Combining technical depth with governance discipline
Cybersecurity practitioner focused on security governance, evidence-led assurance, privacy, AI risk, and executive-ready risk communication.
Experience spans financial services, technology/SaaS, and digital-platform environments across security engineering, assurance and testing, security-program management, secure SDLC, cloud and container security, risk acceptance, customer assurance, and incident readiness.
vciso.tr is not a software or licensing channel. Recommendations are driven by business risk, evidence quality, customer expectations, and sustainable ownership—not product commissions.
How I work
- Risk before tooling: Clarify business impact and the decision required before selecting a control or product.
- Evidence before claims: Turn “we do this” into verifiable policy, process, technical output, and traceable records.
- Ownership before completion: Governance is not complete without an owner, target date, and closure evidence.
- Executive language: Translate technical findings into risks and options a leadership team or board can act on.
- Minimum unnecessary tooling: Do not buy another platform to solve a problem the existing environment can address.
Areas of expertise
Cybersecurity governance and vCISO
ISO 27001 and SOC 2 readiness
Application and cloud security
Vulnerability and risk management
AI/LLM security and AI governance
Vendor and third-party risk
Customer assurance
Incident readiness and executive reporting
Credentials and education
Security architecture, governance, and risk management foundation.
Security management, program governance, and executive risk alignment.
Structured delivery, stakeholder management, and program execution.
Education: Master’s degree in Information Technologies. Credentials and education are not proof on their own; vciso.tr complements them with practical implementation, transparent methodology, and verifiable-output discipline.