I prepare checklists and guidelines tailored to customer requirements in accordance with the R155 and ISO 21434 standards. I am also conducting cyber security risk analyses for projects. In these risk analyses, I simulate threat scenarios in a lab environment and carry out attacks on relevant components (ECUs, EVSE, infotainment equipment, CAN communications). I am working on the following projects:
I played a significant role in establishing Aselsan's Cyber Security Department. Our primary objective was to ensure that all products manufactured by Aselsan were designed with a cybersecurity perspective, and to identify security vulnerabilities in the devices already produced. I actively participated in creating cybersecurity processes at Aselsan, preparing cybersecurity guidelines for military devices, and developing secure software development guides. I was responsible for defining requirements for projects, conducting software/hardware security tests, and performing penetration tests on systems after security testing. To raise cybersecurity awareness and emphasize the importance of the Zero Trust Model, I participated in various activities and meetings within the company. I collaborated with different teams on communication devices, cameras, tanks, and aircraft project.
I am well-versed in standards such as DO-356A, DO-326A, NIST 800-53, NIST 800-207, NIST 800-30, and NIST 800-37. I worked on the following projects:
I developed the authentication kernel module and the Human-Machine Interface (HMI) for IP encryption devices. I used the C programming language.
I set up a development environment with a CI/CD pipeline to automatically test the code loaded into the IP encryption device. I wrote extra scripts for the JDSU device (using Perl and Python languages). The CI/CD pipeline triggered the tester, allowing automated tests to be performed on the IP device and reports to be generated and delivered.
I completed an intensive internship period with a focus on programming and cybersecurity. During this time, I worked extensively on Active Directory. I also developed a subdomain finder tool called "SeDeF" Additionally, I wrote scripts for Metasploit using Ruby.
I found myself within the Linux operating system without having taken an operating systems course. During my internship, I learned how to write and compile Linux kernel modules. I made modifications to certain modules in the Linux operating system and developed a new kernel module for a project. Additionally, I prepared a report on Linux Hardening.
AutoISAC operates with the aim of enhancing the automotive industry's resilience against cyberattacks by developing advanced security measures and raising awareness within the industry.
I took part in the Locked Shield 2022 international cyber defense exercise as a member of Turkey's network team.
I have made a presentation on System Security Engineer in Aselsan
I took part in the Locked Shield 2021 international cyber defense exercise as a member of Turkey's network team.