InfoSec Strategy Lead - ISO 27001 & Risk Oversight

AXA Türkiye

Fatih

On-site

TRY 600,000 - 800,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Performance‑Based Bonus
Private Pension System
Share Purchase Program
Private Health Insurance
Life Insurance
Family health coverage
Transportation support
Meal Card
Flexible Benefits Program
AXA Competency Academy

Job summary

AXA Türkiye is seeking a senior information security leader to shape and evolve the corporate information security strategy in alignment with business objectives. The role involves governance, regulatory compliance (ISO 27001, PCI-DSS, KVKK, GDPR) and overseeing audit processes with proactive risk monitoring.

Ideal candidate will have 5+ years in information security, strong stakeholder management, and relevant certifications (CISSP/CISM/CISA/ISO 27001 Lead Auditor).

Qualifications

  • Bachelor's degree in a related field such as MIS, CE, SE, IE or E&E.
  • Minimum 5 years in information security, IT risk, internal control or audit functions.
  • Solid knowledge of cybersecurity risks, security architectures, IAM, network security, and security operations.
  • Certifications such as CISSP, CISM, CISA and/or ISO 27001 Lead Auditor/Lead Implementer are preferred.
  • Strong analytical thinking, problem solving and stakeholder management.
  • Excellent planning and organizational abilities.
  • Hands‑on experience with DLP and vulnerability scanners.
  • Ability to follow English-language resources and communicate professionally in English.

Responsibilities

  • Shape and evolve the corporate information security strategy aligned with business objectives.
  • Contribute to security governance frameworks and decision-making processes.
  • Ensure sustainable compliance with ISO 27001, PCI-DSS.
  • Drive implementation and oversight of security requirements related to KVKK, GDPR and other regulatory frameworks.
  • Manage audit processes and remediation of findings.
  • Maintain communication with executive management and governance committees.
  • Lead vulnerability management and security risk monitoring; report security metrics.

Skills

Information security governance
Stakeholder management
English communication
Vulnerability management
Security operations
DLP tools
Security risk monitoring
Analytical thinking

Education

Bachelor's degree in MIS/CE/SE/IE/EE

Tools

ISO 27001 Lead Auditor/Lead Implementer
PCI-DSS

Job description

AXA Group

As one of the world’s leading insurance companies, AXA serves 93 million customers with more than 145,000 employees in 51 countries. With its mission of acting for human progress by protecting what matters, its people strategy, “

AXA Türkiye

As AXA Türkiye, united by the

AXA Group

As one of the world’s leading insurance companies, AXA serves 93 million customers with more than 145,000 employees in 51 countries. With its mission of acting for human progress by protecting what matters, its people strategy, “Care & Dare”, ensures that what is valuable to employees, customers, and society is protected with an empathetic approach; by fostering innovation, courage, and a development-oriented mindset. By evolving from a claim payer into a true customer partner, AXA helps people see the future with confidence, not risk; continuously advancing its technologies with a commitment to shaping the future of insurance, fighting climate change, improving access to healthcare services, supporting economic development, and contributing to the production of scientific knowledge.

AXA Türkiye

As AXA Türkiye, united by the One AXA spirit and recognized for its bold moves in the industry, our culture is built on thinking differently, pursuing innovation, and putting people at the center. Guided by the belief that everyone at AXA has talent — each with their own potential — our AXA Employee Experience Journey is fundamentally shaped by talent management.

Through our human resources strategy—which we define as a holistic approach to talent, placing the employee at the center of the entire journey—we provide a personalized experience for everyone.

With practices that simplify, digitalize, and enhance employee experience, we support our people in discovering their strengths, realizing their potential, taking ownership of their development, shaping their work and careers, and progressing confidently with the pride of being part of AXA.

Aligned with our talent acquisition strategy that states “We hire for AXA, not for the position,” our goal is not only to meet the human resource needs we search for, but also we grow with people who embrace leadership at every level and shape their own career paths — nurturing leaders from within our own organization.

At AXA Türkiye, we create inclusive environments where everyone feels they truly belong, regardless of gender, race, age, or other differences. We foster a working culture that enriches diversity and overcomes challenges together; we offer opportunities that allow each employee to contribute to society, the environment, and their own personal development. From the very beginning of our recruitment processes, we adopt an unbiased approach to ensure everyone is evaluated with equal opportunities.

Are you ready to get to know us better on this journey where sustainable development and growth open new doors — and where you can set your own pace and direction?

