The #1 platform that brings everything marketing and customer engagement teams need in one place, to become unstoppable.
Senior Information Security Engineer
Location
Turkey
Posted
38 days ago
Salary
0
Seniority
Senior
Job Description
Senior Information Security Engineer
Insider One
• Drive the implementation, maintenance, and continuous improvement of the ISO 27001 Information Security Management System (ISMS), including control maturity tracking and audit readiness • Support SOC 2 Type II compliance efforts, including control implementation, evidence collection, and audit coordination • Conduct and document internal audits, manage findings, and follow up on remediation plans across teams • Own and evolve the company-wide risk management program, including risk register, scoring methodology, risk acceptance, and exception processes • Provide governance and security oversight for AWS environments, including cloud security posture, access controls, and configuration baselines • Collaborate with Red Team and Blue Team to track, prioritize, and close technical security findings • Maintain, update, and enforce security policies, standards, and procedures across the organization • Design and execute security awareness and training programs tailored to different roles (engineering, ops, business) • Lead third-party/vendor security assessments, including risk evaluation, tiering, and continuous monitoring • Support and coordinate security incident handling, reporting, and post-incident review processes • Contribute to data protection and privacy governance (KVKK, GDPR), including DPIA processes and data lifecycle management • Drive AI / LLM governance practices, including secure usage policies, data exposure controls, and risk assessments for AI tools • Act as a security consultant to business units and engineering teams, supporting secure architecture, design reviews, and risk-based decision making • Contribute to security architecture and design review processes, including threat modeling and secure design guidance • Coordinate and enhance business continuity and disaster recovery (BCP/DR) processes, including testing, documentation, and continuous improvement
Job Requirements
- Strong knowledge of ISO 27001, ISMS processes, internal audits, and control frameworks
- Hands-on experience with risk management practices, including risk identification, scoring, and mitigation tracking
- Experience in Business Continuity Management (BCM) and disaster recovery planning
- Solid understanding of AWS services and cloud security governance, including IAM, logging, and baseline hardening
- Familiarity with SOC 2 Type II framework and control domains
- Understanding of data security concepts, including data classification, data inventory, and data protection mechanisms
- Experience with vendor security and third-party risk management processes
- Knowledge of privacy regulations such as KVKK and GDPR, including practical implementation
- Familiarity with AI/LLM risks and governance concepts is a strong plus
- Strong documentation and reporting skills for audits, compliance, and executive visibility
- Experience in responding to customer security questionnaires and audits
- Strong analytical thinking and ability to assess both technical and business risks
- Ability to take ownership of security domains and drive initiatives end-to-end
- Excellent written and verbal communication skills in English
- Strong collaboration skills with both technical (engineering, DevOps) and non-technical teams
- Ability to understand and communicate the business impact of security decisions
- Capable of evaluating the security posture across cloud, application, endpoint, and data layers
- Comfortable acting as a trusted advisor and consultant to internal stakeholders *
- Proactive mindset with a focus on continuous improvement
- Willingness to provide on-call support for security-related incidents when necessary *
- Ownership of security projects from planning to execution and closure
- Ability to track, validate, and close findings from audits, pentests, and internal reviews *
- Experience working with ticketing systems (Jira, etc.) to manage security tasks and follow-ups
- Actively contributes to team collaboration, knowledge sharing, and process improvement
- Ability to communicate clearly with internal teams, auditors, and external stakeholders
- Maintains a positive and solution-oriented mindset in a fast-paced environment
Benefits
- Enjoy a monthly meal allowance designed to enhance your daily routine.
- Access comprehensive private health insurance.
- Feed your curiosity with access to Spotify, LinkedIn Learning, Blinkist, MasterClass, Neoskola, and CloudGuru.
- Level up with internal trainings covering AI fundamentals, coding, foreign languages, and a wide range of personal development skills.
- Be part of a diverse team that’s as global as it gets, where every voice is heard and 50+ nationalities build together.
- Become a Shareowner through our eligibility-based “ESOP” and own a piece of what you build.
- Help build the team you want to work with and enjoy rewarding referral bonuses.
- Opportunities to give back to your community through volunteering and purpose-driven social impact projects.
- From global retreats to team-building activities, expect year-round events that turn into lifelong memories.
- Get inspired by the greatest minds in the tech industry through events like our Tech & Dev Talks.
