702,996open jobs
41,505companies
99,778added this week
Browse all
Salary
$52k – $145k per year (Estimated)
Location
In office (Istanbul)
Seniority
Senior · 6+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Lostar, siber güvenlik danışmanlığı, sızma testi, denetim ve uyum hizmetleriyle kurumların dijital risklerini yönetmesine destek olur.

Founded in 1998, Lostar is one of Turkey's longest-established independent information security firms, with more than 1,500 projects delivered over more than 25 years.

Our services span offensive security - internet and intranet penetration testing - alongside governance and compliance work against internationally recognised frameworks (ISO 27001, ISO 22301, ISO 20000, ISO 9001, COBIT, ITIL), data protection programmes under KVKK and GDPR, and employee security awareness programmes built on our own methodology.

Our consultants are trained and experienced, and they design solutions that balance technical rigour with commercial reality: the optimal answer for the client, not the most expensive one. Rooted in Turkey, we work from three offices - Istanbul, London and Sakarya.

We work with the best to create the best service and value for our clients.

Follow us

  • LinkedIn: Lostar
  • Instagram: LostarInfoSec
  • X (TR): Lostar · X (EN): Lostar_EN
  • YouTube: LostarTV
  • Facebook: Lostar · Facebook (Jobs): LostarKariyer

Websites: https://lostar.com (EN) · https://lostar.com.tr (TR)

We are looking for a Senior Consultant to join Lostar's Governance, Risk and Compliance practice.

You will advise enterprise clients across banking, capital markets, insurance, energy, telecommunications and manufacturing on information security management, IT service management, business continuity and data protection. This is a client-facing senior role: you will own delivery on your engagements rather than support someone else's.

How the week works. Our hybrid model is built around client work rather than desk time: two days per week at client sites (primarily in Istanbul), three days remote, and one day per month together at our Istanbul office for team, methodology and practice development. Assignments outside Istanbul come up periodically, along with occasional travel to our London office, so you should be comfortable travelling when an engagement calls for it.

What you will do

  • Lead GRC engagements end to end: scoping, gap analysis, control design, documentation, implementation support and internal audit.
  • Advise clients against international standards and frameworks (ISO 27001, ISO 22301, ISO 20000, ISO 9001, COBIT, ITIL) and applicable regulation - KVKK, GDPR, and sector-specific requirements from Turkish regulators including BDDK, SPK, TCMB, EPDK and SEDDK.
  • Run two to four parallel engagements: track status, manage scope and timelines, and keep both the client and internal teams continuously informed.
  • Prepare and present findings, risk assessments and remediation roadmaps to client management, up to and including board level.
  • Support clients through certification audits and regulatory examinations.
  • Mentor junior consultants and contribute to our internal methodology, templates and quality standards.
  • Contribute to business development: scoping calls, proposal and statement-of-work input, and research into emerging regulatory areas (NIS2, DORA, the EU Cyber Resilience Act, the EU AI Act) before they become client requirements.
  • Work with our AI-assisted delivery tooling and help shape it - we build our own platforms for project delivery, evidence management and reporting.

Required

  • Bachelor's degree in Computer Engineering, Software Engineering, Electrical & Electronics Engineering, Industrial Engineering, Information Systems or Computer Science - or equivalent professional experience in a related field.
  • Minimum 6 years' experience in IT governance, information security management, IT audit or GRC consultancy.
  • Demonstrable hands-on delivery on projects involving internationally recognised standards, frameworks and applicable regulation (ISO 27001, ISO 22301, ISO 20000, ISO 9001, COBIT, ITIL, KVKK, GDPR or equivalent).
  • Solid command of information technology and information security concepts and practices.
  • Proven project management experience, including managing multiple concurrent engagements.
  • Ability to produce audit-quality documentation and present to senior stakeholders.
  • Professional-level written and spoken Turkish and English (C1 or above in both).
  • Full-time availability and willingness to travel as engagements require.

Preferred

  • Master's degree in information technology, information security or management.
  • At least one relevant certification: ISO 27001 / ISO 22301 / ISO 20000 / ISO 9001 Lead Auditor or Internal Auditor, CISA, CRISC, CISM or CISSP.
  • Experience in regulated sectors - financial services, insurance, energy or telecommunications.
  • Familiarity with emerging EU regulation (NIS2, DORA, CRA, AI Act) and its implications for Turkish organisations.

How you work

  • Curious, and genuinely following developments in technology, regulation and practice.
  • Effective, efficient and outcome-oriented.
  • A strong communicator, comfortable taking initiative, and a real team player.

