
Information Security Officer
Job description
About the role
The role establishes and maintains the security posture for the Turkish regulatory environment. The position acts as the local security owner for the Turkish entity and its infrastructure.
Security professionals protect systems, data, and users. They review code, run tests, monitor threats, and respond to incidents. The field spans application security, infrastructure security, and governance. Security work is careful, evidence based, and constantly evolving. Security teams work in a landscape of constant change, with new threats and new rules every year. Most companies invest heavily in training and tooling for their teams.
Key facts
What you'll do
Incident response is led at the CISO level for high-severity security events.
Local infrastructure and cloud environments, including AWS and Huawei Cloud, are secured to support customer-facing platforms.
The local security team is built and managed, including defining roles, hiring talent, and developing capabilities.
Requirements
The posting states a bachelor's degree requirement. 8+ years of information security experience is mandatory, including at least 3 years in a CISO, Deputy CISO, or Head of Security capacity.
Experience with Turkish financial regulators (SPK) or TÜBİTAK-criteria audits is required.
A strong knowledge of KVKK and its practical implementation is required.
Solid understanding of cloud security, network security, and application security is required.
Experience building security programs in regulated financial institutions such as banking, fintech, capital markets, or crypto is required.
Excellent communication skills in both Turkish and English are required.
A strong risk management mindset and the ability to translate technical risk into business impact are required.
Nice to have
Direct experience at a cryptocurrency exchange or digital asset company is advantageous.
Familiarity with cryptoasset custody security, cold and hot wallet architecture, and key management is beneficial.
Certifications such as CISSP, CISM, CISA, and ISO 27001 Lead Auditor are valued.
Exposure to multi-jurisdiction compliance across regions such as the EU and KZ is beneficial.
Practical notes
The role is based in Istanbul, Turkey, and requires presence in this location.
Typical interview steps
Security interviews usually include a technical assessment, a threat modeling exercise, and behavioral rounds. Candidates may be asked to review a code sample for vulnerabilities or design a secure system. Practical knowledge and clear risk communication are the core skills. Interviewers often ask how you triage and communicate risk. Showing calm judgment under pressure matters as much as technical depth.
Good to know
Information security professionals in financial services operate under strict regulatory frameworks.
The role commonly involves audits, risk registers, and policy documentation.
Cloud platforms, wallet systems, and key management solutions are central to the work.
Security standards such as ISO 27001 and NIST CSF provide common control baselines.
Clear communication with regulators and executive stakeholders is a core part of the position.
Questions to ask
Good questions to ask the employer in the interview: what does success look like in the first six months, how is the team structured, what is the current biggest challenge, and how are decisions made. Asking about growth paths and the review process is also well received. Employers expect questions, and good ones show preparation.
Career growth
Security careers grow from analyst or engineer to senior, staff, and leadership roles. Specializations include cloud security, application security, and security operations. Certifications help early; demonstrated impact matters later. Security careers reward specialization and a track record of finding and fixing real issues. Written communication of risk is a core skill at senior levels.