Senior Consultant — Governance, Risk & Compliance (GRC)

Company Description
Founded in 1998, Lostar is one of Turkey's longest-established independent information security firms, with more than 1,500 projects delivered over more than 25 years.
Our services span offensive security — internet and intranet penetration testing — alongside governance and compliance work against internationally recognised frameworks (ISO 27001, ISO 22301, ISO 20000, ISO 9001, COBIT, ITIL), data protection programmes under KVKK and GDPR, and employee security awareness programmes built on our own methodology.
Our consultants are trained and experienced, and they design solutions that balance technical rigour with commercial reality: the optimal answer for the client, not the most expensive one. Rooted in Turkey, we work from three offices — Istanbul, London and Sakarya.
We work with the best to create the best service and value for our clients.
Follow us
- LinkedIn: Lostar
- Instagram: LostarInfoSec
- X (TR): Lostar · X (EN): Lostar_EN
- YouTube: LostarTV
- Facebook: Lostar · Facebook (Jobs): LostarKariyer
Websites: https://lostar.com (EN) · https://lostar.com.tr (TR)
Job Description
We are looking for a Senior Consultant to join Lostar's Governance, Risk and Compliance practice.
You will advise enterprise clients across banking, capital markets, insurance, energy, telecommunications and manufacturing on information security management, IT service management, business continuity and data protection. This is a client-facing senior role: you will own delivery on your engagements rather than support someone else's.
How the week works. Our hybrid model is built around client work rather than desk time: two days per week at client sites (primarily in Istanbul), three days remote, and one day per month together at our Istanbul office for team, methodology and practice development. Assignments outside Istanbul come up periodically, along with occasional travel to our London office, so you should be comfortable travelling when an engagement calls for it.
What you will do
- Lead GRC engagements end to end: scoping, gap analysis, control design, documentation, implementation support and internal audit.
- Advise clients against international standards and frameworks (ISO 27001, ISO 22301, ISO 20000, ISO 9001, COBIT, ITIL) and applicable regulation — KVKK, GDPR, and sector-specific requirements from Turkish regulators including BDDK, SPK, TCMB, EPDK and SEDDK.
- Run two to four parallel engagements: track status, manage scope and timelines, and keep both the client and internal teams continuously informed.
- Prepare and present findings, risk assessments and remediation roadmaps to client management, up to and including board level.
- Support clients through certification audits and regulatory examinations.
- Mentor junior consultants and contribute to our internal methodology, templates and quality standards.
- Contribute to business development: scoping calls, proposal and statement-of-work input, and research into emerging regulatory areas (NIS2, DORA, the EU Cyber Resilience Act, the EU AI Act) before they become client requirements.
- Work with our AI-assisted delivery tooling and help shape it — we build our own platforms for project delivery, evidence management and reporting.
Qualifications
Required
- Bachelor's degree in Computer Engineering, Software Engineering, Electrical & Electronics Engineering, Industrial Engineering, Information Systems or Computer Science — or equivalent professional experience in a related field.
- Minimum 6 years' experience in IT governance, information security management, IT audit or GRC consultancy.
- Demonstrable hands-on delivery on projects involving internationally recognised standards, frameworks and applicable regulation (ISO 27001, ISO 22301, ISO 20000, ISO 9001, COBIT, ITIL, KVKK, GDPR or equivalent).
- Solid command of information technology and information security concepts and practices.
- Proven project management experience, including managing multiple concurrent engagements.
- Ability to produce audit-quality documentation and present to senior stakeholders.
- Professional-level written and spoken Turkish and English (C1 or above in both).
- Full-time availability and willingness to travel as engagements require.
Preferred
- Master's degree in information technology, information security or management.
- At least one relevant certification: ISO 27001 / ISO 22301 / ISO 20000 / ISO 9001 Lead Auditor or Internal Auditor, CISA, CRISC, CISM or CISSP.
- Experience in regulated sectors — financial services, insurance, energy or telecommunications.
- Familiarity with emerging EU regulation (NIS2, DORA, CRA, AI Act) and its implications for Turkish organisations.
How you work
- Curious, and genuinely following developments in technology, regulation and practice.
- Effective, efficient and outcome-oriented.
- A strong communicator, comfortable taking initiative, and a real team player.
Additional Information
What we offer
- Breadth of exposure. Across our client portfolio you will see more regulated environments in a year than most in-house roles offer in five — and you will see them from the inside, at decision level.
- Work that runs ahead of the market. We build methodology for NIS2, DORA, CRA and the EU AI Act before they land as client obligations, which means you advise rather than catch up.
- Certifications and training on us. We cover the full cost of role-relevant certifications and training — ISO lead auditor tracks, CISA, CRISC, CISM — and give you the study time to do them properly.
- Tooling that respects your time. We build our own delivery platform: AI-assisted drafting, structured evidence management, and four-eye quality control on every deliverable. Your hours go into judgement, not formatting.
- A clear path. Senior Consultant to Principal Consultant or Practice Lead, based on delivery quality, client trust and the people you develop — not on tenure.
- Professional visibility. Our consultants publish, speak at conferences and teach at university level. If you want a public profile in this field, we will actively support it.
- Institutional depth. More than 25 years, three offices, 1,500+ projects. There are senior people to escalate to and a proven methodology to build on rather than reinventing every engagement.
- Hybrid working as described above, private health insurance, and meal and transport support.
One more thing, for those who read to the end.
In your cover letter, or the message field of the application form, write "Annex A" and add one sentence naming an ISO 27001 Annex A control that in your experience most organisations implement badly.
You'll be redirected to
the company's application page