Information Technology Auditor
As the leading force of Türkiye’s National Technology Initiative, Baykar develops indigenous and national high-technology Unmanned Aerial Vehicle (UAV) systems and creates global impact with proven platforms. With our end-to-end engineering approach from R&D to production, we continue to deliver projects that push technological boundaries.
OUR DEPARTMENT:
Network, Information Technologies, and Information Security Systems Department is responsible for the end-to-end design, development, management, and security of the organization’s digital infrastructure. Under this department; software development, system and infrastructure management, network technologies, information security, artificial intelligence and data analytics, DevOps processes, ERP systems, and software testing activities are carried out with an integrated approach.
In line with the principles of high availability, scalability, and security, the department aims to contribute to the digital transformation of corporate processes by developing modern software architectures, cloud and on-premise infrastructures, automation solutions, and advanced analytics applications.
POSITION OBJECTIVE:
In line with the organization’s strategic objectives, the purpose of this role is to design end-to-end network infrastructures for Unmanned Aerial Vehicle (UAV) and critical communication systems, develop modern and high-performance software solutions to manage these infrastructures, and advance digital transformation initiatives through network automation. This position serves as a bridge between the physical network layer and software architecture, ensuring secure, reliable, and uninterrupted operational capabilities.
WHAT AWAITS YOU:
- Plan, execute, and report on Information Technology (IT) audits.
- Conduct IT risk assessments and contribute to maintaining the IT risk inventory.
- Support the monitoring and enhancement of information security, IT governance, and compliance processes.
- Evaluate the effectiveness of internal control mechanisms and prepare recommendations for improvement.
- Perform process analyses in line with frameworks such as COBIT, ISO/IEC 27001, NIST, ITIL, and similar standards.
- Assess and monitor compliance with regulations, organizational policies, and international standards.
- Track and report audit findings, identified risks, and remediation actions.
- Support internal and external audits as well as regulatory inspections.
- Participate in on-site audits at suppliers, subcontractors, and company locations when required, conduct on-site assessments, and report findings.
- Evaluate controls related to information security, cybersecurity, and business continuity processes.
- Collaborate closely with business units to improve processes and enhance risk awareness.
GENERAL QUALIFICATIONS:
- Bachelor's degree in Computer Engineering, Software Engineering, Management Information Systems, Electrical and Electronics Engineering, or a related field.
- Minimum of 2 years of experience in at least one of the following areas: IT audit, information security audit, IT risk management, Governance, Risk and Compliance (GRC), or internal audit.
- Knowledge of one or more of the following domains: Identity and Access Management (IAM), application security, cloud technologies and cloud security, network security, vulnerability management and incident response, system hardening, asset management, and Secure Software Development Lifecycle (Secure SDLC).
- At least intermediate-level knowledge and experience in information security audit methodologies and processes, including audit planning, control testing, and audit reporting.
- Understanding of IT governance, risk management, and internal control processes.
- Knowledge of the ISO/IEC 27001 Information Security Management System (ISMS) standard and its core requirements.
- Familiarity with information security principles, cybersecurity controls, and relevant industry standards.
- Strong analytical thinking, problem-solving, and reporting skills.
- Excellent written and verbal communication skills, with the ability to collaborate effectively across cross-functional teams.
- Eager to learn, committed to continuous improvement, and results-oriented.
ADDITIONAL QUALIFICATIONS (PREFERRED):
- Experience in IT audit, IT risk management, GRC, or information security within an international audit or consulting firm is preferred.
- Knowledge of regulations issued by the Turkish Personal Data Protection Authority (KVKK), the Banking Regulation and Supervision Agency (BDDK), the Financial Crimes Investigation Board (MASAK), and other relevant regulatory authorities.
- Experience in IT risk management, control testing, compliance assessments, and the development of policies and procedures.
- Professional certifications such as CISA, CRISC, CISM, CGEIT, ISO/IEC 27001 Lead Auditor (LA), ISO 31000, COBIT, ITIL, or equivalent are preferred.