Risk, Compliance & Information Security Executive

Ticimax

Ataşehir

On-site

TRY 400,000 - 560,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Ticimax is seeking a Risk, Compliance & Application Security Executive to ensure our software products are secure and compliant with regulations. You will manage PCI DSS and ISO 27001 programs, oversee vulnerability assessments, and coordinate internal and external penetration tests.

You will analyze vulnerabilities, implement controls, and enhance our GRC/ SIEM monitoring while preparing for audits and maintaining documentation. Strong English communication is required for global teamwork.

Qualifications

  • Experience with PCI DSS and ISO 27001 compliance and certification.
  • Hands-on vulnerability assessment and penetration testing.
  • Strong documentation and audit preparation skills.
  • Proficiency in English (written and verbal).

Responsibilities

  • Manage PCI DSS (Service Provider Level 1) and ISO 27001 compliance and certification processes
  • Analyze security vulnerabilities and propose effective technical and organizational controls
  • Plan and coordinate internal and external penetration tests, and follow up on remediation
  • Perform regular vulnerability assessments using tools such as Nessus, Qualys, etc.
  • Conduct risk assessments and prepare corrective action plans
  • Use SIEM and GRC tools for monitoring and reporting
  • Prepare for audits and manage relevant documentation
  • Raise awareness across the organization on compliance and security best practices

Skills

PCI DSS
ISO 27001
Vulnerability scanning
GRC & compliance reporting
Documentation & audit prep
English language

Tools

Nessus
Qualys
SIEM

Job description

Shape Your Future at Ticimax!
Position: Risk, Compliance & Application Security Executive
Location: Kozyatağı Allianz Tower (Hybrid)
Job Summary

We are looking for a Risk, Compliance & Application Security Executive to ensure our software products are secure and compliant with relevant regulations. This role will manage penetration testing, vulnerability assessment, and oversee certification processes such as PCI DSS and ISO 27001.

Responsibilities:
  • Manage PCI DSS (Service Provider Level 1) and ISO 27001 compliance and certification processes
  • Analyze security vulnerabilities and propose effective technical and organizational controls
  • Plan and coordinate internal and external penetration tests, and follow up on remediation
  • Perform regular vulnerability assessments using tools such as Nessus, Qualys, etc.
  • Conduct risk assessments and prepare corrective action plans
  • Use SIEM and GRC tools for monitoring and reporting
  • Prepare for audits and manage relevant documentation
  • Raise awareness across the organization on compliance and security best practices
Required Skills:
  • Solid understanding of PCI DSS and ISO 27001 frameworks
  • Hands-on experience with vulnerability scanning tools (e.g. Nessus, Qualys) and SIEM platforms
  • Familiarity with GRC systems and compliance reporting
  • Strong documentation, audit preparation, and analytical skills
  • Proficiency in English (written and verbal)
Nice to Have:
  • Experience in secure software development practices
  • Familiarity with remediation follow-ups after penetration tests
  • Relevant certifications (e.g. OSCP, CEH, ISO 27001 Lead Auditor, CISA)
Does This Interest You?
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT MANAGER
IT MANAGER

Ticimax • Ataşehir

Hybrid
Training and career growth opportunities
Supportive team atmosphere
Regular team events
Senior System Engineer
Senior System Engineer

Ticimax • Ataşehir

Hybrid
TRY 45,000 - 65,000
Opportunities for training and career growth
Supportive working atmosphere
Regular team celebrations
InfoSec & Compliance Exec - PCI/ISO 27001, App Security
InfoSec & Compliance Exec - PCI/ISO 27001, App Security

Ticimax • Ataşehir

Hybrid
TRY 400,000 - 560,000
Senior IT & Infrastructure Lead - Hybrid, Cloud & Security
Senior IT & Infrastructure Lead - Hybrid, Cloud & Security

Ticimax • Ataşehir

Hybrid
Training and career growth opportunities
Supportive team atmosphere
Regular team events
EY Türkiye - Cyber Security / Manager
EY Türkiye - Cyber Security / Manager

Ernst & Young Advisory Services Sdn Bhd • Fatih

On-site
TRY 350,000 - 750,000
EY Türkiye - Risk Consulting / Senior Consultant (İstanbul)
EY Türkiye - Risk Consulting / Senior Consultant (İstanbul)

Ernst & Young Advisory Services Sdn Bhd • Fatih

On-site
TRY 2,310,000 - 3,235,000
Flexible work environment
Diverse, inclusive culture
Senior Security Engineer 'Information Security Architecture'
Senior Security Engineer 'Information Security Architecture'

Yapı Kredi Teknoloji • İzmit

Hybrid
TRY 180,000 - 240,000
Hybrid work model
Koç Group Community offices
Structured technology career path
+3
EY Türkiye - Cyber Security / Manager
EY Türkiye - Cyber Security / Manager

EY • Fatih

On-site
TRY 400,000 - 700,000
Cyber Security (Offensive) Associate/Senior Associate (JP00359)
Cyber Security (Offensive) Associate/Senior Associate (JP00359)

PwC Türkiye • Fatih

On-site
TRY 300,000 - 450,000
EY Türkiye - Cyber Security / Senior Consultant
EY Türkiye - Cyber Security / Senior Consultant

Ernst & Young Advisory Services Sdn Bhd • Fatih

On-site
TRY 350,000 - 520,000