Information Security Manager İş İlanı

İşveren Hakkında
 İş İlanları

QUALIFICATIONS AND JOB DESCRIPTION

The Information Security Manager’s mission is to provide an effective Information Security capability to proactively protect the confidentiality, integrity and availability of Bupa Acıbadem Sigorta data, intellectual property, information and technology assets.

  • Actively govern Information Security and Cyber Security risks in the company that meets compliance, regulatory requirements and Bupa Acıbadem Sigorta’s risk appetite.
  • Work with global teams to ensure IT policies, standards, and control frameworks to local laws, regulations and other local requirements.
  • Responsible for Information Security, Cyber Security, Data Privacy and actions required by laws and regulations (ISO 27001, PCI/DSS, SOX, COBIT, GDPR, KVKK).
  • Continuous Security monitoring, vulnerability and penetration testing and compliance monitoring activities.
  • To create and manage a targeted information security awareness training program for all employees, contractors and approved system users, and establish metrics to measure the effectiveness of the program.
  • Design, develop, and implement Cyber security solutions for various products and solutions, as required.
  • Evaluate, define, and assess application security requirements, including threat and vulnerability assessment.
  • Perform vendor, software and application security assessments.
  • Develop, maintain and execute a proactive Information Security strategy that evolves with the business needs.
  • Create and maintain security and data privacy, data protection and encryption, security assessment, incident response documentation and procedures.
  • Review and analyze security alerts and vulnerabilities from vendors and other security sources


  • 10+ years information security and/or related technology experience and track record in information security and risk management.
  • Must have at least a bachelor's degree, preferably in computer science or engineering fields.
  • Knowledge and experience in Cybersecurity, IT and Governance frameworks such as ISO 27001/27002, NIST, SOX, PCI/DSS, GDPR, KVKK, COBIT, ITIL.
  • Solid knowledge of security principles and practices.
  • Practices and methods of IS strategy, enterprise architecture and security architecture.
  • Excellent command of Turkish and English
  • Proven experience in the following topics are desired:
  1. Windows and Linux based operating systems,
  2. Network protocols, routing and switching
  3. Firewalls, IDS/IPS, WAF, EDR, SIEM, VPN, MFA, DDos protection
  4. Cyber intelligence, ethical hacking and threat modeling, secure coding practices
  5. Vulnerability management, Threat management, SAST, DAST