Skip to main content
HimalayasHimalayas logo
Buğra ÖğütBT
Looking for a job

Buğra Öğüt

@bugraogut

20+ years in GRC, quality and infosec, with ISO, risk, audit and compliance experience across automotive, IT, energy, SaaS, and cybersecurity.

Turkey
Message

What I'm looking for

Governance, Risk and Compliance Professional | Consultant and Auditor

I’m looking to lead GRC and information security work—turning ISO/NIST requirements into practical processes, driving risk and evidence readiness, and supporting audit-ready compliance for technology, energy, and critical-infrastructure environments.

I am a Governance, Risk and Compliance professional with 20+ years of experience across automotive, IT services, energy, SaaS, and cybersecurity.

I build practical, scalable, and audit-ready management systems—grounded in ISO 27001, ISO 9001, ISO 42001, ISO 20000, ISO 27701, and ISO 22301—while strengthening compliance posture through clear governance and risk priorities.

I lead consultancy and management activities for domestic and international clients, assessing maturity, identifying gaps, prioritizing risks, and preparing for audits against ISO standards and frameworks such as IEC 62443, NIST SP 800 series, and CIS Controls.

I am also certified as ISO 27001 LA, ISO 42001 LA, ISO 9001 IA, Information and Communication Security Guide Compliance D1 D2 Lead Auditor, ITIL V3 Foundation.

I translate requirements into day-to-day business processes, especially in SaaS and technology-driven environments, ensuring audit evidence is complete and customer-aligned.

I bring hands-on auditing and operational discipline from global organizations such as Honda, Siemens, and Atos.

My background includes internal audits, risk assessment and control improvement, policy/procedure and documentation development, certification readiness, supplier assessments, and internal process review—so compliance works as an enabling system, not just a checkbox.

Experience

Work history, roles, and key accomplishments

AC

Senior GRC Expert

ADEO Cybersecurity

May 2024 - Feb 2026 (1 year 9 months)

Provided GRC consultancy to assess client maturity, identify gaps, prioritize risks, and prepare audit readiness for ISO/IEC and regulatory frameworks including ISO 27001, ISO 27701, ISO 20000, ISO 22301, IEC 62443, KVKK, NIST SP 800 series, and CIS Controls. Delivered cybersecurity maturity assessments and ISMS consulting engagements for domestic and international clients.

OA

Business Processes & Quality Manager

Optimum Otomotiv Satış Sonrası Çözümleri A.Ş.

May 2023 - May 2024 (1 year)

Supported governance, risk, compliance, and information security activities in a SaaS/technology-driven environment by improving risk controls, preparing audit evidence, and recommending internal process improvements. Helped align business processes with ISO 9001, ISO 27001, ISO 27701, ISO 22301, and KVKK requirements.

ODC İş Çözümleri Danışmanlık A.Ş. logoOA

Governance, Risk and Compliance Manager

Mar 2021 - Mar 2023 (2 years)

Improved compliance posture and information security governance by strengthening internal processes, documentation, and audit readiness for security, data protection, risk management, and business continuity requirements. Developed policies and procedures and supported customer security/compliance expectations aligned to ISO standards and GDPR/KVKK.

BT

ISO 27001 Auditor

BTYÖN Teknoloji

Feb 2021 - Mar 2021 (1 month)

Planned, conducted, and reported ISO 27001 ISMS internal audits for BTYÖN's clients. Produced audit results and supported assessment activities across diverse client industries.

OA

Quality and Process Manager

Odeon Yazılım ve Teknoloji A.Ş.

Jun 2020 - Dec 2020 (6 months)

Supported ISO 9001, ISO 20000, ISO 27001, and ITIL-based management systems through process analysis, documentation, and continuous improvement activities. Helped align internal processes and controls with KVKK/GDPR personal data protection requirements.

OA

Quality Manager

Optimum Otomotiv Satış Sonrası Çözümleri A.Ş.

Apr 2017 - Jun 2020 (3 years 2 months)

Managed governance, risk, compliance, and information security activities by improving compliance posture, security practices, internal processes, documentation, and audit readiness. Supported alignment with ISO 27001 and GDPR/KVKK requirements for risk management and business continuity.

Siemens Sanayi ve Ticaret A.Ş. logoSA

Business Excellence Specialist

Siemens Sanayi ve Ticaret A.Ş.

Dec 2014 - Mar 2017 (2 years 3 months)

Supported quality management, process governance, documentation, internal audit preparation, and compliance-related activities in the energy management sector. Coordinated corrective/preventive action tracking and audit evidence management to support continuous improvement and customer expectations.

Atos Bilişim ve Danışmanlık A.Ş. logoAA

Quality, Security and Risk Specialist

Jan 2010 - Dec 2014 (4 years 11 months)

Supported enterprise IT services environments with ISO-based management system activities, including quality management, information security, internal audits, and governance documentation. Contributed to implementation, maintenance, and improvement of ISO 9001, ISO 27001, and ISO 20000-aligned processes and certification readiness.

HA

Quality Development Engineer

Honda Türkiye A.Ş.

Mar 2007 - Dec 2009 (2 years 9 months)

Supported quality management and process improvement in automotive manufacturing through documentation, internal control activities, and corrective action management. Performed process reviews and contributed to root cause analysis, corrective/preventive action follow-up, and continuous improvement.

TC

Quality Assurance Officer

55th Maintenance Center Command

Feb 2006 - Nov 2006 (9 months)

Established and applied the AQAP-2120 NATO Quality Management System in a maintenance center command environment and trained military and civilian personnel. Produced QMS documentation including quality manual content, policies, procedures, plans, instructions, and templates.

AT

Project Executive

A-Kalite Danışmanlık ve Eğitim Ltd. Şti.

May 2004 - Nov 2005 (1 year 6 months)

Provided client consultancy for ISO 9001, ISO 14001, and ISO 45001 management systems. Supported management system adoption through advisory and implementation guidance.

Education

Degrees, certifications, and relevant coursework

Anadolu University logoAU

Anadolu University

Bachelor of Science, Management Information Systems

2019 - 2023

Grade: GPA: 3.11/4.00

Completed a BSc in Management Information Systems at Anadolu University (2019–2023), with a GPA of 3.11/4.00.

Marmara University logoMU

Marmara University

Master of Science, Engineering Management

2003 - 2005

Grade: GPA: 92/100

Earned an MSc in Engineering Management (with thesis) at Marmara University (2003–2005), with a GPA of 92/100.

Dokuz Eylül University logoDU

Dokuz Eylül University

Bachelor of Science, Industrial Engineering

1999 - 2003

Grade: GPA: 2.94/4.00

Completed a BSc in Industrial Engineering at Dokuz Eylül University (1999–2003), with a GPA of 2.94/4.00.

Tech stack

Software and tools used professionally

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan