Skip to content
View mfkocalar's full-sized avatar

Block or report mfkocalar

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
mfkocalar/README.md

πŸ›‘οΈ About Me

πŸ‘‹ Hi, I'm Mehmet Fatih Kocalar β€” a cybersecurity professional with 12+ years of experience doing one thing: making organizations harder to attack and faster to recover when they are.

🎯 My work sits at the intersection of technical depth and strategic clarity. I've led SOC operations, built vulnerability management programs from scratch, designed cloud security architectures across hybrid and cloud-native environments, and guided organizations through ISO 27001, NIST, and PCI-DSS compliance β€” not as checkbox exercises, but as genuine risk reduction.

🏭 The sectors I've worked across β€” fintech, energy, telecommunications, technology, critical infrastructure, health tech, and medical education β€” share a common thread: the cost of getting security wrong is existential. That reality keeps my work grounded.

🀝 Open to conversations about security strategy, team building, and complex risk challenges.


🌐 Socials

LinkedIn GitHub


πŸ” What I Do

Area Focus
πŸ” Threat Detection & IR Leading SOC teams through high-pressure incidents and building playbooks that reduce response time and noise
☁️ Cloud & Enterprise Security Designing security frameworks for hybrid, cloud-native, and legacy environments
πŸ“‹ Compliance & Risk Alignment Translating ISO 27001, SOC2, NIST CSF, and PCI-DSS into practical controls that reduce actual risk
πŸ›‘οΈ Vulnerability Management Building and maturing programs that prioritize what matters, not just what's loud
🀝 Cross-Functional Leadership Bridging the gap between technical teams and business stakeholders so security decisions stick

πŸ… Certifications

CEH ISO 27001 LA


🧰 Tech Stack

πŸ” SIEM & SOC Platforms

Splunk ArcSight QRadar

πŸ›‘οΈ Network Security

FortiGate PaloAlto CheckPoint NAC DLP Mail Gateway Sandbox

πŸ”Ž Vulnerability Management

Nessus Qualys ORCA Security

πŸ”‘ Identity & Access

CyberArk OKTA

☁️ Cloud Platforms

AWS Azure

πŸ“‹ Compliance & Frameworks

MITRE ATT&CK Cyber Kill Chain NIST ISO 27001 ISO 27019 PCI-DSS COBIT SOX CIS Benchmarks OWASP

πŸ› οΈ Productivity & Operations

G-Suite JIRA KnowBe4 Endpoint Protection


πŸ“Š GitHub Stats



πŸ’° You can help me by Donating

PayPal

Popular repositories Loading

  1. OWASP-Security-Skills OWASP-Security-Skills Public

    Claude Code plugin with two OWASP-grounded security skills: audit code, APIs, Kubernetes and LLM/agent apps against OWASP standards, and review against a 14-domain secure coding checklist.

    Python 2 3

  2. mcp-security-review mcp-security-review Public

    Forked from oguzhantopgul/mcp-security-review

    An AI skill that teaches language models how to perform intelligent security reviews of MCP

  3. mfkocalar mfkocalar Public

  4. SecureNewspaper SecureNewspaper Public

    Python 1

  5. havadis havadis Public

    Havadis β€” a public, source-independent daily security newspaper aggregating cybersecurity RSS feeds

    TypeScript