JOB DETAILS

Senior Consultant — Governance, Risk & Compliance (GRC)

CompanyLostar
LocationIstanbul
Work ModeOn Site
PostedJuly 30, 2026
About The Company
Company Profile Lostar Inc., founded in 1998, based in Istanbul/Turkey, provides competitive edge in an uncertain world with Business and Technology Risk Consulting. Lostar helps companies secure their business assets and digital infrastructure by providing a wide range of customized consulting, auditing and training services. Core activities include assessing risks, designing security systems, developing and implementing strategies and undertaking reviews. The company combines the ability to identify the key issues and formulate strategies in the most complex and dynamic environments, with the know-how to provide practical support at the coalface. This can include advice and assistance in selecting the most appropriate solution, undertaking a tendering process and getting the best from your manned service. Of course, we also know that nothing stands still, and even where security procedures are sound, weak links may start to emerge. We believe firmly that checks and balances should be in place to get things back on track before serious problems can emerge. For that reason, an important part of our work has involved testing the system, to see if equipment and people are still operating, as they should.
About the Role

Company Description

Founded in 1998, Lostar is one of Turkey's longest-established independent information security firms, with more than 1,500 projects delivered over more than 25 years.

Our services span offensive security — internet and intranet penetration testing — alongside governance and compliance work against internationally recognised frameworks (ISO 27001, ISO 22301, ISO 20000, ISO 9001, COBIT, ITIL), data protection programmes under KVKK and GDPR, and employee security awareness programmes built on our own methodology.

Our consultants are trained and experienced, and they design solutions that balance technical rigour with commercial reality: the optimal answer for the client, not the most expensive one. Rooted in Turkey, we work from three offices — Istanbul, London and Sakarya.

We work with the best to create the best service and value for our clients.

Follow us

  • LinkedIn: Lostar
  • Instagram: LostarInfoSec
  • X (TR): Lostar · X (EN): Lostar_EN
  • YouTube: LostarTV
  • Facebook: Lostar · Facebook (Jobs): LostarKariyer

Websites: https://lostar.com (EN) · https://lostar.com.tr (TR)

 

Job Description

We are looking for a Senior Consultant to join Lostar's Governance, Risk and Compliance practice.

You will advise enterprise clients across banking, capital markets, insurance, energy, telecommunications and manufacturing on information security management, IT service management, business continuity and data protection. This is a client-facing senior role: you will own delivery on your engagements rather than support someone else's.

How the week works. Our hybrid model is built around client work rather than desk time: two days per week at client sites (primarily in Istanbul), three days remote, and one day per month together at our Istanbul office for team, methodology and practice development. Assignments outside Istanbul come up periodically, along with occasional travel to our London office, so you should be comfortable travelling when an engagement calls for it.

What you will do

  • Lead GRC engagements end to end: scoping, gap analysis, control design, documentation, implementation support and internal audit.
  • Advise clients against international standards and frameworks (ISO 27001, ISO 22301, ISO 20000, ISO 9001, COBIT, ITIL) and applicable regulation — KVKK, GDPR, and sector-specific requirements from Turkish regulators including BDDK, SPK, TCMB, EPDK and SEDDK.
  • Run two to four parallel engagements: track status, manage scope and timelines, and keep both the client and internal teams continuously informed.
  • Prepare and present findings, risk assessments and remediation roadmaps to client management, up to and including board level.
  • Support clients through certification audits and regulatory examinations.
  • Mentor junior consultants and contribute to our internal methodology, templates and quality standards.
  • Contribute to business development: scoping calls, proposal and statement-of-work input, and research into emerging regulatory areas (NIS2, DORA, the EU Cyber Resilience Act, the EU AI Act) before they become client requirements.
  • Work with our AI-assisted delivery tooling and help shape it — we build our own platforms for project delivery, evidence management and reporting.

Qualifications

Required

  • Bachelor's degree in Computer Engineering, Software Engineering, Electrical & Electronics Engineering, Industrial Engineering, Information Systems or Computer Science — or equivalent professional experience in a related field.
  • Minimum 6 years' experience in IT governance, information security management, IT audit or GRC consultancy.
  • Demonstrable hands-on delivery on projects involving internationally recognised standards, frameworks and applicable regulation (ISO 27001, ISO 22301, ISO 20000, ISO 9001, COBIT, ITIL, KVKK, GDPR or equivalent).
  • Solid command of information technology and information security concepts and practices.
  • Proven project management experience, including managing multiple concurrent engagements.
  • Ability to produce audit-quality documentation and present to senior stakeholders.
  • Professional-level written and spoken Turkish and English (C1 or above in both).
  • Full-time availability and willingness to travel as engagements require.

Preferred

  • Master's degree in information technology, information security or management.
  • At least one relevant certification: ISO 27001 / ISO 22301 / ISO 20000 / ISO 9001 Lead Auditor or Internal Auditor, CISA, CRISC, CISM or CISSP.
  • Experience in regulated sectors — financial services, insurance, energy or telecommunications.
  • Familiarity with emerging EU regulation (NIS2, DORA, CRA, AI Act) and its implications for Turkish organisations.

How you work

  • Curious, and genuinely following developments in technology, regulation and practice.
  • Effective, efficient and outcome-oriented.
  • A strong communicator, comfortable taking initiative, and a real team player.

Additional Information

What we offer

  • Breadth of exposure. Across our client portfolio you will see more regulated environments in a year than most in-house roles offer in five — and you will see them from the inside, at decision level.
  • Work that runs ahead of the market. We build methodology for NIS2, DORA, CRA and the EU AI Act before they land as client obligations, which means you advise rather than catch up.
  • Certifications and training on us. We cover the full cost of role-relevant certifications and training — ISO lead auditor tracks, CISA, CRISC, CISM — and give you the study time to do them properly.
  • Tooling that respects your time. We build our own delivery platform: AI-assisted drafting, structured evidence management, and four-eye quality control on every deliverable. Your hours go into judgement, not formatting.
  • A clear path. Senior Consultant to Principal Consultant or Practice Lead, based on delivery quality, client trust and the people you develop — not on tenure.
  • Professional visibility. Our consultants publish, speak at conferences and teach at university level. If you want a public profile in this field, we will actively support it.
  • Institutional depth. More than 25 years, three offices, 1,500+ projects. There are senior people to escalate to and a proven methodology to build on rather than reinventing every engagement.
  • Hybrid working as described above, private health insurance, and meal and transport support.

    One more thing, for those who read to the end.

    In your cover letter, or the message field of the application form, write "Annex A" and add one sentence naming an ISO 27001 Annex A control that in your experience most organisations implement badly.

Key Skills
Governance, Risk & ComplianceISO 27001ISO 22301ISO 20000ISO 9001COBITITILKVKKGDPRInformation security managementIT auditProject managementRisk assessmentStakeholder managementBusiness continuityData protection
Categories
ConsultingSecurity & SafetyTechnologyManagement & LeadershipFinance & Accounting
Benefits
Private health insuranceMeal supportTransport supportCertification and training coverageStudy time for certifications
Job Information
📋Core Responsibilities
Lead end-to-end GRC engagements including scoping, gap analysis, control design, and implementation support for enterprise clients. Advise management on regulatory compliance and international standards while mentoring junior consultants and contributing to internal methodology.
📋Job Type
full time
📊Experience Level
5-10
💼Company Size
37
📊Visa Sponsorship
No
💼Language
English
🏢Working Hours
40 hours
Apply Now →

You'll be redirected to
the company's application page