Information Security Specialist
USE Insider
Job Summary
Insider is seeking a highly motivated and detail-oriented Information Security Specialist to join their growing security team. The role involves ensuring compliance with security standards like ISO 27001 and SOC 2 Type 2, managing business continuity processes, and supporting security governance for AWS environments. The specialist will drive ISO 27001 ISMS implementation, conduct internal audits, enhance Business Continuity and Disaster Recovery processes, and support SOC 2 Type 2 compliance. Responsibilities also include providing cloud security governance for AWS, collaborating with Red/Blue teams, maintaining security policies, executing security awareness programs, assessing third-party security, handling security incidents, and ensuring alignment with privacy regulations like KVKK and GDPR.
Must Have
- Deep knowledge of ISO 27001, internal audits, and risk management
- Experience in Business Continuity Management (BCM)
- Hands-on knowledge of AWS services and cloud governance
- Familiarity with SOC 2 Type 2 framework
- Solid understanding of databases and data protection
- Strong documentation and reporting skills
- Experience with customer security requirements
- Understanding of KVKK and GDPR
- Strong analytical thinking and communication skills
- Ability to collaborate with technical and non-technical teams
Good to Have
- Willingness to provide on-call support
- Takes ownership of complex security projects
- Works cross-functionally to re-test and close security findings
- Capable of raising internal tickets and driving resolution
- Actively contributes to team collaboration
- Maintains a positive mindset
Perks & Benefits
- Access to "Tech Talks" and "Dev Talks"
- Hackathons and programming competitions
- Free access to Laracast, Egghead, LinkedIn Learning, Blinkist, Masterclass, and Spotify
- Shareowner System
- Inclusive Private Health Insurance
- Monthly Multinet for food expenses
- Team Activities
- No Dress code
Job Description
An Information Security Specialist in Insider day in and day out:
- We are looking for a highly motivated and detail-oriented Information Security Specialist to join our growing security team. The ideal candidate will be responsible for ensuring the organization’s compliance with security standards such as ISO 27001 and SOC 2 Type 2, managing business continuity processes, and supporting security governance on AWS environments. This role requires a proactive mindset, strong technical knowledge, and a good understanding of both internal IT systems and regulatory frameworks like KVKK and GDPR.
- Drive the implementation and continuous improvement of ISO 27001 Information Security Management System (ISMS)
- Conduct and document internal audits and follow up with action plans
- Coordinate and enhance Business Continuity and Disaster Recovery processes
- Support SOC 2 Type 2 compliance efforts and evidence collection
- Provide governance support for AWS infrastructure and cloud security configurations
- Collaborate with internal Red Team and Blue Team to follow up on technical findings
- Maintain, update, and implement security policies, standards, and procedures
- Plan and execute security awareness programs (training, campaigns, gamification, etc.)
- Assess third-party security through security assurance reviews
- Support security incident handling and security reporting processes
- Provide input on privacy regulations (KVKK, GDPR) and ensure alignment with global policies
- Act as a security consultant to business units and IT teams
We want you to join us while we are taking a step into the future if you have:
- Deep knowledge of ISO 27001, internal audits, and risk management practices
- Experience in Business Continuity Management (BCM) processes
- Hands-on knowledge of AWS services and cloud governance best practices
- Familiarity with SOC 2 Type 2 framework and security control families
- Solid understanding of databases, data classification, and data protection methods
- Strong documentation and reporting skills, especially for audit and compliance deliverables
- Experience in preparing and filling customer security requirements
- Understanding of KVKK, GDPR, and related data privacy regulations
- Strong analytical thinking and ability to ask the right questions
- Ability to follow through on complex tasks with minimal oversight
- Excellent written and verbal communication skills
- Strong interpersonal skills, ability to collaborate with technical and non-technical teams
- Ability to understand business value of security within the product and tech ecosystem
- Capable of organizing and reviewing the security posture of network, application, and endpoint layers
- Comfortable providing consultancy and training to internal stakeholders
- Willingness to provide on-call support when necessary
- Takes ownership of complex security projects and delivers end-to-end
- Works cross-functionally to re-test, validate and close security findings
- Capable of raising internal tickets and driving resolution of issues found via audits or reviews
- Actively contributes to team collaboration and gives constructive feedback
- Maintains a positive mindset and can communicate clearly with both internal and external partners
- Advanced in English (written and spoken)
While exporting our technology to the world, we offer you:
- “Tech Talks” with famous and groundbreaking people from the software world, “Dev Talks” where our Software Developers talk about their career steps, and many events where groundbreaking ideas are discussed,
- Hackathons we organize inside that push the boundaries, programming challenges, and coding competitions,
- Free access to exclusive services such as Laracast, Egghead, LinkedIn Learning, Blinkist, Masterclass, and Spotify
- Shareowner System that we offer to all Insiders who meet certain criteria
- Inclusive Private Health Insurance
- Multinet to cover food expenses covered on a monthly basis
- Team Activities that are bursting with fun,
- No Dress code! This is a fast and innovative startup, you can wear whatever you want.