CoreX Holding is a highly diversified, vertically integrated, global industrial conglomerate established in 2024 by Robert Yüksel YILDIRIM after 35 years of his vast industrial, financial, and operational experience at YILDIRIM Group. With financial headquarters in Amsterdam, the Netherlands, and operational headquarters in Istanbul, Türkiye, CoreX is dedicated to creating new success stories through a visionary approach and exponential growth under the leadership and vision of its founder, Robert Yüksel YILDIRIM.
CoreX operates in 8 sectors, including metals & mining, ports & terminals, chemicals, green energy, shipping & logistics, infrastructure & construction, international trading, and financial investments. The company is active in 33 countries across 5 continents, employing over 25,000 people globally. As a profit-driven company, CoreX intends to focus on its future growth, utilizing its deep experience and extensive business know-how.
We are looking for a Senior IT Audit Manager to join our headquarters in Maslak, Istanbul.
Role Summary
The Senior IT Audit Manager will lead IT and technology audit engagements across multiple countries and business sectors, including metals and mining, ports and terminals, logistics, construction, and energy.
The role is responsible for assessing technology risks and evaluating the design and operating effectiveness of controls across the Group’s IT infrastructure, information security environment, operational technology systems (OT/SCADA), and digital transformation initiatives.
The position will also contribute to the annual IT risk assessment, the development of the risk-based IT Audit Plan, and the preparation of executive-level reporting. It offers broad exposure to senior management, country leadership teams, and key technology stakeholders across the Group.
Qualifications
- Bachelor’s degree in Computer Engineering, Management Information Systems, Software Engineering, Industrial Engineering, or a related technical discipline. A master’s degree is considered an advantage.
- CISA certification is required. Additional certifications such as CRISC, CISM, CISSP, CEH, or ISO/IEC 27001 Lead Auditor are considered strong advantages.
- At least 10 years of relevant experience in IT audit, IT governance, technology risk management, or cybersecurity assurance, including a minimum of five years in a leadership or managerial capacity.
- Experience within a multinational industrial group, preferably operating in critical infrastructure sectors such as ports, logistics, energy, heavy industry, or mining, is highly desirable.
- In-depth knowledge of leading IT governance, risk management, and information security frameworks, including COBIT, ISO/IEC 27001, NIST, and ITIL.
- Strong knowledge of applicable data protection and cybersecurity legislation and regulatory requirements, including the GDPR, KVKK, and the NIS2 Directive.
- Solid understanding of IT general controls, application controls, network and infrastructure security, cloud computing environments, identity and access management, and industrial control systems, including OT/SCADA security.
- Full professional proficiency in written and spoken English, with the ability to prepare and present reports in an international business environment.
- Experience using computer-assisted audit techniques and data analytics tools such as SQL, Python, ACL, and Power BI.
- Experience with audit management and governance, risk, and compliance platforms.
- Strong analytical, communication, leadership, and stakeholder management capabilities.
- Willingness and ability to travel internationally as required.
Responsibilities
- Support the Chief Audit Officer in preparing and presenting clear, concise, and risk-focused IT audit reports, executive summaries, and technology risk dashboards to senior management and the Audit Committee.
- Lead and oversee the execution of the annual IT Audit Plan, ensuring that technology, cybersecurity, and operational technology audits are performed independently, objectively, and in accordance with applicable professional standards.
- Evaluate the design and operating effectiveness of internal controls across key areas, including IT governance, infrastructure, cloud environments, cyber defence, identity and access management, business continuity and disaster recovery, and third-party technology risk management.
- Assess compliance with applicable local and international technology regulations, cybersecurity legislation, and data protection requirements, including KVKK, the GDPR, and the NIS2 Directive.
- Identify IT control deficiencies, cybersecurity vulnerabilities, and process inefficiencies, and recommend practical, proportionate, and high-impact actions to mitigate technology risks.
- Collaborate with the CIO, CISO, and business-unit technology leaders to assess emerging risks relating to artificial intelligence, automation, cloud transformation, the Internet of Things, and other developing technologies.
- Lead and advance the use of data analytics, continuous auditing, continuous control monitoring, and automated control-testing methodologies throughout the audit lifecycle.
- Support technology due diligence and post-acquisition integration reviews from an information security, cybersecurity, and technology risk perspective.
- Monitor the implementation of agreed management actions and provide timely escalation of overdue or high-risk remediation items.
- Mentor, coach, and develop members of the IT audit team, supporting the development of technical expertise, leadership capabilities, and professional qualifications.
What We Offer
- A strategic leadership role within a growing global industrial group with an ambitious technology and digital transformation agenda.
- International assignments across a highly diverse portfolio of businesses, industries, and geographies.
- Direct exposure to senior executives, CIOs, CISOs, and country leadership teams.
- The opportunity to build, shape, and modernize a data-driven and technology-focused IT Audit function.
- Significant professional development opportunities in emerging technology risks, operational technology security, data analytics, and global regulatory compliance.
We look forward to meeting you!
Many thanks for your attention in advance.