Founded in 2018, Marti is Türkiye’s leading mobility app, offering multiple transportation services to its riders. Marti operates a ride-hailing service that matches riders with car, motorcycle, and taxi drivers, and operates a large fleet of rental e-mopeds, e-bikes, and e-scooters. All of Marti’s offerings are serviced by proprietary software systems and IoT infrastructure.
Marti's vision is that everything on wheels will be electric and everything electric will be shareable. Since 2019, we have experienced significant growth and maintained robust unit economics year-round. Our goal is to expand our urban transportation services, introduce new environmentally sustainable and shared mobility options, and leverage our existing scale and customer base to offer technology-enabled services beyond transportation. By pursuing sustainable growth, we strive to positively impact the communities we serve and make a meaningful impact on the future of mobility.
Marti invites applications from dynamic, innovative and highly motivated candidates for the following position;
Key Responsibilities
Network and IT Infrastructure
- Own the company’s enterprise network, systems, and infrastructure architecture.
- Manage firewalls, switches, routers, VPNs, wireless networks, load balancers, servers, and connectivity infrastructure.
- Design and improve network segmentation, VLANs, routing, redundancy, secure remote access, and high-availability architectures.
- Manage Microsoft Active Directory, Group Policy, DNS, DHCP, authentication, authorization, and user lifecycle processes.
- Ensure the secure and reliable operation of Windows and Linux server environments.
- Manage on-premises, data-center, cloud, and hybrid infrastructure connectivity and controls.
- Monitor infrastructure availability, capacity, performance, and service continuity.
- Improve backup, restoration, disaster recovery, and business continuity capabilities.
- Lead root-cause analysis for major infrastructure incidents and ensure permanent corrective actions are implemented.
- Manage infrastructure inventory, licensing, lifecycle, technology vendors, and critical changes.
Cyber Security
- Define the company’s cyber security strategy, policies, standards, control framework, and roadmap.
- Lead the implementation, configuration, onboarding, integration, hardening, and operational management of EDR, SIEM, PAM, firewall, vulnerability-management, email-security, and data-protection solutions.
- Ensure that existing security tools are correctly configured, adequately covered, actively monitored, and capable of generating actionable outcomes.
- Manage EDR agent deployment, SIEM log-source onboarding, privileged-account onboarding, and security-control coverage.
- Develop SIEM use cases, correlation rules, dashboards, alerts, tuning processes, and escalation workflows.
- Establish and enforce hardening standards for Active Directory, endpoints, servers, network devices, and critical systems.
- Manage vulnerability scanning, penetration testing, remediation, risk acceptance, and validation processes.
- Design and improve IAM, MFA, RBAC, least-privilege, privileged-access, periodic access-review, and joiner-mover-leaver processes.
- Prepare and maintain incident-response plans, technical playbooks, escalation procedures, and communication protocols.
- Coordinate cyber security incident response, including containment, eradication, recovery, evidence preservation, and post-incident review.
- Manage third-party security assessments, security-awareness programs, and phishing simulations.
- Collaborate with Software Engineering, Platform, DevOps, Cloud, Product, and Data teams to embed security-by-design principles.
Governance, Risk, and Compliance
- Develop and maintain a technology-control environment appropriate for a company publicly listed in the United States.
- Support SOX IT General Controls, including access management, change management, IT operations, control testing, evidence collection, and remediation.
- Contribute to compliance with KVKK, ISO 27001, internal policies, contractual obligations, and applicable information-security requirements.
- Establish and maintain cyber security and technology risk registers.
- Coordinate internal audits, external audits, independent assessments, and remediation activities.
- Define and report cyber security and infrastructure KPIs and KRIs.
- Present security posture, material risks, incidents, remediation progress, and strategic priorities to the CTO and senior management.
Team Leadership
- Define the organizational structure and operating model for the Network and Cyber Security functions.
- Build, recruit, develop, and manage the team according to the company’s evolving needs.
- Establish clear ownership across network engineering, systems administration, security operations, identity security, and governance.
- Set team objectives, priorities, KPIs, working practices, and development plans.
- Provide technical leadership during critical infrastructure and security incidents.
- Manage relationships with SOC, MSSP, consulting, audit, and technology providers.
- Build sustainable processes that reduce dependency on individual team members.
Required Qualifications
- Bachelor’s degree in Computer Engineering, Computer Science, Electrical and Electronics Engineering, Information Systems, or a related field.
- At least 10 years of professional experience across network infrastructure, systems administration, and cyber security.
- At least 3–5 years of team leadership, technical leadership, or management experience.
- Strong and demonstrable experience in both Network/IT Infrastructure and Cyber Security.
Experience exclusively in network infrastructure or exclusively in cyber security will not be sufficient. Candidates must have managed both areas and demonstrated the ability to align infrastructure operations with cyber security strategy.
- Hands-on experience managing enterprise firewalls, switches, routers, VPNs, wireless networks, servers, and related infrastructure.
- Strong experience with Microsoft Active Directory, Group Policy, DNS, DHCP, identity management, and access-control processes.
- Practical experience implementing and operating EDR, SIEM, PAM, vulnerability-management, and related security solutions.
- Strong knowledge of network segmentation, system hardening, privileged-access management, vulnerability remediation, and incident response.
- Experience with security frameworks and standards such as NIST CSF, CIS Controls, CIS Benchmarks, and ISO 27001.
- Ability to translate technical risks into business impact, priorities, and actionable remediation plans.
- Advanced professional proficiency in written and spoken English.
- Ability to communicate effectively in English with international executives, auditors, board-level stakeholders, vendors, consultants, and global business partners.
- Ability to prepare and present policies, technical reports, risk assessments, audit evidence, incident communications, and management presentations in English.
Preferred Qualifications
- Experience working for a publicly listed, US-listed, highly regulated, or independently audited company.
- Experience with SOX ITGC, SEC-related control environments, internal controls, or corporate-governance requirements.
- Experience leading ISO 27001 implementation or certification programs.
- Experience in cloud security, container security, Kubernetes, DevSecOps, or application security.
- Experience in technology, mobility, fintech, e-commerce, marketplace, telecommunications, or another high-traffic digital business.
- Certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer or Lead Auditor, CCNP, Microsoft certifications, or equivalent credentials.
- Experience establishing or managing SOC and MSSP services.
- Experience working in a fast-growing scale-up environment.