Information Security Engineer (Remote)
This is the employer's own posting, not a copy on a job board.
What we know
Is it still open?
Confirmed still open
Last checked 4h ago — checked against the employer's own applicant tracking system, which is the company answering directly.
We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.
How old is it?
Posted 184d ago
The date the source published, not the day we noticed it (2026-03-31). Last seen at its source just now.
We have tracked this listing since 24 Sep 2026 (7 days). The employer's own board has carried it every time we have read it, most recently just now.
Is it remote?
Marked remote on the employer's board
Their board carries a remote setting on this posting — a field they filled in, not wording we read. The location field names somewhere specific, which is usually where the team or the entity sits.
Who may apply?
Turkey
The description agrees: it names Turkey.
What the ad says
…Work from anywhere in Turkey through our fully remote setup…
Pay not stated
Similar roles pay $4,400–7,250/mo
Middle 50% of 9 listings that do state pay — Engineering · all levels · Turkey · USD/month. This employer has published no salary; this is what comparable listings we hold disclose, never converted between currencies or periods. How this is calculated.
Skills named in the ad
Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.
Carried by 1 source
-
lever employer's own board first seen 7d ago · last seen just now
The listing
What You Will Do
- Drive the implementation, maintenance, and continuous improvement of the ISO 27001 Information Security Management System (ISMS), including control maturity tracking and audit readiness
- Support SOC 2 Type II compliance efforts, including control implementation, evidence collection, and audit coordination
- Conduct and document internal audits, manage findings, and follow up on remediation plans across teams
- Own and evolve the company-wide risk management program, including risk register, scoring methodology, risk acceptance, and exception processes
- Provide governance and security oversight for AWS environments, including cloud security posture, access controls, and configuration baselines
- Collaborate with Red Team and Blue Team to track, prioritize, and close technical security findings
- Maintain, update, and enforce security policies, standards, and procedures across the organization
- Design and execute security awareness and training programs tailored to different roles (engineering, ops, business)
- Lead third-party/vendor security assessments, including risk evaluation, tiering, and continuous monitoring
- Support and coordinate security incident handling, reporting, and post-incident review processes
- Contribute to data protection and privacy governance (KVKK, GDPR), including DPIA processes and data lifecycle management
- Drive AI / LLM governance practices, including secure usage policies, data exposure controls, and risk assessments for AI tools
- Act as a security consultant to business units and engineering teams, supporting secure architecture, design reviews, and risk-based decision making
- Contribute to security architecture and design review processes, including threat modeling and secure design guidance
- Coordinate and enhance business continuity and disaster recovery (BCP/DR) processes, including testing, documentation, and continuous improvement
What You Will Need
- Strong knowledge of ISO 27001, ISMS processes, internal audits, and control frameworks
- Hands-on experience with risk management practices, including risk identification, scoring, and mitigation tracking
- Experience in Business Continuity Management (BCM) and disaster recovery planning
- Solid understanding of AWS services and cloud security governance, including IAM, logging, and baseline hardening
- Familiarity with SOC 2 Type II framework and control domains
- Understanding of data security concepts, including data classification, data inventory, and data protection mechanisms
- Experience with vendor security and third-party risk management processes
- Knowledge of privacy regulations such as KVKK and GDPR, including practical implementation
- Familiarity with AI/LLM risks and governance concepts is a strong plus
- Strong documentation and reporting skills for audits, compliance, and executive visibility
- Experience in responding to customer security questionnaires and audits
- Strong analytical thinking and ability to assess both technical and business risks
- Ability to take ownership of security domains and drive initiatives end-to-end
- Excellent written and verbal communication skills in English
- Strong collaboration skills with both technical (engineering, DevOps) and non-technical teams
- Ability to understand and communicate the business impact of security decisions
- Capable of evaluating the security posture across cloud, application, endpoint, and data layers
- Comfortable acting as a trusted advisor and consultant to internal stakeholders
- Proactive mindset with a focus on continuous improvement
- Willingness to provide on-call support for security-related incidents when necessary
- Ownership of security projects from planning to execution and closure
- Ability to track, validate, and close findings from audits, pentests, and internal reviews
- Experience working with ticketing systems (Jira, etc.) to manage security tasks and follow-ups
- Actively contributes to team collaboration, knowledge sharing, and process improvement
- Ability to communicate clearly with internal teams, auditors, and external stakeholders
- Maintains a positive and solution-oriented mindset in a fast-paced environment