
at Shell
CommoditiesPosted 9 days ago
No clicks
**IT Compliance Analyst - Experienced Professional** Drive IT security compliance in Turkey, ensuring systems' security controls meet ISO9001, ISO27001, and TS EN ISO 14001 standards. Key responsibilities include: - Managing ISO27001 surveillance audits and recertification processes - Protecting IT infrastructure, ensuring confidentiality, integrity, and availability - Coordinating penetration testing for applications - Representing IT in company-wide compliance activities and providing security guidance - Monitoring and managing security incidents, applying metrics for control effectiveness - Planning and delivering information security awareness trainings - Experienced in IT security or cyber defense, with a proven track record in ISO27001 processes Requires 7+ years of experience, strong communication skills, and ability to adapt to unproven technologies. Must be comfortable with changing scope and priorities, and capable of working under pressure.
- Compensation
- Not specified
- City
- Istanbul
- Country
- Not specified
Currency: Not specified
Full Job Description
Job Family Group:
Worker Type:
Posting Start Date:
Business Unit:
Experience Level:
Job Description:
Job Purpose
Ensure that Security controls for Systems are in place, provide for support IS027001 Certification Process and to implement IT Security Policies as necessary.
Accountabilities:
Working in full compliance with ISO9001 Quality Management System and ISO/IEC 27001 Information Security Management System.
Fully compliant with TS EN ISO 14001 Environmental Management System standards/procedures/work instructions.
Directly drives Shell Turkeys annual ISO/IEC 27001 surveillance audits and the full recertification process conducted every three years, ensuring organizational readiness, evidence coordination, audit execution, and timely closure of all findings.
Responsible for protecting IT infrastructure by ensuring confidentiality, integrity and availability of information assets.
Responsible for ensuring that all applications supported in Turkey undergo regular penetration testing, managing the endtoend process including coordination of tests, sharing of findings, and driving the timely remediation of all identified vulnerabilities.
Represents IT in all company-wide compliance activities and provides organizationwide guidance on Shells information security requirements, ensuring alignment with corporate policies, ISO/IEC 27001 standards, and overall security posture.
Participate in the establishment and maintenance of information security policies and standards that support business goals and objectives
Fully responsible for monitoring, managing, and coordinating all security incidents occurring in Turkey, ensuring endtoend engagement with IRM, driving the incident process, and providing timely updates to senior management.
Apply metrics to measure, monitor, and report on the effectiveness of information security controls and compliance with information security policies
Control and ensure that information security is not compromised
Report on the performance of the information security management system to top management.
Responsible for planning, coordinating, and delivering all information security awareness trainings for all users across Turkey in line with ISO/IEC 27001 requirements.
Responsible for creating PRs/POs, monitoring invoices, and capitalizing IT assets.
Dimensions:
Individual contributor
No direct budget responsibility
Typical Job Grade of Supervisor/Manager: JG4 or higher
Skills & Requirements:
Minimum 7 years' experience in IT Security or Cyber Defense and ability to adopt new security techniques quickly.
Preferred Experienced in ISO27001 Process and Information Security Guideline.
Experience and knowledge of IT Security Policies.
Good team player and able to efficiently work and communicate with 3rd party service providers
IT Security focused and able to provide trainings to the users.
Able to deliver under time pressure and deliver on strict deadlines
Excellent communication skills.
Good Business English, written and oral
Good Analytical skills
Result oriented
Special Challenges:
The operational nature of the role will require out-of-hour working, sometimes unplanned and on call
Needs to be able to deal with state of the art, differentiated and often unproven technologies which require some learning on the job
Needs to be comfortable with sometimes vague and changing scope and priorities in a rapidly changing environment
Ability to ensure one team mindset across the various teams to drive effective delivery
-
DISCLAIMER:





