Topalan

Topalan

Cyber Security Architect & Senior Security Engineer | Threat Detect | Exploit Dev | Malware Analyst | Cloud & SOC Sec | Zero Trust | CISSP | AWS | DevSecOps | AI-Driven Security | NIST | Adversarial ML | LLM Sec @ Enerjisa

About

Advanced cybersecurity architect with 20+ years of expertise in offensive and defensive security. I specialize in malware analysis, exploit development, and securing large-scale enterprise and cloud environments. My approach blends reverse engineering, red team operations, and cloud-native security to deliver preemptive defense strategies. Skilled in static/dynamic malware analysis using Ghidra, FlareVM, IDA Pro, x64dbg, and custom-built Python/C++ tools. I develop proof-of-concept (PoC) exploits (BOF, ROP, Shellcode) and conduct red team exercises that simulate nation-state adversaries. I’ve led incident response and threat hunting teams across critical infrastructure, applying threat intelligence (OSINT, CTI), memory/network forensics, and SIEM correlation rules to detect and contain advanced threats. Experienced in integrating malware sandboxing and behavior-based detection systems into SOC/SOAR environments. Cloud security is a key focus—I secure workloads across AWS, Azure, and GCP, embedding security in DevOps pipelines using IaC (Terraform), Kubernetes, and container hardening. I apply Zero Trust, MITRE ATT&CK, and compliance frameworks (ISO 27001, NIST 800-53/82/115, GDPR, DORA, NIS2) Malware Analysis | Exploit Development | Reverse Engineering | Red Team Penetration Testing | Threat Hunting | Forensics | SOC/SIEM | SOAR Cloud Security (AWS, Azure, GCP) | Kubernetes | DevSecOps | IaC AI/LLM Security | Adversarial ML | Prompt Injection | Supply Chain Risks ICS/SCADA Security | IEC 62443 | OT Forensics | Microsegmentation Certifications (Malware & Offensive Security Focused): OSCP (Offensive Security Certified Professional) GREM (GIAC Reverse Engineering Malware) GPEN (GIAC Penetration Tester) CISSP, CISM, CRTO, CRISC, CEH, CHFI, GCFA, GXPN, CCSP, GCIH AWS Certified Security – Specialty | ISO 27001 LA | MITRE ATT&CK Defender I thrive where complex threats meet critical systems. I build secure, scalable, and intelligence-driven cyber programs that defend against today’s adversaries and anticipate tomorrow’s. • Implemented OT/ICS security frameworks (ISA/IEC 62443), reducing industrial cyber risks in national energy systems. • Designed multi-vendor firewall architecture (Palo Alto, Fortinet, Check Point) with 99.99% uptime. • Built hybrid security infrastructure (on-prem & cloud: Azure, AWS) with unified policy enforcement and compliance. • Improved SOC efficiency by 40% via automated MTTD/MTTR and advanced threat analytics. • Integrated SIEM/SOAR (Splunk, QRadar, Cortex XSOAR) for real-time detection and automated incident response.

Country

Türkiye

City

Ankara

Industry

Computer & Network Security

Skill

Siber Güvenlik, Bilgi Teknolojisi, Software Development | Python | Java | C++ | Bash, AWS Cloud Secrity | Google Cloud Security | Azure Cloud Security , IT Security Assessments, Security Engineering, Incident Response, Threat Modeling, Reverse Engineering | Exploit Development | Malware Analysis, Penetration Testing | Adversary Simulation | Burp Suite, Metasploit | Cobalt Strike | Ghidra | x64dbg, YARA Rules | Red Teaming | Fuzzing | Buffer Overflow Exploits, SIEM (Splunk, ELK, QRadar) | SOAR | Threat Hunting, MITRE ATT&CK Framework | Digital Forensics | Memory Forensics, IOC/IOA Analysis | Incident Response | Volatility, Autopsy | Packet Analysis | DPI | Log Parsing | Regex, DevSecOps | CI/CD Security | CSPM | CWPP, Kubernetes Security | Docker | Falco | Aqua Security, IAM | SSO | MFA | OAuth 2.0 | SAML | OIDC, Python for Security Automation

