Risk, Compliance & Information Security Executive
Indexed description
Position: Risk, Compliance & Application Security Executive
Location: Kozyatağı Allianz Tower (Hybrid)
Job Summary
We are looking for a Risk, Compliance & Application Security Executive to ensure our software products are secure and compliant with relevant regulations. This role will manage penetration testing, vulnerability assessment, and oversee certification processes such as PCI DSS and ISO 27001.
Responsibilities:
- Manage PCI DSS (Service Provider Level 1) and ISO 27001 compliance and certification processes
- Analyze security vulnerabilities and propose effective technical and organizational controls
- Plan and coordinate internal and external penetration tests, and follow up on remediation
- Perform regular vulnerability assessments using tools such as Nessus, Qualys, etc.
- Conduct risk assessments and prepare corrective action plans
- Use SIEM and GRC tools for monitoring and reporting
- Prepare for audits and manage relevant documentation
- Raise awareness across the organization on compliance and security best practices
- Solid understanding of PCI DSS and ISO 27001 frameworks
- Hands-on experience with vulnerability scanning tools (e.g. Nessus, Qualys) and SIEM platforms
- Familiarity with GRC systems and compliance reporting
- Strong documentation, audit preparation, and analytical skills
- Proficiency in English (written and verbal)
- Experience in secure software development practices
- Familiarity with remediation follow-ups after penetration tests
- Relevant certifications (e.g. OSCP, CEH, ISO 27001 Lead Auditor, CISA)
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search