07/30/2026 updated

**** ******** ****
verified
Premium member
100 % available

Senior Cybersecurity Consultant (CISA | ISO 27001 / 27701 / 22301 / 42001 Lead Auditor | NIS2 | DORA

Talinn, Estonia
Worldwide
Elektrotechnik, B.Eng, TU
Talinn, Estonia
Worldwide
Elektrotechnik, B.Eng, TU

Profile attachments

Zeugnis
Zeugnis
Cisa
SGS_AUDITLOG_20210628_0001.pdf
CFE Audit Log - Burak Güçer - 15102025.pdf
BG-INFOGRAFIC.jpg
Burak_Gucer_ISO22301-2019.pdf
Burak Gücer - 42001 LAC.pdf
Burak Güçer - 27701 LAC Geçiş.pdf
Burak_Gucer_ISO27001-2022 (1).pdf
9001-2015LA.pdf
Burak_Gucer_EN_2026-07.pdf

About me

Ich berate Organisationen zu ISO 27001, NIS2, DORA, Cyber Resilience Act, EASA Part-IS, TISAX, Datenschutz & KI-Governance – mit Fokus auf pragmatische Umsetzung und Audits. Gerne vernetze ich mich zum Austausch und für mögliche Projekte.

NIS 2DORAComplianceComputer SecurityConsultingGovernance Risk Management and ComplianceOperationalizationCertified Information Systems AuditorTisaxSecurity AuditsIT Security StandardsSecurity ConsultancyRisk Management

Fachliche Kompetenzen & Expertise
Als europaweit tätiger Berater für Cybersecurity, Compliance und KI-Governance bringe ich über zwei Jahrzehnte Erfahrung in der Entwicklung widerstandsfähiger, konformer und zukunftssicherer Managementsysteme mit. Ich verbinde technische Informationssicherheit mit strategischer Governance, um Organisationen ganzheitlich durch digitale und regulatorische Transformationen zu führen – einschließlich eines klaren, risikobasierten Ansatzes für den verantwortungsvollen KI-Einsatz über den gesamten Lebenszyklus.
Kernkompetenzen
Informationssicherheit & Datenschutz: Konzeption, Implementierung und Optimierung von ISMS (ISO 27001) sowie PIMS (ISO 27701) – u. a. in den Branchen Luftfahrt, Finanzen, Automobil und Technologie.
KI-Governance & Ethik: Operationalisierung der ISO 42001 zur Sicherstellung von Transparenz, Verantwortlichkeit und vertrauenswürdigem KI-Management – im Einklang mit dem EU AI Act und internationalen Standards.
Regulatorische Compliance: Umsetzung von NIS2, DORA, EASA Part-IS und TISAX mit Fokus auf rechtliche Konformität, operative Resilienz und Zertifizierungsfähigkeit.
Risikomanagement & Governance: Fundierte Erfahrung in Enterprise Risk Management, Business Continuity und Governance-Strukturen zur Stärkung strategischer Entscheidungen und organisationaler Resilienz.
Audit & Advisory: Zertifizierter Lead Auditor (ISO 27001, ISO 27701) und CISA – erfahren in internen, Lieferanten- und Zertifizierungsaudits sowie in vCISO-Beratung zur kontinuierlichen Verbesserung.
Strategische Umsetzung: Übersetzung komplexer regulatorischer Anforderungen in praxisnahe, wertschaffende Strategien, die Vertrauen, Compliance und Nachhaltigkeit nachhaltig stärken.
Beratungsansatz
Ergebnisorientiert, interkulturell und pragmatisch: Ich kombiniere europäische Regulatorik-Expertise mit globalen Best Practices und einem KI-first-Mindset, um Risiken frühzeitig zu adressieren, Kontrollen wirksam zu verankern und den Mehrwert messbar zu machen. So unterstütze ich Organisationen auf dem Weg zu nachweisbarer Verbesserung, erfolgreicher Zertifizierung und belastbarem digitalem Vertrauen.

Languages

GermanFluentEnglishFluentTurkishNative speaker

Project history

Contracted Lead Auditor

CFE Certification Ltd UK

Auditing, Taxes & Law

10-50 team member

Main business services include, but not limited to
* Strategic IT and Business Alignment (Consultancy & Workshops)
* Business Analysis & IT Architecture (Consultancy & Workshops)
* Building & Optimizing ICT Organizations (Consultancy & Workshops)
* Process optimization (Consultancy & Workshops)
* Information Security (Consultancy, Audit and Workshops)
My job and responsibilities cover
* Building and maintaining advisory relationship with C-level and senior executives
* Overall P/L responsibility for the operations
* Demand Generation & Business Development for the services and partner products
* Program Management

Contractor/Principal Auditor

SGS AS

Auditing, Taxes & Law

1000-5000 team member

Since I am self-employed I worked at SGS Turkey as a contractor and held the
position Principal Auditor.
Our business unit was called "Certification and Business Enhancement" which
means we certify our clients that they are compliant with standards and we
consult them to enhance their business processes and organization in means of
Digital Transformation.
Leading Audits and holding seminars for the clients to transfer know-how
related with Information Security Management, Cyber Security, Risk Management,
Quality Management, Process Optimization and Business Continuity.
Serve as primary troubleshooter for technical, personnel, and audit related
issues.
Created new business opportunities by understanding the customer needs during
events, audits and seminars.
Since Part-Time Working model has been changed, I have resigned my contractor
position.

