Apply Edge Start your job search

Senior IT Governance, Risk & Compliance Specialist

GİZLİ · Istanbul, Türkiye

Apply & track with Apply Edge

QualificationsBachelor’s degree in Computer Engineering, Industrial Engineering, Electrical-Electronics Engineering, Mathematics Engineering, Computer Science, Management Information Systems, or other relevant disciplines,Minimum 5 years of experience in IT Governance, IT Risk, IT Compliance, Information Security Compliance, IT Audit, or related areas, preferably within the financial services sector,Knowledge and practical experience in BDDK regulations applicable to information systems, information security, IT risk management, and IT audit processes,Hands-on experience with ISO/IEC 27001 Information Security Management System (ISMS), including internal audits, control testing, certification/surveillance audit preparation, and remediation activities,Knowledge and experience in relevant standards and frameworks such as ISO/IEC 27001, COBIT, ITIL, and NIST,Knowledge of IT risk assessment methodologies, control design, control testing, and control effectiveness assessment,Experience in translating regulatory and standard requirements into control requirements, compliance checklists, control matrices, and periodic testing plans,Experience in internal, external, independent, and regulatory audit processes, including preparation and assessment of audit evidence,Experience in performing gap analyses and tracking audit findings, control deficiencies, and remediation actions through closure,Experience in preparing and maintaining IT and information security policies, procedures, standards, instructions, and process documentation,Knowledge of Business Continuity Management (BCM), Business Impact Analysis (BIA), Disaster Recovery (DR), and related testing processes,Good understanding of IT infrastructure, information security, access management, patch and vulnerability management, backup, logging, change management, and similar IT control areas,Knowledge of ITIL processes and IT service management,Strong analytical thinking, documentation, reporting, problem-solving, and follow-up skills,Ability to effectively communicate and coordinate with technical teams, management, auditors, and other stakeholders,Preferably experienced in banking, financial services, factoring, financing, or other regulated industries,ISO/IEC 27001 Lead Auditor/Lead Implementer, CISA, CRISC, COBIT, or similar certifications are preferred.ResponsibilitiesEstablish, develop, operate, and ensure the sustainability of IT Governance, Risk & Compliance processes,Establish and operate a continuous IT compliance and control monitoring mechanism covering applicable BDDK regulations, ISO/IEC 27001 requirements, internal policies, and other relevant regulatory and contractual requirements,Monitor applicable legislation, regulations, standards, and regulatory guidance; assess their impact on IT and information security processes and coordinate required compliance activities,Maintain a regulatory and compliance obligations register and periodically review changes in applicable regulatory requirements,Translate regulatory and standard requirements into measurable IT controls, control owners, evidence requirements, testing procedures, and review frequencies,Establish and maintain an IT Compliance Control Matrix / Control Library mapping regulatory and standard requirements to internal policies, procedures, technical controls, control owners, evidence requirements, and testing frequencies,Develop and execute annual and periodic IT compliance and control testing plans based on regulatory requirements and risk assessments,Perform and document periodic control testing and compliance reviews covering areas including information security, identity and access management, privileged access management, periodic access reviews, patch management, vulnerability management, backup and restore, log management, change management, configuration management, business continuity, disaster recovery, third-party services, and other relevant IT control areas,Assess the design and operating effectiveness of IT controls through evidence-based reviews and identify control deficiencies and improvement opportunities,Maintain continuous audit and compliance readiness by ensuring that required documentation, control evidence, records, and supporting materials are current, complete, traceable, and readily available,Coordinate between IT teams, Information Security teams, Risk and Compliance functions, internal auditors, independent audit firms, and regulatory authorities during internal, external, independent, and regulatory audits,Coordinate the preparation, validation, and timely provision of IT documentation and audit evidence requested during audits,Record audit findings, control deficiencies, and compliance gaps; identify relevant action owners and target dates; and monitor remediation actions through closure,Perform IT risk assessments, maintain the IT Risk Register, and monitor risk treatment and mitigation actions in collaboration with relevant technical and business units,Prepare, update, and periodically review IT and information security policies, procedures, standards, instructions, and process documentation,Monitor IT processes to ensure that they are performed in accordance with approved policies, procedures, standards, regulatory requirements, and defined controls,Support the establishment and maturity improvement of IT processes in line with ITIL principles, including Incident Management, Problem Management, Change Management, Request Management, Configuration Management, and Service Level Management,Define and periodically review roles and responsibilities related to IT processes and controls and establish RACI matrices where required,Support Business Continuity Management (BCM), Business Impact Analysis (BIA), Disaster Recovery (DR), and periodic/annual DR testing activities from an IT governance, risk, and compliance perspective,Monitor third-party and outsourced IT services from a governance, risk, compliance, and control perspective and follow up on identified risks and remediation actions,Establish and monitor KPI, KRI, SLA, compliance, audit, and control-effectiveness metrics and prepare periodic management reports and dashboards,Report significant IT risks, compliance gaps, overdue actions, recurring control deficiencies, and audit findings to relevant management and governance bodies,Track improvement opportunities related to IT governance, risk, compliance, and control processes and coordinate their implementation with relevant teams,Contribute to the continuous improvement and maturity of the organization’s IT Governance, Risk & Compliance framework.