Bizi Takip Edin
Koç Topluluğuna ilişkin güncel haberler için bizi sosyal medya hesaplarımızdan takip edin.
- KVKK Aydınlatma Metni
- Çerez Aydınlatma Metni
- Bize Ulaşın
- © 2026 - Koç Holding
Key Responsibilities
• Lead the management and continuous improvement of the Information Security Management System (ISMS)
• Drive compliance programs related to ISO 27001 and other relevant IT governance, risk, and security standards
• Assess and enhance compliance with information security policies, procedures, standards, and control requirements across IT teams
• Lead IT risk management, governance, and internal control activities to strengthen the organization’s security posture
• Oversee the identification, assessment, mitigation, and monitoring of information security and IT-related risks
• Manage the vulnerability management program and ensure timely remediation of identified security gaps
• Coordinate penetration testing, security assessments, and independent security review activities
• Lead internal and external audit engagements and ensure the effective remediation of audit findings
• Monitor regulatory, legal, and policy changes and ensure organizational compliance with applicable information security requirements
• Oversee the alignment of IT service management (ITSM) processes with security, control, and compliance requirements
• Manage third-party and vendor security risk assessment processes
• Establish and report key information security, risk, and compliance metrics to senior management on a regular basis
• Promote and strengthen a culture of information security awareness across the organization
• Ensure that security, risk, and compliance requirements are integrated into IT projects and technology initiatives
• Continuously monitor emerging cyber threats, industry trends, and evolving security practices, providing strategic recommendations to management for enhancing the organization's security capabilities.
Qualifications
• Bachelor's degree from a university in a relevant field of study
• Minimum 10 years of experience in information security, cybersecurity, IT risk management, governance, compliance, or related disciplines,
• Proven experience leading information security or cybersecurity teams, with at least 3 years in a managerial role,
• Strong expertise in Information Security Management Systems (ISMS), particularly ISO 27001, with hands-on experience managing internal audits, external audits, and certification processes,
• Demonstrated experience in developing, implementing, and continuously enhancing enterprise-wide information security strategies,
• Sound knowledge of information security regulations and data privacy requirements, including KVKK, GDPR, and related legislation,
• Experience in identifying, assessing, and managing information security risks across complex technology environments,
• Proven track record in vulnerability management, penetration testing, security assessments, and security monitoring practices,
• Strong understanding of SIEM, EDR/XDR, threat management, and incident response capabilities,
• Experience designing and implementing end-to-end security architectures leveraging both defensive and offensive cybersecurity approaches,
• Knowledge of secure software development practices (DevSecOps) and the integration of security controls throughout the software development lifecycle,
• Familiarity with IT governance, service management, and control frameworks such as COBIT and ITIL,
• Relevant professional certifications such as CISM, CISSP, CISA, CRISC, and/or ISO 27001 Lead Implementer/Auditor are preferred,
• Strong leadership capabilities with a demonstrated ability to build, develop, and mentor high-performing teams,
• Ability to lead initiatives that strengthen information security awareness and foster a security-focused culture across the organization,
• Proven ability to collaborate effectively with cross-functional IT teams and business stakeholders,
• Excellent communication and stakeholder management skills, with the ability to build strong relationships with senior leadership, audit teams, and external partners,
• Strong decision-making, problem-solving, and crisis management capabilities, with a proactive and results-oriented mindset.
Yağmur Bayrak - İşe Alım ve İşveren Markası Sorumlusu
Sorunsuz bir Koç Kariyerim deneyimi için Google Chrome, Firefox, Safari veya Microsoft Edge ile giriş yapmalısın.
Daha yüksek ekran çözünürlüğünü desteleyen bir cihaz kullanarak Koç Kariyerim'e giriş yapabilirsin. En az 1024 piksel genişliğinde bir ekrana ihtiyacın var.