Experience

Enerjisa

Senior Cyber Security Expert

Enerjisa

LinkedIn
2023-9 - Present · 3 yrs 1 mo

Ankara, Turkey

Enerjisa is one of Turkey's leading energy companies, specializing in electricity distribution and retail. The company is known for its strong focus on digital transformation and cybersecurity, managing both IT and OT/ICS infrastructures in compliance with international standards. • IT & OT/ICS Security: Aligned with IEC 62443 and NIST SP 800-82 • Zero Trust Architecture (ZTNA): Micro-segmentation, identity-based access, least privilege enforcement • Cloud Security: Secured Azure and AWS environments, compliant with ISO/IEC 27017, CIS Benchmarks • Container Security: Hardened Kubernetes, Docker, Kafka, Rancher platforms • SDN & Hybrid Infrastructure: Designed controls per ISO/IEC 27001 and 27002 • Penetration Testing & Vulnerability Assessments: Based on OWASP, NIST SP 800-115, ISO/IEC 27005 • Threat Intelligence & OSINT: Conducted GDPR-compliant investigations and forensic support • Advanced Security Platforms: Managed NGFW, EDR/XDR, SIEM (Splunk), and SOAR systems & Log Analysis • Incident Response: Optimized for automated detection and rapid mitigation • Cross-Functional Collaboration: Ensured compliance with NIS2 Directive and enterprise-wide risk policies Key Achievements : • I implemented OT/ICS security frameworks aligned with ISA/IEC 62443 standards, significantly reducing industrial cyber risks across national energy infrastructure. • I designed and deployed a multi-vendor firewall architecture (Palo Alto, Fortinet, CP), achieving 99.99% uptime in mission-critical systems. • I built a resilient hybrid security architecture integrating on-prem systems with Azure and AWS, ensuring unified policy enforcement, real-time monitoring, and full regulatory compliance. • I restructured Security Operations Center (SOC) processes and leveraged automation to reduce MTTD and MTTR by over 40%. • I integrated SIEM and SOAR platforms (Splunk, QRadar, Cortex XSOAR), streamlining incident response, enabling real-time threat correlation, and automating remediation steps.

ARD Grup Bilişim Teknolojileri

Senior Application Security Architect

ARD Grup Bilişim Teknolojileri

LinkedIn
2021-4 - 2023-7 · 2 yrs 4 mos

Ankara, Türkiye

• Applied secure coding standards based on OWASP ASVS, NIST SP 800-53, and ISO 27001 to design and validate secure application architectures. • Led end-to-end application security testing using SAST, DAST, IAST, and RASP to identify and remediate vulnerabilities across web and cloud-native environments. • Threat detection, access control, and resilience within CI/CD pipelines. • Collaborated with development teams to integrate security gates and automated checks via Azure DevOps, Terraform, and Docker, enabling streamlined DevSecOps workflows and continuous compliance. • Designed secure network and cybersecurity architectures for sectors including blockchain, gaming, healthtech, IoT, and information security. • Partnered with cloud and DevOps teams to deliver scalable, resilient, and secure-by-design solutions aligned with business needs. • Integrated DevSecOps practices into SDLC by leveraging GitLab CI and GitHub Actions, following ISO 27034 and NIST SSDF frameworks. • Conducted comprehensive application security testing on APIs, microservices, and CI/CD pipelines, ensuring compliance with OWASP Top 10 and ASVS requirements. • Designed and deployed Zero Trust architectures for cloud-native and hybrid infrastructures, achieving compliance with ISO 27017, GDPR, NIS2, and PCI-DSS regulations. Key Achievements: • Contributed to the successful implementation of Zero Trust Application Security models, significantly enhancing threat detection and reducing access risks within CI/CD pipelines. • Increased automation of security validation in DevSecOps workflows, resulting in faster, more reliable, and secure release cycles. • Played a key role in delivering compliant security architectures across regulated industries, ensuring strict adherence to international standards and regulations. • Accelerated vulnerability remediation processes by integrating continuous testing tools, improving the overall security posture of applications.

Destek A.Ş.

Cyber Security Team Lead

Destek A.Ş.

LinkedIn
2019 - 2021 · 2 yrs
Destek A.Ş.

Principal Cybersecurity Engineer

Destek A.Ş.

LinkedIn
2017 - 2019 · 2 yrs

• Architect and enforce Zero Trust security models to minimize attack surfaces and ensure continuous verification across all network zones. • Deploy and tune Security Information and Event Management (SIEM) and Security Orchestration, Automation and Response (SOAR) platforms to enhance threat detection and automate incident response workflows. • Oversee comprehensive vulnerability management programs, ensuring timely patching and remediation across diverse environments. • Lead proactive threat hunting initiatives leveraging threat intelligence and coordinate rapid incident response and digital forensic investigations. • Implement robust encryption protocols and multi-factor authentication to protect data confidentiality and integrity. • Ensure compliance with global security frameworks such as NIST, ISO 27001, and GDPR. • Conduct risk assessments and design resilient business continuity and disaster recovery plans. Key Achievements: • Contributed over 30% improvement in network security posture by architecting and enforcing Zero Trust security models that minimized attack surfaces. • Successfully led the deployment and fine-tuning of SIEM and SOAR platforms, increasing threat detection efficiency and automating incident response processes by approximately 40%. • Played a key role in accelerating vulnerability management, reducing patching and remediation timeframes by 35% across diverse environments. • Led proactive threat hunting and digital forensic investigations, contributing to a 25% decrease in potential breach incidents. • Implemented advanced encryption and multi-factor authentication solutions, improving data confidentiality and integrity by more than 30%. • Ensured 100% compliance with NIST, ISO 27001, and GDPR standards through risk assessments and security framework alignment. • Promoted security awareness initiatives that increased employee participation in training programs by 50%, fostering a stronger organizational security culture.