What we offer

  • Breadth of exposure. Across our client portfolio you will see more regulated environments in a year than most in-house roles offer in five - and you will see them from the inside, at decision level.
  • Work that runs ahead of the market. We build methodology for NIS2, DORA, CRA and the EU AI Act before they land as client obligations, which means you advise rather than catch up.
  • Certifications and training on us. We cover the full cost of role-relevant certifications and training - ISO lead auditor tracks, CISA, CRISC, CISM - and give you the study time to do them properly.
  • Tooling that respects your time. We build our own delivery platform: AI-assisted drafting, structured evidence management, and four-eye quality control on every deliverable. Your hours go into judgement, not formatting.
  • A clear path. Senior Consultant to Principal Consultant or Practice Lead, based on delivery quality, client trust and the people you develop - not on tenure.
  • Professional visibility. Our consultants publish, speak at conferences and teach at university level. If you want a public profile in this field, we will actively support it.
  • Institutional depth. More than 25 years, three offices, 1,500+ projects. There are senior people to escalate to and a proven methodology to build on rather than reinventing every engagement.
  • Hybrid working as described above, private health insurance, and meal and transport support.
  • One more thing, for those who read to the end:

In the message or cover letter field of your application, write "Annex A" and add one sentence naming an ISO 27001 Annex A control that in your experience most organisations implement badly.

Applications without it are not reviewed. This is deliberate. We would rather read fifty applications from people who read the posting than five hundred from people who did not. If you have got this far, you are already the kind of candidate we are looking for.

We respond to every application that meets the above.

Lostar is an equal opportunity employer. We assess applications solely on qualifications and experience, and we do not discriminate on the basis of gender, age, disability, ethnicity, religion or any other protected characteristic. Personal data submitted as part of your application is processed in accordance with KVKK and our candidate privacy notice.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
702,996 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Istanbul
$176k – $301k per year (Estimated) • Remote • Full-Time • Bachelor's Degree • United States
AI/ML
AI Agents
Agentic Workflows
DevOps
SLI/SLO/SLA
Wi-Fi
Cybersecurity
ISO 27001
SOC 2
GDPR
Analytics
Master Data Management
Apply
Head of Engineering 5 days ago
$44k – $91k per year (Estimated) • Equity • In office • 8+ years exp • Bachelor's Degree • Johannesburg
AI/ML
Copilot
Cursor
Claude Code
AI Agents
LLMOps
LLM Guardrails
EU AI Act
Machine Learning
DevOps
GCP
Azure
AWS
Platform Engineering
FinOps
Cybersecurity
GDPR
Management
Agile
Scrum
Apply
Solution Architect 5 days ago
$35k – $83k per year (Estimated) • In office • Full-Time • Sofia
DevOps
GCP
Azure
AWS
FinOps
DNS
Cybersecurity
ISO 27001
SOC 2
Zero Trust
Microsoft Entra ID
Apply
$76k – $160k per year (Estimated) • Remote/Hybrid • Full-Time • 5+ years exp • Warsaw
Cybersecurity
GDPR
Apply
$48k – $62k per year • Remote/Hybrid • Contractor • Budapest
Cybersecurity
GDPR
Apply
$47k – $123k per year (Estimated) • Remote/Hybrid • Full-Time • Istanbul
Python
PowerShell
Bash
AI/ML
Red Teaming
DevOps
VMWare
Hyper-V
GitHub
Linux
Windows
TCP/IP
DNS
DHCP
VPN
VLAN
Cybersecurity
Nmap
Impacket
BloodHound
NetExec
Responder
Microsoft Entra ID
Active Directory
LDAP
Apply
Penetration Tester 8 months ago
$34k – $82k per year (Estimated) • Remote/Hybrid • Full-Time • 2+ years exp • Istanbul
AI/ML
Red Teaming
Cybersecurity
ISO 27001
Active Directory
Apply
$39k – $85k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Istanbul
Analytics
Power BI
Microsoft Excel
Management
Microsoft Office
Apply
$61k – $139k per year (Estimated) • Remote/Hybrid • Full-Time • 5+ years exp • Istanbul
Apply
Equity • In office • Full-Time • Istanbul
Design
SolidWorks
Fusion 360
AutoCAD
Apply
$72k – $134k per year (Estimated) • Remote/Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • Istanbul
Java
Kotlin
SQL
Java
Spring Boot
Databases
RabbitMQ
Apache Kafka
DevOps
Rest API
CI/CD
Git
Docker
Kubernetes
Web3
Smart Contracts
Management
Agile
Apply
See all jobs
This is one of many
702,996 more open roles from verified company boards, updated every day.