- Work from anywhere in Turkey through our fully remote setup.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Senior Security Engineer, Software
DraftKings Inc.Defining what it means to build and deliver the most extraordinary sports & entertainment experiences.The Crown is Yours
At DraftKings, AI is becoming an integral part of both our present and future, powering how work gets done today, guiding smarter decisions, and sparking bold ideas. It's transforming how we enhance customer experiences, streamline operations, and unlock new possibilities. Our teams are energized by innovation and readily embrace emerging technology. We're not waiting for the future to arrive. We're shaping it, one bold step at a time. To those who see AI as a driver of progress, come build the future together. The Crown Is Yours As a Senior Security Engineer, you will help shape how we build and scale secure systems across DraftKings, working closely with security engineers and developers to embed secure by default into everything we ship while owning key areas of security functionality and turning strategy into scalable solutions. You bring deep technical expertise, a builder's mindset, and the ability to influence how we approach security across the business, all while collaborating with a global, cross disciplinary team that moves fast, supports one another, and values every perspective from day one. What You'll Do - Design and evolve our secure development lifecycle (SDLC), building the rules, processes, and platforms that keep our systems resilient. - Build and integrate custom and off-the-shelf security tools to automate vulnerability detection across applications and infrastructure. - Act as a subject matter expert on our SDLC, partnering with Detection and Response (DART) to strengthen investigation capabilities. - Lead and influence remediation of complex, cross-functional security issues across teams and systems. - Stay ahead of the threat landscape-identifying risks, tools, and mitigation strategies that keep our platforms secure at scale. - Share knowledge, mentor teammates, and help build a culture where security is a shared responsibility. What You'll Bring - 5+ years of engineering experience building and operating production systems with a security-first mindset. - Strong coding experience in one or more languages; .NET experience is a plus. - Broad technical depth across systems, operating systems, file systems, networking, cloud security, and automation. - A genuine drive to protect the privacy and security of our players and teammates. - Clear, thoughtful communication skills and a collaborative approach to solving complex challenges. - The ability to prioritize, adapt, and deliver in a fast-moving, high-impact environment. Join Our Team We're a publicly traded (NASDAQ: DKNG) technology company headquartered in Boston. As a regulated gaming company, you may be required to obtain a gaming license issued by the appropriate state agency as a condition of employment. Don't worry, we'll guide you through the process if this is relevant to your role. The US base salary range for this full-time position is 136,000.00 USD - 170,000.00 USD, plus bonus, equity, and benefits as applicable. Our ranges are determined by role, level, and location. The compensation information displayed on each job posting reflects the range for new hire pay rates for the position across all US locations. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific pay range and how that was determined during the hiring process. It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Director of Security Partnerships
Infatica.ioGlobal data intelligence partner offering advanced web scraping & ethical proxies. 🌎 Worldwide IP locations since 2019
Infatica.io is a global provider of proxy and DaaS solutions. Now we are looking for an experienced Director of Security Partnerships in information security. Role Overview The role’s objective is to build and develop trusted relationships with leading antivirus vendors and other players in the cybersecurity ecosystem, shaping joint strategies, integrations, and business initiatives
• Lead information security for client solutions and Practice Area technology, partnering with key stakeholders to deliver secure products and services to clients, including on‑premises and cloud infrastructure components. • Embed security controls, patterns, and tooling into product and solution teams across all stages of the secure development lifecycle (SDLC), with a strong focus on shift-left practices. • Oversee security assurance for products and solutions, evaluating the implementation and effectiveness of security controls. • Identify, assess, and manage security weaknesses, vulnerabilities, and risks from multiple sources (e.g. security testing, threat intelligence and audits), ensuring appropriate response and management of these issues (e.g. treatment plans, remediation actions, and risk acceptance where applicable). • Lead Practice Area delivery of relevant global security and transformation initiatives, ensuring successful execution and alignment with Practice Area priorities and client requirements. • Provide Practice Area incident support to Cyber Operations, acting as a security subject matter expert (SME) for the business division and supporting investigations. • Support client security requests, including (but not limited to) RFIs, audits and security questionnaires.
• Develop an agent health and remediation process by which endpoints with deficient endpoint security health are identified and remediated • Lead global agent health monitoring and remediation activities • Leverage IT security tooling to deploy and remove software applications • Collect and document the health criteria for each respective endpoint security agent and report on health metrics globally • Leverage automation to ensure the deployment, monitoring, and logging of endpoint security technology globally