Vision Solutions

Security Solutions Architect

Vision Solutions

LinkedIn
2014 - 2017 · 3 yrs

Ankara, Turkey

As the lead architect for advanced cybersecurity software solutions specializing in Network Access Control (NAC) and Security Information and Event Management (SIEM), I design scalable, resilient architectures that enable zero-trust network access and real-time threat intelligence. My work integrates cutting-edge engineering principles with deep domain expertise to build intelligent systems that provide comprehensive visibility, automated response capabilities, and adaptive security policies. These solutions empower organizations worldwide to proactively monitor, detect, and mitigate evolving cyber threats within complex and dynamic digital infrastructures. As the lead architect and core member of the development team for advanced cybersecurity software solutions specializing in Network Access Control (NAC) and Security Information and Event Management (SIEM), I designed scalable and resilient architectures that enable zero-trust network access and real-time threat intelligence. I contributed directly to the development of security products, integrating cutting-edge engineering principles with deep domain expertise to build intelligent systems offering comprehensive visibility, automated response capabilities, and adaptive security policies. These solutions empower organizations worldwide to proactively monitor, detect, and mitigate evolving cyber threats within complex and dynamic digital infrastructures.

Barikat Grup

Senior Network Security Engineer

Barikat Grup

LinkedIn
2011 - 2014 · 3 yrs

Ankara, Turkey

As a Network Security Engineer, I design, implement, and manage comprehensive network security infrastructures leveraging leading technologies such as Fortinet, Palo Alto Networks, Check Point, alongside advanced Network Access Control (NAC) and Security Information and Event Management (SIEM) systems. I enforce zero-trust architectures using NAC solutions like Cisco ISE and Aruba ClearPass, while integrating SIEM platforms such as Splunk, QRadar, and LogRhythm to provide continuous threat monitoring, log aggregation, and automated incident response. Skilled in configuring and tuning next-generation firewalls (NGFWs) from industry leaders, I apply granular access controls, intrusion prevention, and deep packet inspection to protect enterprise networks. By collaborating closely with cross-functional teams, I ensure network segmentation, policy enforcement, and compliance with global standards including ISO 27001, NIST, PCI-DSS, and GDPR, maintaining a resilient security posture against evolving cyber threats.

Soitron Group

Network Security Engineer

Soitron Group

LinkedIn
2006 - 2011 · 5 yrs

Ankara, Türkiye

As a Network Security Engineer at Soitron Group in Ankara, Turkey, I specialized in implementing robust network security solutions by configuring Cisco TACACS+ with ACS Servers and Cisco Identity Services Engine (ISE) to enforce granular access control and authentication policies. I collaborated with cross-functional teams to deploy advanced deep packet inspection (DPI) technologies such as Procera Sandvine, enhancing network visibility and threat detection capabilities. My role included optimizing firewall policies and managing secure routing protocols to ensure resilient and compliant network infrastructure aligned with enterprise security standards.

Multiple Companies

Junior Security Engineer

Multiple Companies

LinkedIn
2000-1 - 2005-12 · 6 yrs

Ankara, Türkiye

• Implemented IT security measures across multiple local IT companies to protect systems and data. • Designed and integrated datacenter infrastructure architecture for improved efficiency. • Collaborated with teams to enhance systems integration and streamline operations.

Education

Netkent Akdeniz Araştırma ve Bilim Üniversitesi

Netkent Akdeniz Araştırma ve Bilim Üniversitesi

LinkedIn

Computer and Information Systems Engineering

Computer Science High Honour

Anadolu University

Anadolu University

LinkedIn

Management Information Systems

Anadolu University

Anadolu University

LinkedIn

Business Management

Dokuz Eylul University

Dokuz Eylul University

LinkedIn

Topalan Contact Information

Email

******@***.com

Phone

(**) *** ****

Find the Right Leads
Find Verified Contact Data

Try with: Jensen Huang @ nvidia.com Click to autofill
LeadContact awards, five-star ratings, and GDPR compliance badges

What LeadContact does well

Find verified emails, phone numbers, and decision-makers with 98% accuracy.

Find Leads

Find Leads

Find the right people by company, role, industry, location, and more.

925M+ professional profiles

Find Leads
Find Emails

Find Emails

Access verified email addresses for your target contacts.

657M+ emails

Find Emails
Find Phone Numbers

Find Phone Numbers

Get cross-validated phone data from multiple top sources.

239M+ phone numbers

Find Phone Numbers

More Accurate. Lower Cost.

Find contact data in 1 tool with 98% accuracy

LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.

LeadContact Logo
Competitor Tools

All these = $289 per month

Great conversations start with the right contact.

It’s time to find yours.