Fatih Kocalar
Senior Cloud Security Engineer @ AMBOSS
About
I've spent 12+ years doing one thing: Making organizations harder to attack and faster to recover when they are.My work sits at the intersection of technical depth and strategic clarity. I've led SOC operations, built vulnerability management programs from scratch, designed cloud security architectures across hybrid and cloud-native environments, and guided organizations through ISO 27001, NIST, and PCI-DSS compliance not as checkbox exercises, but as genuine risk reduction.The sectors I've worked across fintech, energy, telecommunications, technology, and critical infrastructure, health tech and medical education share a common thread: the cost of getting security wrong is existential. That reality keeps my work grounded.What I have:🔍 Threat Detection & Incident Response: Leading SOC teams through high-pressure incidents and building the playbooks that reduce response time and noise.☁️ Cloud & Enterprise Security Architecture: Designing security frameworks that work in the real world: hybrid, cloud-native, and legacy environments alike.📋 Compliance & Risk Alignment: Translating ISO 27001, SOC2, NIST CSF, and PCI-DSS into practical controls that satisfy regulators and reduce actual risk.🛡️ Vulnerability Management: Building and maturing programs that prioritize what matters, not just what's loud🤝 Cross-Functional Leadership: Bridging the gap between technical teams and business stakeholders so security decisions stick.Open to conversations about security strategy, team building, and complex risk challenges.
-
Germany
Telecommunications
SOC 2, Business Continuity, Disaster Recovery, Incident Response, Vulnerability Management, Cyber Risk Management, Risk Reduction, Public Speaking, Leadership, Microsoft 365 Security, Project Teams, Communication, Security Controls, Microsoft Defender, Microsoft 356, Amazon Web Services (AWS), Microsoft Azure, Payment Card Industry Data Security Standard (PCI DSS), Network Security, SIEM
Experience

Senior Cloud Security Engineer
Berlin, Germany
To execute the long-term security strategy, aligning technical security debt reduction with business growth and platform scalability. Embedding security best practices from initial design and deep-dive code reviews to automated deployment and continuous monitoring. Acting as the central security authority, coordinating complex initiatives across multiple engineering squads to ensure consistent implementation of security controls and standards. Leading comprehensive security risk assessments To conduct proactive security reviews, identifying potential attack vectors before code reaches production.

IT Security Officer
Berlin, Germany
Lead enterprise-wide security initiatives, reducing internal and external cyber risk exposure through proactive detection and remediation strategies. Implement and enforce security controls across Microsoft Azure and Microsoft 365, increasing overall cloud compliance with NIST CSF. Own and manage the vulnerability management lifecycle. Conduct security assessments, to uplift in the organization’s security maturity score. Collaborate cross-functionally with IT, compliance, DevOps, Software Development to ensure alignment with OWASP Top 10, CIS Controls, and ISO 27001. Manage security operations and incident response processes, reducing time to detect and contain threats. Spearheaded continuous improvement initiatives through threat analysis.

Senior Security Engineer
Berlin, Germany
Designed, deployed, and maintained end-to-end security architectures across cloud and on-prem environments, ensuring high availability and regulatory compliance. Conducted regular penetration tests and vulnerability scans, leading to reduce in exploitable risks. Monitored SIEM and EDR systems for anomalies, implementing behavioral analytics to improve detection coverage across endpoints and servers. Responded to and managed security incidents using documented IR processes. Maintained security policies, access control procedures, and secure coding guidelines aligned with ISO 27001 and NIST 800-53. Collaborated with DevOps and software engineering teams to embed security-by-design and DevSecOps practices into CI/CD pipelines. Regularly assessed threat trends and threat intel feeds, integrating emerging risk scenarios.

Information Security Manager
Istanbul, Turkey
Developed and executed an enterprise-wide information security strategy, enhancing the company’s overall security posture in line with PCI DSS, SOX, and ISO 27001. Built and enforced comprehensive security policies, procedures, and awareness programs, achieving 100% participation in security training across departments. Led risk management processes, identifying, assessing, and mitigating business-impacting risks through continuous evaluation of controls and third-party exposure. Deployed new security tools and technologies, such as DLP, SIEM, and vulnerability scanning platforms, improving incident detection rates. Collaborated with global InfoSec teams and compliance stakeholders to align risk and control frameworks with local and international regulations. Managed security budgets and vendor relationships, optimizing spend while increasing tool efficacy through effective vendor evaluation and contract negotiation. Delivered timely security consulting and risk advice to product, legal, IT, and development teams to ensure secure product delivery and compliance readiness. Drove patch and vulnerability management processes, ensuring critical vulnerabilities were remediated.

Senior R&D Specialist - Cloud&Platform
Ankara, Turkey
Maintaining large scale (150+ servers), high traffic (millions of requests daily), and distributed payment systems, Maintaining configuration assessments of systems to implement CIS Benchmark’s best practices. Managing the availability, latency, scalability, security and efficiency of software and systems both on cloud and on-premises, Managing services compliant with standards PCI-DSS, ISO 20000, ISO 22301 and ISO 27001. Reviewing and influencing new designs, architectures, standards, and methods for cyber security and micro services. Resolving critical service problems that detected on critical services and security products. Configuration of web servers running on docker. Creation of use cases and dashboards, reporting of events and investigation of potential incidents on SIEM solutions. (Graylog, IBM Qradar)

Information Security Consultant
Ankara, Turkey
Creation of use cases and dashboards, reporting of events and investigation of potential incidents on SIEM solutions. Reviewing, analyzing and developing of Use Cases. Creating and deploying of Incident Response Plans and playbooks for Financial Companies. Security maturity assessments & analysis for Gulf Region Country corporations. Creation of DLP policies, fine tunings and mitigating false positives. Hardening of endpoints and servers with the scope of CIS Benchmarks. Security Architecture Assessments as Zero Trust.

Cyber Security Specialist
Ankara, Turkey
Coordinating & Managing OT&IT Security Project. Compliance with Critical Infrastructure Regulations. Managing, updating and configuring security products such as NG Firewall, Mail GW, Antivirus, Load Balancer, SIEM, PAM, NAC, Sandbox. Hardening on systems. Vulnerability analysis Analyzing scada protocols and work flows. Implementing of ISO27001 & ISO27019 standards.

Cyber Security Specialist
SIEM (Logsign) experience including management, rules creation, use case deployment, reporting, correlation and investigation. Consulting to clients about implementing sources in their corporations on SIEM. Updating, troubleshooting and assisting to write correlations & alarms

Information Technology Auditor
Kocaeli, Turkey
Auditing with COBITv4 & PCIDSS Standarts and banking regulations in Turkey. Performed internal network penetration tests (host discovery, port scanning and vulnerability analysis with using nmap, wireshark, kali linux and nessus) Performed mobile application test with using BurpSuite for banking application (iOS)
Fatih Kocalar's Contact Information
Phone
Find the Right Leads
Find Verified Contact Data
What LeadContact does well
Find verified emails, phone numbers, and decision-makers with 98% accuracy.
Find Leads
Find the right people by company, role, industry, location, and more.
925M+ professional profiles

Find Emails
Access verified email addresses for your target contacts.
657M+ emails

Find Phone Numbers
Get cross-validated phone data from multiple top sources.
239M+ phone numbers

More Accurate. Lower Cost.
Find contact data in 1 tool with 98% accuracy
LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.
Great conversations start with the right contact.
It’s time to find yours.




