Information Security Manager

Aygaz A.Ş.

Ümraniye

On-site

TRY 600,000 - 1,000,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Aygaz A.Ş. in Turkey seeks an experienced IT Governance and Information Security leader to guide governance, risk management, and audit activities across the IT organization, aligning with ISO 27001 and global best practices.

The role focuses on developing enterprise-wide information security strategies, managing audits, and fostering a security-aware culture among cross-functional teams and senior stakeholders.

Qualifications

  • 10+ years of information security leadership and governance experience.
  • At least 3 years in a managerial role.
  • Strong knowledge of ISMS and ISO 27001 with audits and certification processes.
  • Familiarity with KVKK, GDPR and related data privacy laws.
  • Certifications such as CISM, CISSP, CISA, CRISC or ISO 27001 Lead Implementer/Auditor preferred.
  • Ability to lead cross-functional teams and manage stakeholders.

Responsibilities

  • Lead ISMS governance and continuous improvement efforts.
  • Drive ISO 27001 and other IT governance program compliance and audits.
  • Oversee IT risk management, governance and internal controls.
  • Manage vulnerability management, penetration testing and security assessments.
  • Coordinate internal and external security audits and remediation actions.
  • Report security, risk and compliance metrics to senior management.

Skills

Leadership
Governance
Risk management
Information security
Strategic planning
Communication
Stakeholder management
Crisis management

Education

Bachelor's degree

Tools

ISMS ISO27001
SIEM
EDR/XDR
COBIT
ITIL
Audit management tools

Job description

We are seeking an experienced IT Governance and Information Security leader to join our Information Technology organization, providing leadership in information security governance, IT risk management, regulatory compliance, and audit activities, while enhancing the company’s IT governance framework and ensuring alignment with international standards and best practices.

Qualifications
  • Bachelor's degree from a university in a relevant field of study
  • Minimum 10 years of experience in information security, cybersecurity, IT risk management, governance, compliance, or related disciplines,
  • Proven experience leading information security or cybersecurity teams, with at least 3 years in a managerial role,
  • Strong expertise in Information Security Management Systems (ISMS), particularly ISO 27001, with hands-on experience managing internal audits, external audits, and certification processes,
  • Demonstrated experience in developing, implementing, and continuously enhancing enterprise-wide information security strategies,
  • Sound knowledge of information security regulations and data privacy requirements, including KVKK, GDPR, and related legislation,
  • Experience in identifying, assessing, and managing information security risks across complex technology environments,
  • Proven track record in vulnerability management, penetration testing, security assessments, and security monitoring practices,
  • Strong understanding of SIEM, EDR/XDR, threat management, and incident response capabilities,
  • Experience designing and implementing end-to-end security architectures leveraging both defensive and offensive cybersecurity approaches,
  • Knowledge of secure software development practices (DevSecOps) and the integration of security controls throughout the software development lifecycle,
  • Familiarity with IT governance, service management, and control frameworks such as COBIT and ITIL,
  • Relevant professional certifications such as CISM, CISSP, CISA, CRISC, and/or ISO 27001 Lead Implementer/Auditor are preferred,
  • Strong leadership capabilities with a demonstrated ability to build, develop, and mentor high-performing teams,
  • Ability to lead initiatives that strengthen information security awareness and foster a security-focused culture across the organization,
  • Proven ability to collaborate effectively with cross-functional IT teams and business stakeholders,
  • Excellent communication and stakeholder management skills, with the ability to build strong relationships with senior leadership, audit teams, and external partners,
  • Strong decision-making, problem-solving, and crisis management capabilities, with a proactive and results-oriented mindset.
Key Responsibilities
  • Lead the management and continuous improvement of the Information Security Management System (ISMS)
  • Drive compliance programs related to ISO 27001 and other relevant IT governance, risk, and security standards
  • Assess and enhance compliance with information security policies, procedures, standards, and control requirements across IT teams
  • Lead IT risk management, governance, and internal control activities to strengthen the organization’s security posture
  • Oversee the identification, assessment, mitigation, and monitoring of information security and IT-related risks
  • Manage the vulnerability management program and ensure timely remediation of identified security gaps
  • Coordinate penetration testing, security assessments, and independent security review activities
  • Lead internal and external audit engagements and ensure the effective remediation of audit findings
  • Monitor regulatory, legal, and policy changes and ensure organizational compliance with applicable information security requirements
  • Oversee the alignment of IT service management (ITSM) processes with security, control, and compliance requirements
  • Manage third-party and vendor security risk assessment processes
  • Establish and report key information security, risk, and compliance metrics to senior management on a regular basis
  • Promote and strengthen a culture of information security awareness across the organization
  • Ensure that security, risk, and compliance requirements are integrated into IT projects and technology initiatives
  • Continuously monitor emerging cyber threats, industry trends, and evolving security practices, providing strategic recommendations to management for enhancing the organization's security capabilities.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Manager
Information Security Manager

Aygaz • Ümraniye

On-site
TRY 450,000 - 750,000
Senior Information Security & Risk Leader
Senior Information Security & Risk Leader

Aygaz • Ümraniye

On-site
TRY 450,000 - 750,000
Information Security Specialist
Information Security Specialist

Aygaz • Fatih

On-site
TRY 450,000 - 650,000
Director Information Security
Director Information Security

Executas HR and Business Solutions • Fatih

On-site
TRY 1,500,000 - 2,100,000
Strategic Information Security Director: Risk, Resilience & Strategy
Strategic Information Security Director: Risk, Resilience & Strategy

Executas HR and Business Solutions • Fatih

On-site
TRY 1,500,000 - 2,100,000
Head of IT & Information Security
Head of IT & Information Security

Hsb Solutions • Turkey

On-site
TRY 500,000 - 1,000,000
Senior Infrastructure and Application Security Specialist
Senior Infrastructure and Application Security Specialist

Gizli • Fatih

On-site
TRY 300,000 - 500,000
IT Information Security Specialist
IT Information Security Specialist

Nobel Ilac A.S • Ümraniye

On-site
TRY 600,000 - 900,000
Senior Information Security & Compliance Specialist
Senior Information Security & Compliance Specialist

Nobel Ilac A.S • Ümraniye

On-site
TRY 600,000 - 900,000
Senior Information Technologies Process Management Specialist
Senior Information Technologies Process Management Specialist

GİZLİ • Fatih

On-site
TRY 700,000 - 1,100,000