Information Security Engineer

Posted 1 day ago

This is a fully remote position, open to applicants in Turkey.

📋 Description

• Lead the implementation, maintenance, and ongoing enhancement of the ISO 27001 Information Security Management System.

• Assist with SOC 2 Type II compliance efforts, which include control implementation, evidence gathering, and audit coordination.

• Perform and document internal audits, oversee findings, and monitor remediation plans.

• Take ownership of and advance the company-wide risk management program.

• Provide governance and security oversight for AWS environments.

• Work in collaboration with Red Team and Blue Team to prioritize and resolve technical security issues.

• Maintain, revise, and enforce security policies, standards, and procedures.

• Design and implement role-specific security awareness and training initiatives.

• Lead security assessments of third-party vendors and ensure continuous monitoring.

• Assist with handling security incidents, reporting, and conducting post-incident reviews.

• Contribute to KVKK and GDPR data protection and privacy governance, including DPIA processes and data lifecycle management.

• Promote AI/LLM governance practices, including policies for secure usage and risk assessments.

• Provide guidance to business units and engineering teams on secure architecture, design reviews, and risk-based decision-making.

• Participate in threat modeling and offer secure design recommendations.

• Coordinate and enhance business continuity and disaster recovery processes, including testing and documentation.


⛳️ Requirements

• Extensive knowledge of ISO 27001, ISMS processes, internal audits, and control frameworks.

• Practical experience with risk management practices, including risk identification, scoring, and tracking mitigation efforts.

• Background in Business Continuity Management and disaster recovery planning.

• Strong understanding of AWS services and cloud security governance, including IAM, logging, and baseline hardening.

• Familiarity with the SOC 2 Type II framework and its control domains.

• Comprehension of data security concepts, such as data classification, inventory, and protection mechanisms.

• Experience managing vendor security and third-party risk processes.

• Knowledge of KVKK and GDPR, including practical application.

• Familiarity with AI/LLM risks and governance concepts is a significant advantage.

• Excellent documentation and reporting skills for audits, compliance, and executive visibility.

• Experience addressing customer security questionnaires and audits.

• Strong analytical abilities to assess both technical and business risks.

• Capacity to take ownership of security areas and drive initiatives from start to finish.

• Exceptional written and verbal communication skills in English.

• Strong collaborative skills for working with both technical and non-technical teams.

• Ability to comprehend and convey the business implications of security decisions.

• Proficiency in evaluating security posture across cloud, application, endpoint, and data layers.

• Willingness to act as a trusted advisor and consultant to internal stakeholders.

• Proactive approach with an emphasis on continuous improvement.

• Readiness to provide on-call support for security-related incidents as needed.

• Responsibility for security projects from planning through execution and closure.

• Ability to track, validate, and resolve findings from audits, pentests, and internal reviews.

• Experience with ticketing systems such as Jira.

• Capability to communicate effectively with internal teams, auditors, and external stakeholders.


🏝️ Benefits

• Monthly meal allowance.

• Comprehensive private health insurance.

• Access to platforms like Spotify, LinkedIn Learning, Blinkist, MasterClass, Neoskola, and CloudGuru.

• Internal training in AI fundamentals, coding, foreign languages, and personal development skills.

• Eligibility-based ESOP share ownership.

• Referral bonuses.

• Opportunities for volunteering and engaging in purpose-driven social impact projects.

• Global retreats and team-building activities.

• Tech & Dev Talks.

• Fully remote work from any location within Turkey.

People also viewed

OpenLoop12 hours ago

Staff Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Funcional Health Tech12 hours ago

Information Security Governance Analyst (Mid-Level)

BR flagBrazil OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Salesforce12 hours ago

Security Architect Lead

US flagArizona, +13 more statesFull-timeCybersecurity / Security Engineer$150.1k – $227k/year
ApplyView job
CNO Financial Group12 hours ago

Lead IT Security Architect – SailPoint

US flagIllinois, +6 more statesFull-timeCybersecurity / Security Engineer$130.5k – $195.7k/year
ApplyView job
GuidePoint Security14 hours ago

Security Architect – AD/Entra ID

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Applied Research Solutions17 hours ago

Information System Security Engineer – ISSE

US flagOhio OnlyFull-timeCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers