8000
Skip to content
View mfkocalar's full-sized avatar
  • Berlin
  • 16:14 (UTC +02:00)

Block or report mfkocalar

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
mfkocalar/README.md

πŸ›‘οΈ About Me

πŸ‘‹ Hi, I'm Mehmet Fatih Kocalar β€” a cybersecurity professional with 12+ years of experience doing one thing: making organizations harder to attack and faster to recover when they are.

🎯 My work sits at the intersection of technical depth and strategic clarity. I've led SOC operations, built vulnerability management programs from scratch, designed cloud security architectures across hybrid and cloud-native environments, and guided organizations through ISO 27001, NIST, and PCI-DSS compliance β€” not as checkbox exercises, but as genuine risk reduction.

🏭 The sectors I've worked across β€” fintech, energy, telecommunications, technology, critical infrastructure, health tech, and medical education β€” share a common thread: the cost of getting security wrong is existential. That reality keeps my work grounded.

🀝 Open to conversations about security strategy, team building, and complex risk challenges.


🌐 Socials

LinkedIn GitHub


πŸ” What I Do

Area Focus
πŸ” Threat Detection & IR Leading SOC teams through high-pressure incidents and building playbooks that reduce response time and noise
☁️ Cloud & Enterprise Security Designing security frameworks for hybrid, cloud-native, and legacy environments
πŸ“‹ Compliance & Risk Alignment Translating ISO 27001, SOC2, NIST CSF, and PCI-DSS into practical controls that reduce actual risk
πŸ›‘οΈ Vulnerability Management Building and maturing programs that prioritize what matters, not just what's loud
🀝 Cross-Functional Leadership Bridging the gap between technical teams and business stakeholders so security decisions stick

πŸ… Certifications

CEH ISO 27001 LA


🧰 Tech Stack

πŸ” SIEM & SOC Platforms

Splunk ArcSight QRadar

πŸ›‘οΈ Network Security

FortiGate PaloAlto CheckPoint NAC DLP Mail Gateway Sandbox

πŸ”Ž Vulnerability Management

Nessus Qualys ORCA Security

πŸ”‘ Identity & Access

CyberArk OKTA

☁️ Cloud Platforms

AWS Azure

πŸ“‹ Compliance & Frameworks

MITRE ATT&CK Cyber Kill Chain NIST ISO 27001 ISO 27019 PCI-DSS COBIT SOX CIS Benchmarks OWASP

πŸ› οΈ Productivity & Operations

G-Suite JIRA KnowBe4 Endpoint Protection


πŸ“Š GitHub Stats



πŸ’° You can help me by Donating

PayPal

Popular repositories Loading

  1. OWASP-Security-Skills OWASP-Security-Skills Public

    Python 1 2

  2. log4j-affected-db log4j-affected-db Public

    Forked from cisagov/log4j-affected-db

    A community sourced list of log4j-affected software

  3. log4j-scanner log4j-scanner Public

    Forked from cisagov/log4j-scanner

    log4j-scanner is a project derived from other members of the open-source community by CISA to help organizations identify potentially vulnerable web services affected by the log4j vulnerabilities.

    Java

  4. iris-web iris-web Public

    Forked from dfir-iris/iris-web

    Incident Response collaborative platform

    JavaScript

  5. API-Security-Checklist API-Security-Checklist Public

    Forked from shieldfy/API-Security-Checklist

    Checklist of the most important security countermeasures when designing, testing, and releasing your API

  6. Awesome-Cloud-Security Awesome-Cloud-Security Public

    Forked from NextSecurity/Awesome-Cloud-Security

    Awesome curate list of cyber security penetration testing tools for Cloud Security mainly AWS/Azure/Google

0