Our Team

Meet our team.

We work with KVKK attorneys registered with the Ankara and Istanbul Bar Associations, TSE-certified penetration testers, ISO 27001 lead auditors, and data protection specialists. Certifications are genuine and verifiable, and every expert owns a clearly defined area of responsibility.

Legal, offensive security, and product engineering — all three under one roof.

01 — Legal & Compliance

Legal & Compliance

We interpret KVKK Board decisions, draft formal legal notices, manage VERBİS registrations, audit ISO 27001 ISMS implementations, and work on GDPR contracts (DPAs, SCCs). This team builds the first line of legal defense for client organizations.

The logic is simple: Compliance comes before the fine.

Atty. İrem Genç

Atty. İrem Genç

Legal Counsel · KVKK & Data Privacy Law
Ankara BarosuKVKK Process Management

Attorney registered with the Ankara Bar Association. Works on the legal architecture of data processing operations under KVKK, breach response, correspondence with the Turkish Data Protection Authority, and privacy notice / explicit consent documentation.

Prefers to build auditable compliance models by embedding legal requirements into operational processes.

Ankara Barosu KVKK Specialist Data Privacy Law
Full CV & Projects
Atty. Rabia Dağcı

Atty. Rabia Dağcı

GDPR Compliance Attorney · DPA / SCC Specialist
İstanbul BarosuAB Data Protection

Attorney registered with the Istanbul Bar Association. Focuses on GDPR engagements: EU data protection legislation, cross-border data transfers (DPAs, SCCs), and data flows within international group structures.

Interprets GDPR obligations on a risk basis and fits them into the company's daily operations; looks at concrete business impact rather than abstract clauses.

İstanbul Barosu EU GDPR DPO (CFE-CERT) ✓ CIPP/E DPA / SCC
Full CV & Projects
Uygar Aydın

Uygar Aydın

Data Protection & Information Security Lead Auditor · Practice Lead
İstanbulKVKK SpecialistISMS Practitioner

Ten years in cybersecurity, KVKK, and ISO 27001. Leads general management and business development at Nesil Teknoloji; advises on KVKK and GDPR engagements and conducts ISO 27001 and 27701 audits.

Holds CIPP/E, ISO 27001 Lead Auditor, ISO 27701 Lead Implementer, and CISM certifications, along with a CMB Information Systems Independent Audit License (No. 930873).

ISO/IEC 27001:2022 LA ✓ ISO/IEC 27701:2019 LA ✓ CIPP/E ✓ EU GDPR DPO ✓ CISM ✓ CMB Information Systems Independent Audit License No. 930873
Full CV & Projects
Murat Kaya

Murat Kaya

ISO 27001 Lead Auditor · ISMS Lead
İstanbulBGYS MimariRisk Management

ISO 27001 Lead Auditor. Works on ISMS audits, certification processes, and risk management.

Builds client ISMS structures from scratch or aligns existing systems with the standard; prepares internal audit reports in the field.

CISA ✓ CISSP ISO/IEC 27001:2022 LA CompTIA Security+
Full CV & Projects
Murat Nas

Murat Nas

Business Development Director · Strategic Growth
Strategic PartnershipsEnterprise Clients

Business Development Director at Nesil Teknoloji. Works on new business opportunities, enterprise client relationships, and the company's market positioning.

A long-time industry insider; works on enterprise sales, proposal management, and long-term client relationships.

Strategic Growth Enterprise Sales Business Development
Full CV & Projects
Faruk Keten

Faruk Keten

Senior Systems Engineer · Infrastructure Security
Active DirectoryNetwork Architecture

Senior systems engineer. Works on IT infrastructure, network architecture, and Active Directory; enterprise system deployment and security hardening are his domain.

Supports the infrastructure side of both the internal team and client projects; the person who keeps the environment running.

MCSE CCNA Sophos Endpoint MikroTik MTCNA
Full CV & Projects
02 — Offensive Security

Offensive Security

We operate under TSE Class A penetration testing accreditation (TS 13638/T2, No. TSE-STF-065). Our OSCP, OSEP, and CRT certified experts deliver web, mobile, API, network, source code (SAST), and red team engagements across finance, energy, e-commerce, and government.

We prioritize findings not just by CVSS score, but by business impact. We follow the NIST SP 800-115, OWASP WSTG, and OSSTMM frameworks — and write reports in language the reader can act on.

Alpaslan Aydın

Alpaslan Aydın

TSE-Certified Penetration Testing Expert · 10+ Years
Web · Mobile · NetworkRed Team

Ten years of penetration testing. TSE Senior Penetration Testing Expert. Enterprise environments and critical infrastructure testing are his core focus.

