About

Independent cybersecurity leadership, grounded in evidence.

Enfal C is a Chief Information Security Officer with 10+ years of cybersecurity experience, CISSP · CISM · PMP, and a master’s degree in information technologies. The focus is turning technical security work into business risk, ownership, evidence, and decisions.

Practitioner profile

Combining technical depth with governance discipline

Cybersecurity practitioner focused on security governance, evidence-led assurance, privacy, AI risk, and executive-ready risk communication.

Experience spans financial services, technology/SaaS, and digital-platform environments across security engineering, assurance and testing, security-program management, secure SDLC, cloud and container security, risk acceptance, customer assurance, and incident readiness.

vciso.tr is not a software or licensing channel. Recommendations are driven by business risk, evidence quality, customer expectations, and sustainable ownership—not product commissions.

How I work

  • Risk before tooling: Clarify business impact and the decision required before selecting a control or product.
  • Evidence before claims: Turn “we do this” into verifiable policy, process, technical output, and traceable records.
  • Ownership before completion: Governance is not complete without an owner, target date, and closure evidence.
  • Executive language: Translate technical findings into risks and options a leadership team or board can act on.
  • Minimum unnecessary tooling: Do not buy another platform to solve a problem the existing environment can address.

Areas of expertise

Cybersecurity governance and vCISO

ISO 27001 and SOC 2 readiness

Application and cloud security

Vulnerability and risk management

AI/LLM security and AI governance

Vendor and third-party risk

Customer assurance

Incident readiness and executive reporting

Credentials and education

CISSP ISC2

Security architecture, governance, and risk management foundation.

CISM ISACA

Security management, program governance, and executive risk alignment.

PMP PMI

Structured delivery, stakeholder management, and program execution.

Education: Master’s degree in Information Technologies. Credentials and education are not proof on their own; vciso.tr complements them with practical implementation, transparent methodology, and verifiable-output discipline.

Experience context

Security leadership across different operating environments

These are not vciso.tr client references. They are anonymized, high-level summaries of professional career experience.

Financial services

Enterprise security assurance, application security, vulnerability management, cloud security, and AI security.

Technology and SaaS

Security-program and ISMS development, ISO 27001 and SOC 2 readiness, and customer assurance.

Digital platforms

Secure SDLC, threat modeling, security automation, third-party risk, and operational risk.