Barış KEÇECİ
Siber Güvenlik Eğitmeni
EXECUTIVE SUMMARY
Experienced cybersecurity professional with more than 16 years of practical, hands-on experience securing critical infrastructure, enterprise networks, and digital environments across multiple industries. I have been responsible for delivering complex security programs, including zero-trust architecture design, SOC/SIEM and SOAR integrations, OT/ICS protection, and full-scope penetration testing.
My work has consistently focused on strengthening organizations’ cybersecurity posture, improving operational resilience, and ensuring compliance with international standards. I have collaborated closely with technical teams, decision-makers, and partners to deliver solutions that balance robust security with business continuity and innovation.
KEY SKILLS
- Zero-Trust architecture design and network segmentation
- SOC/SIEM engineering, SOAR automation, and incident response
- Threat hunting, adversary simulation, and red team operations
- Full-scope penetration testing and vulnerability assessments
- CTI/OSINT and dark web intelligence reporting
- Security governance & compliance (ISO 27001, GDPR, NIS2, PCI DSS)
- Technical leadership, team enablement, and security program delivery
TECHNICAL EXPERTISE
- Network & Zero-Trust: Palo Alto NGFW, Fortigate, F5, NAC, SD-WAN, DDoS protection
- SOC & SIEM: Logsign, Wazuh, Splunk; playbook automation and incident orchestration
- Red Teaming: Adversary emulation, exploit research, phishing campaigns, purple team
- CTI & OSINT: Threat actor profiling, brand protection, dark web monitoring
- DevSecOps & Cloud: CI/CD hardening, IAM, workload security (AWS, Azure, GCP)
- OT/ICS & Endpoint: PLC/SCADA security, EDR, DLP, container and virtualisation security
MAJOR PROJECTS
QTerminals (Antalya & Qatar) – Port Infrastructure Security & SOC Deployment
Delivered a complete cybersecurity transformation for QTerminals’ critical port operations in Turkey and Qatar. The project covered both IT and OT environments, introducing next-generation security architectures and 24/7 monitoring capabilities.
- Designed and implemented multi-layered NGFW solutions with deep inspection and ICS/SCADA protection.
- Built a 24/7 Security Operations Center (SOC) with automated SIEM/SOAR and intelligence pipelines.
- Reduced detection and response times by over 80% through process automation and playbooks.
- Provided red/blue team exercises, hands-on workshops, and ongoing security consultancy.
- Achieved full compliance with ISO 27001, TISAX, ISPS Code, and NIS2.
Yaşam Hospitals Group – Healthcare Cybersecurity & SOC Modernisation
Led a full-scale cybersecurity and infrastructure upgrade for six hospital facilities, securing sensitive patient data, medical IoT systems, and clinical platforms.
- Unified all locations via an encrypted MPLS and SD-WAN backbone.
- Implemented centralised SOC with SIEM/SOAR for real-time detection and automated response.
- Conducted penetration testing, vulnerability assessments, and red team simulations.
- Secured healthcare data flows with NGFW deployment and encrypted tunnels.
- Delivered compliance with GDPR, KVKK, and ENISA healthcare security requirements.
Yörükoğlu Süt – Zero-Trust & Industrial Cybersecurity Program
Oversaw the design and rollout of a multi-site security architecture covering production plants, logistics sites, and corporate offices.
- Replaced legacy firewalls with Palo Alto NGFW, enabling deep visibility and advanced security features.
- Deployed multi-site SD-WAN and VPN for secure, resilient interconnectivity.
- Integrated a SOC and SIEM/SOAR solution, improving visibility and response times.
- Secured OT/ICS environments with network segmentation and tailored access policies.
MINIZ TRADE GmbH (Düsseldorf) – OT/IT Security Hardening and SOC Onboarding
Delivered a contract-backed cybersecurity programme for a Germany-based industrial/logistics organisation, aligned with German data-protection and European cybersecurity baselines.
- Implemented NGFW policies and micro-segmentation across OT/ICS and corporate segments.
- Onboarded log sources to a central SIEM/SOAR platform for 24/7 monitoring.
- Ran red/blue team exercises to validate exposure and improve response maturity.
- Mapped controls to ISO 27001, NIS2 and customer’s internal audit requirements.