Holds OSCP+, OSCP, CEH, and LPT certifications; works with methodological discipline in the field and writes audit-ready reports.

OSCP+ ✓ OSCP ✓ CEH ✓ LPT TSE Senior Penetration Testing Expert (TS 13638)
Full CV & Projects
Muhammed Halil

Muhammed Halil

CREST Certified Pentester · Web · API · Internal Network
Web · APIInternal Network

CREST CPSA and CRT certified penetration tester. Works on web, API, and internal network pentest projects; reports findings using the OWASP WSTG and NIST SP 800-115 methodologies.

With advanced English and Arabic proficiency, carries out field engagements and technical reporting for clients across the MENA and Gulf regions.

CREST CPSACREST CRTWeb · API PentestInternal Network PentestOWASP WSTGEnglish · Arabic
Full CV & Projects
Sezai Balcı

Sezai Balcı

Red Team · Penetration Tester · Web · API · Active Directory
PentesterRed Team

Penetration tester in the Nesil Teknoloji Red Team. Performs security assessments across web applications, API services, corporate networks and Active Directory environments.

Validates vulnerabilities not only with automated tools but through manual testing methods and realistic attack scenarios.

Web · API PentestActive DirectoryManual Testing
Full CV & Projects
Murat Sevri

Murat Sevri

TSE Senior Penetration Testing Expert · Network & Database Security
Network Penetration TestingDatabase Security

Pentests on the network and database side. Segmentation gaps and database privilege issues are his main focus.

TSE Senior Penetration Testing Expert (TS 13638). Backs up findings with proof and worked examples.

TSE Senior Penetration Testing Expert (TS 13638) Network Pentest Database Assessment Active Directory
Full CV & Projects
Ulaşcan Özbaş

Ulaşcan Özbaş

Red Team Specialist · Cloud & Container Attack Simulation
Cloud Attack SimulationKubernetes Security

Runs attack simulations on cloud and containers. Tests misconfigurations, privilege escalation and container escape on Azure and Kubernetes.

Tests lateral movement across cloud identities. Holds Azure Solutions Architect and CKAD.

Red TeamAzure SecurityKubernetes (CKAD)Cloud Attack SimulationLateral Movement
Full CV & Projects
Eren İnal

Eren İnal

Source Code Analysis (SAST) & Software Security Specialist
Source Code Analysis (SAST)Software Process Security

On the source-code side. Runs code and software-process security testing with SonarQube and Fortify.

Catches flaws early in the code, from a developer's background. Works on the Secure SDLC side.

Source Code Analysis (SAST)SonarQubeFortifySecure SDLC.NET
Full CV & Projects
Alper Çoşar

Alper Çoşar

TSE-Certified Penetration Testing Expert · Internal Network & Infrastructure Security
Internal Network Penetration TestingActive Directory

TSE-Certified Penetration Testing Expert. Internal network pentesting, Active Directory assessment, and infrastructure security are his main areas.

Works within the TS 13638 framework; analyzes internal attack surfaces hands-on and delivers findings in audit-ready reports.

TSE-Certified Penetration Testing Expert (TS 13638) Internal Network Pentest Active Directory CRTP
Full CV & Projects
Buğra Tektepe

Buğra Tektepe

Penetration Testing & Source Code Analysis (SAST) Lead
Hacettepe Computer EngineeringSAST · DAST

Computer Engineering graduate of Hacettepe University. Leads the penetration testing and source code analysis (SAST) team. Works with the TS 13638, OWASP, and PTES frameworks.

Performs code security analysis with Fortify and SonarQube; frames findings through RCA and Secure SDLC so they close permanently.

OSCP GPEN (SANS / GIAC) TSE Senior Penetration Testing Expert (TS 13638) CSSLP Fortify SonarQube
Full CV & Projects
Lizi Natroshvili

Lizi Natroshvili

OSCP-Certified Offensive Security Expert
Offensive SecurityAD & Network

OSCP-certified penetration tester. Works in offensive security with a focus on Active Directory and network attack scenarios.

Tests complex attack chains in the field; reports show how each finding was discovered and how to reproduce it.

OSCP TSE-Certified Penetration Testing Expert (TS 13638) CRTP eJPT
Full CV & Projects
Enes Yüksel

Enes Yüksel

Penetration Tester · Web · API · Red Team
OWASP Top 10API Security

Pentester working across web, API, and network. Deeply familiar with the OWASP Top 10, API security, Active Directory attacks, and red team scenarios.

