Istanbul, Istanbul, Türkiye
Experienced Information Security Specialist with a demonstrated history of working in the information technology and services industry. Skilled in Security Automation, Source Code Analysis and Web, Mobile and Container/K8s Security. Strong information security professional specialized in Penetration Testing, DevSecOps and S-SDLC methodologies.
Contributed efforts for planning, designing, testing and implementing solutions for organization's infrastructure, network and endpoint security services. - Responsible from vulnerability management, application security tests and security operations - Prepared procedures for SDLC, vulnerability management, patch management, security testing etc - Supported security product management with policies and event monitoring - Supported infrastructure security projects for cloud environments - Contributed hardening projects for AD, OS, Firewall, Database, Cloud Environments and security solutions like EDR, AV, IPS etc - Carried out certification studies for PCI DSS, PCI PIN, PCI MPOC, ISO 27001 and done GAP analysis for them - Done research, benchmarks and PoCs for cybersecurity products
Provided consultancy on various cybersecurity topics in order to meet customer demands. Lead the cybersecurity and development teams. Took an active role in the sales and local support of security products. - Application Security Tests & Audit & Security Automation - Network Security Tests & Audit - Vulnerability Management Services & Design - Source Code & Software Composition Analysis (SAST & SCA) - VM & AppSec Products Technical Sales & Local Support - Adversary Emulation and Simulation - IT Security GAP Analysis - IT infrastructure management and bussiness related solution development
Managed application security tests and contributed efforts for the development of automation projects for SAST and Vulnerability Managements processes. Delivered active functional support to architecture team about cloud transformation and cloud security. - Responsible from vulnerability management, source code analysis and application security test services - Done threat modeling and risk assessment for internal or external developed software products - Improved SAST functionality with CI/CD integration and increased scope of services - Prepared ALM, VM and application security related procedures - Supported infrastructure security projects for cloud security topics - Supported the endpoint security, e-mail security and network security products management - Participated in SIEM and vault confi guration management - Performed root cause analysis to investigate incidents and events captured in event management