At Forcerta, I deliver a third-party risk management engagement for Yapı Kredi Bank, assessing external service providers and coordinating risk-based remediation. I also review log records and control evidence for BDDK/BRSA expectations and support ISO 27001 audits and security governance.
For the Women's Tennis Association (WTA), I supported the ISO 27001 program, including scope definition, risk planning and security documentation. I also assessed third-party vendors and developed privacy, data-retention, security-awareness and AI acceptable-use policies.
At Sovos Compliance, I partnered with cloud and product teams on security architecture, customer assurance and technical risk decisions. I participated in SIRT investigations and managed vulnerability risk using Qualys, Rapid7 and Kenna Security.
Earlier, I performed web, mobile and network penetration tests as a Junior Penetration Tester at Btyön Consultancy. My experience also includes security operations, cloud security, banking compliance and pre-sales engineering for security and networking solutions.

