Skip to content
View ersinnerol's full-sized avatar

Block or report ersinnerol

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
ersinnerol/README.md

Hi, I'm Ersin 👋

Cybersecurity Professional & Entrepreneur · 15+ Years in Information Security

Focus Location Experience


🧭 About Me

I'm a cybersecurity professional and entrepreneur based in Istanbul, Türkiye, with 15+ years of hands-on experience across information security, governance, risk, and compliance.

My work sits at the intersection of technical security and business risk management — designing security programs, running third-party risk assessments, aligning organizations with international standards, and building tools that make security operations more efficient.

I believe great security programs are measurable, framework-aligned, and tightly coupled with business outcomes.


🎯 Areas of Expertise

  • Governance, Risk & Compliance (GRC) — program design, policy, audit readiness
  • Third-Party / Supply-Chain Risk Management (TPRM) — vendor security assessments, ongoing monitoring
  • ISO/IEC 27001 — implementation, internal audit, lead auditor engagements
  • T.C. Dijital Dönüşüm Ofisi — Bilgi ve İletişim Güvenliği Rehberi (D1–D2) — lead auditor
  • Cloud Security — AWS security architecture and controls
  • Security Management — security strategy, risk treatment, KPI-driven oversight
  • Offensive Security Awareness — ethical hacking mindset applied to defensive design
  • Regulatory Alignment — KVKK, GDPR, NIS2, DORA readiness

🏅 Certifications

Certification Issuing Body
CISM — Certified Information Security Manager ISACA
CEH — Certified Ethical Hacker EC-Council
ISO/IEC 27001 Lead Auditor Accredited Certification Body
T.C. DDO — Bilgi ve İletişim Güvenliği Rehberi D1–D2 Lead Auditor T.C. Cumhurbaşkanlığı Dijital Dönüşüm Ofisi
AWS Certified Security Amazon Web Services

🧩 Frameworks & Standards

ISO 27001 ISO 27701 ISO 27036 NIST CSF 2.0 NIST 800-161 T.C. DDO BIGR KVKK GDPR NIS2 DORA SIG CAIQ

🛠️ Technology

AWS Security Linux Windows Server Electron JavaScript Node.js HTML5


🚀 Featured Project

An Electron-based desktop application that automates vendor and supplier security assessments and generates professional DOCX risk reports aligned with ISO 27001, NIST SP 800-161, SIG, and CAIQ.

Built for GRC teams who need consistent, audit-ready vendor evaluations without the manual overhead.

TPRM Repo


📊 GitHub Stats

Ersin's GitHub stats

Top Languages


💼 What I'm Working On

  • Building practical, framework-aligned tools for GRC and TPRM practitioners
  • Helping organizations achieve ISO 27001 and T.C. DDO D1–D2 compliance
  • Advising on third-party and supply-chain security programs
  • Sharing knowledge from 15+ years in the field

📫 Get in Touch

If you're working on cybersecurity, GRC, TPRM, or compliance initiatives and think we could collaborate, I'd love to hear from you.

GitHub


"Security is not a product, but a process." — Bruce Schneier

Pinned Loading

  1. tprm tprm Public

    Electron-based Third-Party Risk Management (TPRM) tool that generates automated DOCX risk assessment reports for vendor/supplier security evaluations.

    HTML

  2. iso27001-checklist iso27001-checklist Public

    Practical ISO/IEC 27001:2022 Annex A control checklist in Markdown — 93 controls across Organizational, People, Physical, and Technological themes. Ready for implementation tracking, internal audit…

    1