İş haqqında məlumat:
Position OverviewThe Information Security Engineer is responsible for ensuring the effective governance of information systems, compliance with international and national information security standards, risk management, and internal audit activities within the company. The role includes monitoring information security processes, implementing controls, raising awareness, and supporting the management of information systems in alignment with the company's strategic objectives.Key ResponsibilitiesEnsure that the necessary objectives are achieved in alignment with the company’s strategic plans.Monitor compliance with IT standards and ensure the governance of Information Systems Management Directorate units.Oversee Information Security Management System (ISMS) activities in accordance with international standards (ISO 27001, COBIT) and national regulations (Defense Industry Security Directive, etc.).Identify and assess risks to company assets, determine risk values, and manage information system risks.Plan and implement measures to reduce, eliminate, or transfer identified risks and threats to ensure information security.Plan and conduct internal audits related to information systems security, prepare audit reports, and coordinate with relevant units to address nonconformities.Participate in the preparation and management of Non-Disclosure Agreements (NDAs) related to services provided and received by Information Systems.Establish a recording system for information security incidents, create an incident management platform, and ensure its operation and functionality.Organize and deliver internal training to raise information security awareness among employees.Ensure that IT systems and services are maintained, updated, and audited according to ITIL guidelines, including monitoring administrator access and log records, and execute other tasks assigned by the manager within company interests.
Tələblər:
Bachelor’s or Master’s degree in Information Technology, Cybersecurity, Computer Engineering, or a related fieldMinimum 3–5 years experience in information security, IT governance, or ISMS implementationStrong knowledge of ISO 27001, COBIT, ITIL, and other international information security frameworksExperience with risk management, internal audits, and compliance reportingPractical experience in system monitoring, incident management, and NDA handlingStrong analytical, problem-solving, and coordination skillsAbility to develop and deliver internal information security trainingFamiliarity with system and database administration monitoring tools and log managementEnglish – advanced level, Russian – preferred, Turkish – an advantage
Maaş: Ə/h razılaşma ilə
Son müraciət: 01/10/2026