk assessments.
• Provide guidance to business units and engineering teams on secure architecture, design reviews, and risk-based decision-making.
• Participate in threat modeling and offer secure design recommendations.
• Coordinate and enhance business continuity and disaster recovery processes, including testing and documentation.
• Extensive knowledge of ISO 27001, ISMS processes, internal audits, and control frameworks.
• Practical experience with risk management practices, including risk identification, scoring, and tracking mitigation efforts.
• Background in Business Continuity Management and disaster recovery planning.
• Strong understanding of AWS services and cloud security governance, including IAM, logging, and baseline hardening.
• Familiarity with the SOC 2 Type II framework and its control domains.
• Comprehension of data security concepts, such as data classification, inventory, and protection mechanisms.
• Experience managing vendor security and third-party risk processes.
• Knowledge of KVKK and GDPR, including practical application.
• Familiarity with AI/LLM risks and governance concepts is a significant advantage.
• Excellent documentation and reporting skills for audits, compliance, and executive visibility.
• Experience addressing customer security questionnaires and audits.
• Strong analytical abilities to assess both technical and business risks.
• Capacity to take ownership of security areas and drive initiatives from start to finish.
• Exceptional written and verbal communication skills in English.
• Strong collaborative skills for working with both technical and non-technical teams.
• Ability to comprehend and convey the business implications of security decisions.
• Proficiency in evaluating security posture across cloud, application, endpoint, and data layers.
• Willingness to act as a trusted advisor and consultant to internal stakeholders.
• Proactive approach with an emphasis on continuous improvement.
• Readiness to provide on-call support for security-related incidents as needed.
• Responsibility for security projects from planning through execution and closure.
• Ability to track, validate, and resolve findings from audits, pentests, and internal reviews.
• Experience with ticketing systems such as Jira.
• Capability to communicate effectively with internal teams, auditors, and external stakeholders.
• Monthly meal allowance.
• Comprehensive private health insurance.
• Access to platforms like Spotify, LinkedIn Learning, Blinkist, MasterClass, Neoskola, and CloudGuru.
• Internal training in AI fundamentals, coding, foreign languages, and personal development skills.
• Eligibility-based ESOP share ownership.
• Referral bonuses.
• Opportunities for volunteering and engaging in purpose-driven social impact projects.
• Global retreats and team-building activities.
• Tech & Dev Talks.
• Fully remote work from any location within Turkey.
OpenLoop
Funcional Health Tech
Salesforce
CNO Financial Group
Get handpicked remote jobs straight to your inbox weekly.