Can Kayali-Chief Information Security Officer
Check rate
Experience
Chief Information Security Officer
Universität Salzburg
- Leading the university-wide information security function (approx. 3,000 staff, 16,000 students)
- Building the ISMS (operating model, risk framework, policy suite, and multi-year roadmap)
- Chairing the Information Security Steering Committee and reporting directly to leadership
- Running the ISO 27001 certification programme: scoping, gap analysis and control implementation under way
Head of Information Security
Validis
- Led information security for a London-based fintech serving banking and audit clients, with global operations
- Implemented and rolled out Vanta across the organisation, covering risk management, IAM recertification, vendor management, HR onboarding/offboarding, and internal audit
- