Fatih Kocalar

Fatih Kocalar

Senior Cloud Security Engineer @ AMBOSS

About

I've spent 12+ years doing one thing: Making organizations harder to attack and faster to recover when they are.My work sits at the intersection of technical depth and strategic clarity. I've led SOC operations, built vulnerability management programs from scratch, designed cloud security architectures across hybrid and cloud-native environments, and guided organizations through ISO 27001, NIST, and PCI-DSS compliance not as checkbox exercises, but as genuine risk reduction.The sectors I've worked across fintech, energy, telecommunications, technology, and critical infrastructure, health tech and medical education share a common thread: the cost of getting security wrong is existential. That reality keeps my work grounded.What I have:🔍 Threat Detection & Incident Response: Leading SOC teams through high-pressure incidents and building the playbooks that reduce response time and noise.☁️ Cloud & Enterprise Security Architecture: Designing security frameworks that work in the real world: hybrid, cloud-native, and legacy environments alike.📋 Compliance & Risk Alignment: Translating ISO 27001, SOC2, NIST CSF, and PCI-DSS into practical controls that satisfy regulators and reduce actual risk.🛡️ Vulnerability Management: Building and maturing programs that prioritize what matters, not just what's loud🤝 Cross-Functional Leadership: Bridging the gap between technical teams and business stakeholders so security decisions stick.Open to conversations about security strategy, team building, and complex risk challenges.

Country

-

City

Germany

Industry

Telecommunications

Skill

SOC 2, Business Continuity, Disaster Recovery, Incident Response, Vulnerability Management, Cyber Risk Management, Risk Reduction, Public Speaking, Leadership, Microsoft 365 Security, Project Teams, Communication, Security Controls, Microsoft Defender, Microsoft 356, Amazon Web Services (AWS), Microsoft Azure, Payment Card Industry Data Security Standard (PCI DSS), Network Security, SIEM

Experience

AMBOSS

Senior Cloud Security Engineer

AMBOSS

LinkedIn
2026-2 - Present · 8 mos

Berlin, Germany

To execute the long-term security strategy, aligning technical security debt reduction with business growth and platform scalability. Embedding security best practices from initial design and deep-dive code reviews to automated deployment and continuous monitoring. Acting as the central security authority, coordinating complex initiatives across multiple engineering squads to ensure consistent implementation of security controls and standards. Leading comprehensive security risk assessments To conduct proactive security reviews, identifying potential attack vectors before code reaches production.

Telio Group

IT Security Officer

Telio Group

LinkedIn
2023-6 - 2026-2 · 2 yrs 9 mos

Berlin, Germany

Lead enterprise-wide security initiatives, reducing internal and external cyber risk exposure through proactive detection and remediation strategies. Implement and enforce security controls across Microsoft Azure and Microsoft 365, increasing overall cloud compliance with NIST CSF. Own and manage the vulnerability management lifecycle. Conduct security assessments, to uplift in the organization’s security maturity score. Collaborate cross-functionally with IT, compliance, DevOps, Software Development to ensure alignment with OWASP Top 10, CIS Controls, and ISO 27001. Manage security operations and incident response processes, reducing time to detect and contain threats. Spearheaded continuous improvement initiatives through threat analysis.

Klar

Senior Security Engineer

Klar

LinkedIn
2022-7 - 2023-3 · 9 mos

Berlin, Germany

Designed, deployed, and maintained end-to-end security architectures across cloud and on-prem environments, ensuring high availability and regulatory compliance. Conducted regular penetration tests and vulnerability scans, leading to reduce in exploitable risks. Monitored SIEM and EDR systems for anomalies, implementing behavioral analytics to improve detection coverage across endpoints and servers. Responded to and managed security incidents using documented IR processes. Maintained security policies, access control procedures, and secure coding guidelines aligned with ISO 27001 and NIST 800-53. Collaborated with DevOps and software engineering teams to embed security-by-design and DevSecOps practices into CI/CD pipelines. Regularly assessed threat trends and threat intel feeds, integrating emerging risk scenarios.

iyzico

Information Security Manager

iyzico

LinkedIn
2021-8 - 2022-6 · 11 mos

Istanbul, Turkey

Developed and executed an enterprise-wide information security strategy, enhancing the company’s overall security posture in line with PCI DSS, SOX, and ISO 27001. Built and enforced comprehensive security policies, procedures, and awareness programs, achieving 100% participation in security training across departments. Led risk management processes, identifying, assessing, and mitigating business-impacting risks through continuous evaluation of controls and third-party exposure. Deployed new security tools and technologies, such as DLP, SIEM, and vulnerability scanning platforms, improving incident detection rates. Collaborated with global InfoSec teams and compliance stakeholders to align risk and control frameworks with local and international regulations. Managed security budgets and vendor relationships, optimizing spend while increasing tool efficacy through effective vendor evaluation and contract negotiation. Delivered timely security consulting and risk advice to product, legal, IT, and development teams to ensure secure product delivery and compliance readiness. Drove patch and vulnerability management processes, ensuring critical vulnerabilities were remediated.

