Information Security Engineer (Remote)

    Istanbul, Turkiye
    Full-Time
    Mid (3-6 yrs)
    IT & Security
    First posted 179 days ago
    And now? Now we are looking for a Security Engineer who wants to take their career one step further. If you think you are one of those people, here you will have the chance to work with the world's leading brands with Artificial Intelligence & Machine Learning technologies. Right now, while you are reading this, we are sending an average of 2.2 billion requests and almost 2 billion instant notifications to more than 450 servers a day. On the Artificial Intelligence and Predictive side, we have more than 100 TB of historical data. We do not wait for jobs or opportunities to come to our feet, we create them. We have now reached 25% of global users. If all these interests you, read on for more!
    Our Engineers and Software Developers always think with an innovative perspective, taking advantage of the inexhaustible power of the digital world. They create impressive and intelligent products like a true artist. Our Product and Development teams are located in our Istanbul office, so we produce and develop the technology we export to the world in our own country. As Insider One, we believe in cooperation and adapting the innovations brought by technology by acting fast. We work closely with other Departments with agile teams, and we are not afraid of getting our hands dirty. As we said; we do not wait for jobs or opportunities to come to our feet, we create them ourselves. You can check our Tech Stacks here!
    What You Will Do
  1. Drive the implementation, maintenance, and continuous improvement of the ISO 27001 Information Security Management System (ISMS), including control maturity tracking and audit readiness
  2. Support SOC 2 Type II compliance efforts, including control implementation, evidence collection, and audit coordination
  3. Conduct and document internal audits, manage findings, and follow up on remediation plans across teams
  4. Own and evolve the company-wide risk management program, including risk register, scoring methodology, risk acceptance, and exception processes
  5. Provide governance and security oversight for AWS environments, including cloud security posture, access controls, and configuration baselines
  6. Collaborate with Red Team and Blue Team to track, prioritize, and close technical security findings
  7. Maintain, update, and enforce security policies, standards, and procedures across the organization
  8. Design and execute security awareness and training programs tailored to different roles (engineering, ops, business)
  9. Lead third-party/vendor security assessments, including risk evaluation, tiering, and continuous monitoring
  10. Support and coordinate security incident handling, reporting, and post-incident review processes
  11. Contribute to data protection and privacy governance (KVKK, GDPR), including DPIA processes and data lifecycle management
  12. Drive AI / LLM governance practices, including secure usage policies, data exposure controls, and risk assessments for AI tools
  13. Act as a security consultant to business units and engineering teams, supporting secure architecture, design reviews, and risk-based decision making
  14. Contribute to security architecture and design review processes, including threat modeling and secure design guidance
  15. Coordinate and enhance business continuity and disaster recovery (BCP/DR) processes, including testing, documentation, and continuous improvement
  16. What You Will Need
  17. Strong knowledge of ISO 27001, ISMS processes, internal audits, and control frameworks
  18. Hands-on experience with risk management practices, including risk identification, scoring, and mitigation tracking
  19. Experience in Business Continuity Management (BCM) and disaster recovery planning
  20. Solid understanding of AWS services and cloud security governance, including IAM, logging, and baseline hardening
  21. Familiarity with SOC 2 Type II framework and control domains
  22. Understanding of data security concepts, including data classification, data inventory, and data protection mechanisms
  23. Experience with vendor security and third-party risk management processes
  24. Knowledge of privacy regulations such as KVKK and GDPR, including practical implementation
  25. Familiarity with AI/LLM risks and governance concepts is a strong plus
  26. Strong documentation and reporting skills for audits, compliance, and executive visibility
  27. Experience in responding to customer security questionnaires and audits
  28. Soft Skills & Expectations
  29. Strong analytical thinking and ability to assess both technical and business risks
  30. Ability to take ownership of security domains and drive initiatives end-to-end
  31. Excellent written and verbal communication skills in English
  32. Strong collaboration skills with both technical (engineering, DevOps) and non-technical teams
  33. Ability to understand and communicate the business impact of security decisions
  34. Capable of evaluating the security posture across cloud, application, endpoint, and data layers
  35. Comfortable acting as a trusted advisor and consultant to internal stakeholders
  36. Proactive mindset with a focus on continuous improvement
  37. Additional Expectations
  38. Willingness to provide on-call support for security-related incidents when necessary
  39. Ownership of security projects from planning to execution and closure
  40. Ability to track, validate, and close findings from audits, pentests, and internal reviews
  41. Experience working with ticketing systems (Jira, etc.) to manage security tasks and follow-ups
  42. Actively contributes to team collaboration, knowledge sharing, and process improvement
  43. Ability to communicate clearly with internal teams, auditors, and external stakeholders
  44. Maintains a positive and solution-oriented mindset in a fast-paced environment
  45. What We Offer
  46. Enjoy a monthly meal allowance designed to enhance your daily routine.
  47. Access comprehensive private health insurance.
  48. Feed your curiosity with access to Spotify, LinkedIn Learning, Blinkist, MasterClass, Neoskola, and CloudGuru.
  49. Level up with internal trainings covering AI fundamentals, coding, foreign languages, and a wide range of personal development skills.
  50. Be part of a diverse team that’s as global as it gets, where every voice is heard and 50+ nationalities build together.
  51. Become a Shareowner through our eligibility-based “ESOP” and own a piece of what you build.
  52. Help build the team you want to work with and enjoy rewarding referral bonuses.
  53. Opportunities to give back to your community through volunteering and purpose-driven social impact projects.
  54. From global retreats to team-building activities, expect year-round events that turn into lifelong memories.
  55. Get inspired by the greatest minds in the tech industry through events like our Tech & Dev Talks.
  56. Work from anywhere in Turkey through our fully remote setup.
  57. We aren't just hiring for a position; we are hiring for a mission — a mission to build a lasting legacy that will set the benchmark for the most progressive tech companies out there.
    To do this, we are looking for exceptional talent to join a community of good-hearted individuals who take high ownership and are relentlessly driven to go the extra mile.
    If this sounds like who you are and where you aspire to be, we are excited to meet you.

    We provide equal opportunity in a zero-discrimination workplace and not just welcome but also embrace everyone without regard to sex, race, color, nationality, religion, gender identity, sexual orientation, disability status, citizenship, or marital status.

    Please follow Insider One on LinkedIn, Instagram, X, Facebook and Medium!

    Company:  Insider

    Provides an AI-powered customer engagement platform with CDP, personalization, and cross-channel journey orchestration.
    1001-5000 employees
    Marketing & Advertising
    HQ: Turkey