Information Security Manager

Aygaz

Ümraniye

On-site

TRY 450,000 - 750,000

Full time

42 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

We are seeking an experienced IT Governance and Information Security leader to join our Information Technology organization, providing leadership in information security governance, IT risk management, regulatory compliance, and audit activities, while enhancing the company's IT governance framework and ensuring alignment with international standards and best practices.

The role focuses on ISMS (ISO 27001), audits, and risk management, requiring a strong leadership track record and ability to

Qualifications

  • Bachelor's degree in a relevant field
  • 10+ years of experience in information security, IT risk management or governance
  • 3+ years in a managerial role leading security teams
  • ISMS expertise with ISO 27001 and audit/certification experience
  • Knowledge of KVKK, GDPR and data privacy regulations
  • Experience managing information security risks across complex tech environments
  • Proven vulnerability management and incident response capabilities
  • Familiarity with COBIT and ITIL governance frameworks
  • Strong leadership and cross-functional collaboration
  • Excellent stakeholder management and communication skills

Responsibilities

  • Lead the management and continuous improvement of the Information Security Management System (ISMS)
  • Drive compliance programs related to ISO 27001 and IT governance standards
  • Assess and enhance information security policies, procedures and controls
  • Lead IT risk management, governance and internal control activities
  • Oversee identification, assessment and monitoring of information security risks
  • Oversee vulnerability management and remediation of gaps
  • Coordinate penetration testing and security assessments
  • Lead internal and external audit engagements and remediation of findings
  • Monitor regulatory changes and ensure compliance
  • Align IT service management with security and compliance requirements
  • Oversee third-party security risk processes
  • Report security metrics to senior management
  • Foster a culture of information security awareness
  • Integrate security into IT projects and initiatives
  • Monitor emerging threats and provide strategic recommendations

Skills

Leadership
Stakeholder management
Communication skills
Crisis management

Education

Bachelor's degree in a relevant field

Tools

ISO 27001
COBIT
ITIL
CISM
CISSP
CISA
CRISC

Job description

We are seeking an experienced IT Governance and Information Security leader to join our Information Technology organization, providing leadership in information security governance, IT risk management, regulatory compliance, and audit activities, while enhancing the company's IT governance framework and ensuring alignment with international standards and best practices.

Qualifications
  • Bachelor's degree from a university in a relevant field of study
  • Minimum 10 years of experience in information security, cybersecurity, IT risk management, governance, compliance, or related disciplines,
  • Proven experience leading information security or cybersecurity teams, with at least 3 years in a managerial role,
  • Strong expertise in Information Security Management Systems (ISMS), particularly ISO 27001, with hands-on experience managing internal audits, external audits, and certification processes,
  • Demonstrated experience in developing, implementing, and continuously enhancing enterprise-wide information security strategies,
  • Sound knowledge of information security regulations and data privacy requirements, including KVKK, GDPR, and related legislation,
  • Experience in identifying, assessing, and managing information security risks across complex technology environments,
  • Proven track record in vulnerability management, penetration testing, security assessments, and security monitoring practices,
  • Strong understanding of SIEM, EDR/XDR, threat management, and incident response capabilities,
  • Experience designing and implementing end-to-end security architectures leveraging both defensive and offensive cybersecurity approaches,
  • Knowledge of secure software development practices (DevSecOps) and the integration of security controls throughout the software development lifecycle,
  • Familiarity with IT governance, service management, and control frameworks such as COBIT and ITIL,
  • Relevant professional certifications such as CISM, CISSP, CISA, CRISC, and/or ISO 27001 Lead Implementer/Auditor are preferred,
  • Strong leadership capabilities with a demonstrated ability to build, develop, and mentor high-performing teams,
  • Ability to lead initiatives that strengthen information security awareness and foster a security-focused culture across the organization,
  • Proven ability to collaborate effectively with cross-functional IT teams and business stakeholders,
  • Excellent communication and stakeholder management skills, with the ability to build strong relationships with senior leadership, audit teams, and external partners,
  • Strong decision-making, problem-solving, and crisis management capabilities, with a proactive and results-oriented mindset.
Key Responsibilities
  • Lead the management and continuous improvement of the Information Security Management System (ISMS)
  • Drive compliance programs related to ISO 27001 and other relevant IT governance, risk, and security standards
  • Assess and enhance compliance with information security policies, procedures, standards, and control requirements across IT teams
  • Lead IT risk management, governance, and internal control activities to strengthen the organization’s security posture
  • Oversee the identification, assessment, mitigation, and monitoring of information security and IT-related risks
  • Manage the vulnerability management program and ensure timely remediation of identified security gaps
  • Coordinate penetration testing, security assessments, and independent security review activities
  • Lead internal and external audit engagements and ensure the effective remediation of audit findings
  • Monitor regulatory, legal, and policy changes and ensure organizational compliance with applicable information security requirements
  • Oversee the alignment of IT service management (ITSM) processes with security, control, and compliance requirements
  • Manage third-party and vendor security risk assessment processes
  • Establish and report key information security, risk, and compliance metrics to senior management on a regular basis
  • Promote and strengthen a culture of information security awareness across the organization
  • Ensure that security, risk, and compliance requirements are integrated into IT projects and technology initiatives
  • Continuously monitor emerging cyber threats, industry trends, and evolving security practices, providing strategic recommendations to management for enhancing the organization's security capabilities.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security and IT Governance Assistant Manager
Information Security and IT Governance Assistant Manager

Zurich Insurance • Fatih

On-site
TRY 600,000 - 800,000
Senior Information Security & Risk Leader
Senior Information Security & Risk Leader

Aygaz • Ümraniye

On-site
TRY 450,000 - 750,000
Information Security Specialist
Information Security Specialist

Aygaz • Fatih

On-site
TRY 450,000 - 650,000
Senior IT Governance, Risk & Compliance Specialist
Senior IT Governance, Risk & Compliance Specialist

Hepiyi Sigorta • Ümraniye

On-site
TRY 300,000 - 420,000
Head of IT & Information Security
Head of IT & Information Security

Hsb Solutions • Turkey

On-site
TRY 500,000 - 1,000,000
IT Information Security Specialist
IT Information Security Specialist

Nobel İlaç • Ümraniye

On-site
TRY 350,000 - 550,000
InfoSec & IT Governance Lead - Assistant Manager
InfoSec & IT Governance Lead - Assistant Manager

Zurich Insurance • Fatih

On-site
TRY 600,000 - 800,000
IT Information Security Specialist
IT Information Security Specialist

Nobel Ilac A.S • Ümraniye

On-site
TRY 600,000 - 900,000
Senior Information Security & Compliance Specialist
Senior Information Security & Compliance Specialist

Nobel Ilac A.S • Ümraniye

On-site
TRY 600,000 - 900,000
Information Security Specialist
Information Security Specialist

Koç University • Fatih

On-site
TRY 200,000 - 280,000