Managing Partner

Consulting Associates International, LLC International
The objective of Consulting Associates International LLC is to become a high calibre team of
consultants and auditors serving companies in fields such as
* Program & Project Management
* Risk and Business Impact Analysis
* Business Analysis and Process Optimization
* Business Continuity Planning
* Information Security and/or Quality Management Systems
* PCI DSS, Implementing Cobit, ITIL, ValIT and Risk IT
This company transformed itself to Gucer Auditing & Consulting recently.
My job and responsibilities covered
* Building and maintaining advisory relationship with C-level and senior executives
* Overall P/L responsibility for the operations
* Demand Generation
* Business Development

Chief Information Security Officer

H.C. Starck Group

Industry & Mechanical Engineering

1000-5000 team member

H.C. Strack group consist of several different business units: Metal and ceramic powder, fabricated
products, electronic chemicals and engineering parts.
* Senior executive leading all group-wide Information Security relevant topics such as
confidentiality, integrity and availability of assets.
* Deploying worldwide necessary staff to be responsible for IS-security and to establish IS-security
regulations in coordination with the global IS Security Community, which is also to be in the lead
of CISO.
* Oversee the network of IT security professionals & vendors, who safeguard the company's assets,
intellectual property & computer systems.
* Identify protection goals and objectives consistent with corporate strategic plan.
* Maintain relationship with local, state & federal law enforcement and other related government
agencies.
* Oversee the investigation of security breaches, assist with disciplinary & legal matters
associated with such breaches as necessary.
* Prepare & Conduct awareness programme

CISO

AUDI AG

Automotive & Vehicle Manufacturing

>10.000 team member

The Audi Group with the two brands Audi and Lamborghini is one of the most successful car
manufacturers in the premium segment and belongs to Volkswagen Group.
* Strategic alignment of information security with business strategy to support organizational
objectives
* Risk management by executing appropriate measures to manage and mitigate risks and reduce
potential impacts on information resources to an acceptable level
* Resource management by utilizing information security knowledge and infrastructure efficiently and
effectively
* Computer Emergency Response Team Leader
* Performance measurement by measuring, monitoring and reporting information security governance
metrics to ensure that organizational objectives are achieved
* Annual risk assessment and Quarterly Audits
* Prepare & Conduct awareness programme

Information Security Officer

Turkcell AS
As of December 31, 2008, with its 37 million subscribers, Turkcell is not only the leading operator
in Turkey, but is also the third biggest GSM operator in Europe in terms of subscriber numbers.
* I have developed and maintained the guidelines, standards and policies regarding system and
information ownership; information and data classification.
* Promoted the security and uninterrupted operation of computer-based application systems
* My main responsibilities were deriving security strategy from business needs and communicating
corporate wide, achieving security awareness by conducting group wide trainings for the employees
and Information security management in conformity with BS7799 Standard.

Sr. Project Manager & Supervisor

Vis AS

Internet & IT

250-500 team member

Sales & project management responsibility especially for the security & network management products
and services.
* Established and managed the BU Consultancy by signing a partnership contract with Network
Associates Consultancy Group (McAfee).
* Managed projects such as Assessment and Improvement of IT Initiatives within Denizbank, Zorlu
Group, Telsim (Vodafone), Turkcell and Turk Telekom (AveA)

Cofounder & Shareholder

Simpleks AS

Other

10-50 team member

After having 5 years business experience I have founded together with my colleagues my own company
and became CEO. At the beginning me and my company were doing business in field of 3rd party support
& system integrator activities. After a short while I have initiated new business lines by
introducing new software & hardware. I have successfully established sales channels for CAD/CAE
tools like ESC Schematics and Racal-Redac. Besides we had direct sales to major accounts like Beko,
Teletas, etc. By adding products like Checkpoint, McAfee, etc. we have included the IT-Security
topics into our portfolio.
During the time period 1992 - 2000 I have been working together with Mr. Orhan Karadogan who was
representing Gartner in Turkey.

Senior System Engineer (Supervisor)

Baytur SA

Banking & Financial Services

250-500 team member

Baytur SA (Geneva) belongs to Cukurova Holding the 3rd biggest group in Turkey. I have been
supporting the internal clients in means of computer related problems.

Software Engineer (Team Leader)

Kavi Kablo AS

Industry & Mechanical Engineering

250-500 team member

KAVI is one of the biggest companies in Turkey producing cables and voltage regulators. In order to
optimize the inventory of the semi-products I have developed a customized ERP/CAM software to
support the manufacturing department.

Certificates

ISO42001:2023 Lead Auditor

CFECERT

2025

ISO 27701:2025 LEAD AUDITOR

CFE CERT

2025

ISO27001:2022 Lead Auditor

CFE Cert

2023

ISO22301 Lead Auditor

CFECERT

2022

CISA

ISACA

2009


Portfolio


Recommendations


Contact form

Log in to get in touch

You need to be logged in to use the contact form.

Sign upLog in