Risk, Compliance & Application Security Executive

Team.blue — Turkey · Posted ~1 hour ago

Mid Full-time Hybrid Visa History ✓

Skills

risk assessment application security penetration testing PCI DSS ISO 27001 vulnerability management SIEM GRC Nessus Qualys

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A security and compliance professional is needed to manage certification processes, conduct risk assessments, coordinate security testing, and improve technical controls for software solutions.

Highlights

Hybrid security role focused on compliance programs, vulnerability management, audits, and improving application security practices.

Description

Shape Your Future at Ticimax! 🚀Position: Risk, Compliance & Application Security ExecutiveLocation: Kozyatağı Allianz Tower (Hybrid)Job SummaryWe are looking for a Risk, Compliance & Application Security Executive to ensure our software products are secure and compliant with relevant regulations. This role will manage penetration testing, vulnerability assessment, and oversee certification processes such as PCI DSS and ISO 27001.Responsibilities:Manage PCI DSS (Service Provider Level 1) and ISO 27001 compliance and certification processesAnalyze security vulnerabilities and propose effective technical and organizational controlsPlan and coordinate internal and external penetration tests, and follow up on remediationPerform regular vulnerability assessments using tools such as Nessus, Qualys, etc.Conduct risk assessments and prepare corrective action plansUse SIEM and GRC tools for monitoring and reportingPrepare for audits and manage relevant documentationRaise awareness across the organization on compliance and security best practicesRequired Skills:Solid understanding of PCI DSS and ISO 27001 frameworksHands-on experience with vulnerability scanning tools (e.g. Nessus, Qualys) and SIEM platformsFamiliarity with GRC systems and compliance reportingStrong documentation, audit preparation, and analytical skillsProficiency in English (written and verbal)Nice to Have:Experience in secure software development practicesFamiliarity with remediation follow-ups after penetration testsRelevant certifications (e.g. OSCP, CEH, ISO 27001 Lead Auditor, CISA)Does This Interest You?If you’re ready to make an impact in the e-commerce landscape, we want to hear from you!🌟