Competencies We Expect in Our New Team Member

  • Bachelor's degree in Management Information Systems, Computer Engineering, Software Engineering, Industrial Engineering, Electrical & Electronics Engineering, or a related field
  • Minimum 5 years of experience in Information Security, Information Technology, IT Risk Management, Internal Control, and Audit functions
  • Solid knowledge of cybersecurity risks, security architectures, identity and access management, network security, and security operations
  • Preferably holding one or more of the following certifications: CISSP, CISM, CISA, and/or ISO 27001 Lead Auditor/Lead Implementer
  • Strong analytical thinking, problem-solving, and stakeholder management skillsExcellent planning and organizational abilities
  • Hands-on experience with Data Loss Prevention (DLP) and vulnerability scanning tools
  • Ability to effectively follow English-language resources and communicate professionally in an English-speaking business environment
  • Strong influencing and persuasion skills, with the ability to manage resistance and drive alignment across stakeholders

Areas Where You Will Create Impact

  • Shape and evolve the corporate information security strategy in alignment with business objectives
  • Actively contribute to security governance frameworks and decision-making processes
  • Ensure the sustainable compliance of security practices with international standards such as ISO 27001 and PCI-DSS
  • Drive the implementation and oversight of security requirements related to KVKK, GDPR, and other relevant regulatory frameworks
  • Manage audit processes and ensure timely remediation of findings in line with business priorities
  • Maintain active communication with executive management and governance committees on information security matters
  • Lead vulnerability management and security risk monitoring processes, and regularly report security metrics and performance indicators
  • Assess security requirements and risks throughout project lifecycles, ensuring appropriate controls are embedded from the outset

What We Offer At AXA Türkiye

  • Performance-Based Bonus
  • Employer-Contributed Private Pension System
  • Employee Discounted Share Purchase Program (Shareplan)
  • Private Health Insurance including psychological support coverage
  • Life Insurance
  • Supplementary Health Insurance for spouses and children
  • Discounted OSS and TSS for mothers and fathers
  • Discounted auto, home, and personal accident insurance
  • Transportation support or shuttle
  • Meal Card
  • “Your Choice” Flexible Benefits Program
  • AXA Competency Academy (AYA)

⚕️ Within our holistic Health and Well-being Program Take Care of Yourself” we offer: medical check-ups for employees aged 40 and above, digital medical check-ups, home care services, AXA independent living support, AXA doctor consultation line, Employee Assistance Program (Psychological Counseling, Dental, Mini Check-Up, Psychiatric Treatments, and Supportive Health Services).

⏳ Under Our ‘Waits For You!’ Platform, Designed To Support Work–life Balance, We Provide Additional Support To Our Colleagues Through a Variety Of Leave Types Such As Birthday, “Take Care Of Yourself”, Marriage, Report Card Day, Moving, Hourly Leave, Child Illness, Maternity And Paternity Leave. Additionally

  • Flexibility for Mothers: Remote work until the baby turns 1 year old after maternity leave
  • Flexibility for New Parents: A half-day off each week for up to six months after returning from parental leave
  • Work From Home With Your New Pet: 3 days of remote work when adopting a new pet to support their adjustment.

✅ To create an innovative, flexible, and simple working environment, we bring together all our flexible practices under the “YES!” umbrella—such as Work Anywhere, Flexible Working Hours, Summer Flexibility, Year-End Break, and Your Time—ensuring a working model that supports work-life balance.

Join AXA Türkiye and make your mark on your career journey by setting your own direction and pace 🚀

Visit our career website to learn more about AXA!

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Unit Lead
Information Security Unit Lead

AXA Türkiye • Fatih

On-site
TRY 600,000 - 800,000
Performance‑Based Bonus
Private Pension System
Share Purchase Program
+7
Executive Cybersecurity Strategy Lead
Executive Cybersecurity Strategy Lead

EY • Fatih

On-site
TRY 400,000 - 700,000
Senior Information Security & Risk Leader
Senior Information Security & Risk Leader

Aygaz • Ümraniye

On-site
TRY 450,000 - 750,000
Information Security Manager
Information Security Manager

Aygaz • Ümraniye

On-site
TRY 450,000 - 750,000
IT & Information Security Lead — ISO 27001 & Cloud Ops
IT & Information Security Lead — ISO 27001 & Cloud Ops

Hsb Solutions • Turkey

On-site
TRY 500,000 - 1,000,000
Cybersecurity Strategy Lead: Exec Engagement & Innovation
Cybersecurity Strategy Lead: Exec Engagement & Innovation

Ernst & Young Advisory Services Sdn Bhd • Fatih

On-site
TRY 350,000 - 750,000
InfoSec & Security Operations Lead (ISO 27001, NIS2, SIEM)
InfoSec & Security Operations Lead (ISO 27001, NIS2, SIEM)

Aras Kargo • Fatih

Hybrid
TRY 300,000 - 420,000
Hybrid work model
Birthday leave
Paternity leave (30 days)
+5
Information Security & Risk Analyst
Information Security & Risk Analyst

Mavi • Fatih

On-site
TRY 300,000 - 420,000
Senior Information Security & Compliance Specialist
Senior Information Security & Compliance Specialist

Nobel Ilac A.S • Ümraniye

On-site
TRY 600,000 - 900,000
Cybersecurity Operations Lead
Cybersecurity Operations Lead

Watsons Turkey • Fatih

On-site
TRY 450,000 - 750,000