Token Finansal Teknolojiler

Senior R&D Specialist - Cloud&Platform

Token Finansal Teknolojiler

LinkedIn
2020-12 - 2021-8 · 9 mos

Ankara, Turkey

Maintaining large scale (150+ servers), high traffic (millions of requests daily), and distributed payment systems, Maintaining configuration assessments of systems to implement CIS Benchmark’s best practices. Managing the availability, latency, scalability, security and efficiency of software and systems both on cloud and on-premises, Managing services compliant with standards PCI-DSS, ISO 20000, ISO 22301 and ISO 27001. Reviewing and influencing new designs, architectures, standards, and methods for cyber security and micro services. Resolving critical service problems that detected on critical services and security products. Configuration of web servers running on docker. Creation of use cases and dashboards, reporting of events and investigation of potential incidents on SIEM solutions. (Graylog, IBM Qradar)

Barikat Cybersecurity

Information Security Consultant

Barikat Cybersecurity

LinkedIn
2019-12 - 2020-12 · 1 yr 1 mo

Ankara, Turkey

Creation of use cases and dashboards, reporting of events and investigation of potential incidents on SIEM solutions. Reviewing, analyzing and developing of Use Cases. Creating and deploying of Incident Response Plans and playbooks for Financial Companies. Security maturity assessments & analysis for Gulf Region Country corporations. Creation of DLP policies, fine tunings and mitigating false positives. Hardening of endpoints and servers with the scope of CIS Benchmarks. Security Architecture Assessments as Zero Trust.

Vangölü Elektrik Dağıtım A.Ş. (Vedaş)

Cyber Security Specialist

Vangölü Elektrik Dağıtım A.Ş. (Vedaş)

LinkedIn
2017-5 - 2019-9 · 2 yrs 5 mos

Ankara, Turkey

Coordinating & Managing OT&IT Security Project. Compliance with Critical Infrastructure Regulations. Managing, updating and configuring security products such as NG Firewall, Mail GW, Antivirus, Load Balancer, SIEM, PAM, NAC, Sandbox. Hardening on systems. Vulnerability analysis Analyzing scada protocols and work flows. Implementing of ISO27001 & ISO27019 standards.

Logsign

Cyber Security Specialist

Logsign

LinkedIn
2017-1 - 2017-5 · 5 mos

SIEM (Logsign) experience including management, rules creation, use case deployment, reporting, correlation and investigation. Consulting to clients about implementing sources in their corporations on SIEM. Updating, troubleshooting and assisting to write correlations & alarms

Vision Solutions

Information Security Consultant

Vision Solutions

LinkedIn
2016-1 - 2016-8 · 8 mos

Ankara, Turkey

Yapı Kredi

Information Technology Auditor

Yapı Kredi

LinkedIn
2014-6 - 2015-12 · 1 yr 7 mos

Kocaeli, Turkey

Auditing with COBITv4 & PCIDSS Standarts and banking regulations in Turkey. Performed internal network penetration tests (host discovery, port scanning and vulnerability analysis with using nmap, wireshark, kali linux and nessus) Performed mobile application test with using BurpSuite for banking application (iOS)

Education

Erciyes University

Erciyes University

LinkedIn

Electrical and Electronics Engineering

2009 - 2013 · 4 yrs
Universidad de Zaragoza

Universidad de Zaragoza

LinkedIn

Telecommunications Engineering

2011 - 2011

Exchange Student Program (ERASMUS)

Fatih Kocalar's Contact Information

Email

******@***.com

Phone

(**) *** ****

Find the Right Leads
Find Verified Contact Data

Try with: Jensen Huang @ nvidia.com Click to autofill
LeadContact awards, five-star ratings, and GDPR compliance badges

What LeadContact does well

Find verified emails, phone numbers, and decision-makers with 98% accuracy.

Find Leads

Find Leads

Find the right people by company, role, industry, location, and more.

925M+ professional profiles

Find Leads
Find Emails

Find Emails

Access verified email addresses for your target contacts.

657M+ emails

Find Emails
Find Phone Numbers

Find Phone Numbers

Get cross-validated phone data from multiple top sources.

239M+ phone numbers

Find Phone Numbers

More Accurate. Lower Cost.

Find contact data in 1 tool with 98% accuracy

LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.

LeadContact Logo
Competitor Tools

All these = $289 per month

Great conversations start with the right contact.

It’s time to find yours.