Furkan Kaan I.

Cybersecurity Engineer | OSCP, CRTP

Ankara, Ankara, Türkiye

About

https://furkankisik.medium.com

Experience

  • Cybersecurity Engineer at Siemens
    Jan 2023 - Present · 3 yrs 6 mos

    •Consulting for cybersecurity solutions internally and externally. •Consulting the software teams for secure software development lifecycle and improve their security awareness. •Analyze security needs and plan security activities considering security-by-design and defence-in-depth approaches. •Take active role for defining and applying internal security policies. •Manage vulnerabilities, cybersecurity issues and planning control and actions. •Implementation security hardening to Siemens environment. •Preparing Feasibility Study and Solution Architect during project lifecycle. •Implementation network discovery and network monitoring tools to customer environment. •Re-design and Architecture for Power Companies' ICS /SCADA environments with cybersecurity focus Analyzed requirements and specifications, then designed network and solutions security-by design with best practices like IEC 62443, NERC CIP, NIS2. Prepared solution descriptions and reports. Consult delivery teams for implementing security controls like network and application security, identity and access management, network monitoring, malware protection, inventory analysis. Did security hardening with best practices and CIS benchmarks. •Endpoint Security Solutions Implementation for Power Companies’ ICS /SCADA environments Consulting determines the most suitable Endpoint Security solution (EDR, AV, DLP) for companies, ensuring the installation and configuration of malware protection and device control.

  • Information Security Specialist at Adalet Bakanlığı
    Jan 2018 - Jan 2023 · 5 yrs 1 mo

    •Conducted internal network penetration testing, vulnerability management, and vulnerability remediation for servers and clients. •Performed web apps penetration testing, vulnerability management, and vulnerability remediation for internal and external applications (DAST, SAST). •Developed and implemented Secure Software Development Life Cycle. •Provided consultancy for suitable security solutions, such as Data Loss Prevention (DLP), Database Firewall (DBF), and Database Activity Monitoring (DAM) tools for the ministry's environment. •Created SIEM rules to detect attacks in the ministry's environment in collaboration with SOC teams. •Mitigated the attack surface using the Cyber Attack Simulation Tool (PICUS). •Developed and implemented security policies and procedures. •Delivered training and awareness programs for employees on information security best practices.

  • Innovera (1 yr 5 mos)
    • Security Consultant
      Jul 2017 - Jan 2018 · 7 mos

      •Post-sales and pre-sales activities •Consulting for cybersecurity solutions to diverse industries, including finance, government, and telecommunications. •Installation, Configuration and Administration for Symantec Endpoint Security Solution (EDR, ATP), Symantec Data Loss Prevention (DLP), Symantec Messaging Gateway (SMG), Infoblox DNS Firewall, Forescout Network Access Control (NAC), Vulnerability Scanner (Nessus, Acunetix).

    • Yarı Zamanlı Yardımcı
      Sep 2016 - Jun 2017 · 10 mos

      •Web app security documentation •Penetration Testing Methodology •Developing web app security testing lab

  • Internship at Oran Teknoloji
    Aug 2016 - Sep 2016 · 2 mos

  • Grocery Clerk at Publix Super Markets
    Jun 2015 - Sep 2015 · 4 mos

    I joined Work & Travel program. I worked as a grocery clark in Publix Super Market South Caroline, USA.