Has delivered penetration tests across finance, energy, e-commerce, and government. Reports findings by business impact, not just technical score.

OSCP CEH TSE-Certified Penetration Testing Expert (TS 13638) eWPTX OSWP
Full CV & Projects
Gulzar Mamytova

Gulzar Mamytova

Cybersecurity Analyst · Threat Detection & Incident Response
SOC · Blue TeamThreat Hunting

Cybersecurity analyst on the SOC side: threat detection, log analysis, and incident response.

Performs threat hunting on Splunk and works with the MITRE ATT&CK framework; doesn't just close alerts — digs into root causes.

CompTIA Security+ TSE-Registered Penetration Testing Expert (TS 13638) Splunk Power User MITRE ATT&CK
Full CV & Projects
Ayşenur Ertürk

Ayşenur Ertürk

Cybersecurity Analyst · Threat Detection & Incident Response
SOC Tier-2Incident Response

Cybersecurity analyst. Works on threat detection, EDR log analysis, and incident response.

Operates at SOC Tier 2 in the field; runs proactive scanning and forensic work, not just reactive response.

CompTIA Security+ TSE-Registered Penetration Testing Expert (TS 13638) CySA+ CHFI
Full CV & Projects
Zehra Baranlı

Zehra Baranlı

OSWE-Certified Red Team Specialist · Web Exploitation & Initial Access
Web ExploitationCustom Exploit Development

Works on web-based initial access and exploit development. Chains complex web flaws and writes her own exploits.

Uses internet-facing web apps as the way in. OSWE (Offensive Security Web Expert) certified.

OSWE (Offensive Security Web Expert)Web ExploitationCustom Exploit DevelopmentInitial AccessSource Code Review
Full CV & Projects
Melisa Özen

Melisa Özen

Red Team Specialist · Social Engineering & Initial Access
Social EngineeringInitial Access

On the red team's social engineering and initial access side. Opens the first foothold through targeted phishing and user-focused scenarios.

Hands the access she gains to the operation team. Maps her work to MITRE ATT&CK techniques.

Red TeamSocial EngineeringSpear-PhishingInitial AccessMITRE ATT&CK
Full CV & Projects
ED

Elif Dalbul

Red Team Specialist · Active Directory & Lateral Movement
Active Directory AttacksLateral Movement

Works on Active Directory and lateral movement. Builds credential-harvesting, Kerberos and domain-takeover scenarios.

Shows step by step how one system leads to the next. Delivers findings as an attack-path map.

Red TeamActive DirectoryLateral MovementKerberosBloodHound
Esma Pamuk

Esma Pamuk

Red Team Specialist · C2 Infrastructure & Evasion
Command & Control (C2)EDR/AV Evasion

On the command-and-control (C2) and evasion side. Sets up C2 channels and works on EDR and antivirus bypass.

Focuses on moving through the operation unnoticed. Shares her methods so the defense team can sharpen detection.

Red TeamCommand & Control (C2)EDR EvasionOPSECMITRE ATT&CK
Full CV & Projects
Betül Eren

Betül Eren

Red Team Specialist · Scenario Design & Threat Emulation
Scenario DesignThreat Emulation

Designs the operation scenarios. Models real threat groups' methods (TTPs) through MITRE ATT&CK.

Shapes each scenario around the adversary being emulated. Reports results separately for management and technical teams.

Red TeamThreat EmulationMITRE ATT&CKTTP ModelingScenario Design
Full CV & Projects
Sevim Akdemir

Sevim Akdemir

Red Team Specialist · Penetration Testing
Network & Web Penetration TestingRed Team Operations

Pentests on the red team. Looks for holes across web, network and applications and works the exploitation.

Tests the attack steps in order through operation scenarios. Reports findings with worked examples.

Red TeamPenetration TestingAttack Surface AnalysisLateral MovementMITRE ATT&CK
Full CV & Projects
Fatih Taşkaya

Fatih Taşkaya

Red Team · Social Engineering & Phishing Specialist
PhishingRed Team

Cyber security specialist in the Nesil Teknoloji Red Team, focused on social engineering and phishing simulations. Plans and runs authorised phishing tests to measure employee awareness.

Designs scenarios, runs campaigns and reports results to reduce the human-driven attack surface of organisations.

Social EngineeringPhishing SimulationAwareness Testing
Full CV & Projects
Our Approach

When choosing a cybersecurity vendor, you need to see the name behind the signature. This work is done by people in the field — not by an automated report.