OTHER PROJECTS (Selected Highlights)
• Türkiye Finans Katılım Bankası – Migrated perimeter and datacenter firewalls from Juniper SRX and Check Point to Palo Alto NGFW, enabling User-ID, IPS, and application-aware security policies.
• AXA Sigorta – Re-architected network topology and replaced legacy Check Point systems with Palo Alto NGFW, enabling SSL-VPN, Content-ID, and advanced access control policies.
• KAMUSM (Public Certification Authority) – Executed firewall migration from Check Point and Fortigate to Palo Alto NGFW with enhanced micro-segmentation and content inspection for national security compliance.
• Ak Sigorta – Designed and deployed Citrix Web Application Firewall and delivered comprehensive administrator training for improved web application security posture.
• Trendyol – Implemented Citrix WAF to protect high-traffic e-commerce platforms from OWASP Top 10 vulnerabilities and DDoS attacks, enhancing availability and resilience.
• VakıfBank – Deployed Cisco Firepower NGIPS across multiple data centers, improving threat detection accuracy and reducing false positives.
• PTT (Turkish Post & Telegraph Authority) – Combined Citrix WAF and Palo Alto NGFW for dual-layer protection of nationwide communication and postal infrastructure.
• Ministry of Health (T.C. Sağlık Bakanlığı) – Rolled out Palo Alto NGFW with SSL decryption and threat prevention features, strengthening healthcare network security and compliance.
• Memmar Arabi – Built a full-scale enterprise network and security infrastructure including VoIP systems and secure connectivity for 1,000+ users.
WORK EXPERIENCE
Chief Technology Officer (CTO) & Senior Cybersecurity Advisor
GNSAC Bilişim Teknolojileri Ltd. Şti. — March 2019 – Present | Antalya, Türkiye
Founder and CTO responsible for delivering cybersecurity and network solutions for critical infrastructures and enterprise clients. Involved in architecture design, project delivery, product integration, vendor coordination, and compliance consultancy.
- Directed zero-trust deployments, SOC/SIEM implementations, and OT/ICS hardening projects.
- Led penetration testing, threat intelligence, and incident response operations.
- Reduced MTTD/MTTR from days to minutes with automated security workflows.
- Provided training and capability-building for in-house security teams.
Security Operations Team Leader
CyberLink Teknoloji A.Ş. — Mar 2015 – Mar 2019 | Istanbul, Türkiye
Managed a team delivering enterprise-scale cybersecurity projects, including NGFW, WAF, IPS, and APT solutions.
- Designed and deployed network security infrastructures for finance, public, and telecom clients.
- Delivered certified Palo Alto and Citrix security training programs.
Technical Specialist – Logsign
Logsign SIEM Solutions — Nov 2013 – Feb 2015
Provided SIEM consultancy, firewall integration, and pre/post-sales support.
IT Project Manager – Şekerbank
Şekerbank TTVPN Project — Nov 2012 – Mar 2013
Managed nationwide TTVPN rollout project, coordinating ISP and internal IT operations.
IT Specialist – Libya Projects
Meamar Arabi & T&M Engineering — 2010 – 2011
Delivered network, firewall, server, and VoIP systems for large-scale infrastructure and university projects.
CERTIFICATIONS & TRAININGS
Cybersecurity & Network Certifications
- ISO/IEC 27001:2023 – Information Security Management Systems
- NSE 1, NSE 2, NSE 3 – Fortinet Network Security Expert
- PCNSE 6 – Palo Alto Networks Certified Network Security Engineer
- PSE 7 – Palo Alto Platform Specialist
- ACE PAN-OS 7.0 – Palo Alto Accredited Configuration Engineer
- ASE – Palo Alto Networks Accredited Sales Expert
- CCP-N 10.5 – Citrix Certified Professional – Networking
- CCNP – Cisco Certified Network Professional
- MCSA / MCITP / MCTS – Microsoft Infrastructure Certifications
Advanced Security & Professional Development
- CCIE Security – Cisco Certified Internetwork Expert (Security Track)
- CEH – Certified Ethical Hacker
- CSSA / CSSP – Network Security Administration & Advanced Administration
- DevSecOps & Cloud Security – AWS / Azure / GCP Environment Hardening
- Red Team & Threat Hunting Workshops – Adversary Simulation & TTP Analysis
- SOC / SIEM & SOAR Engineering – Incident Response & Automation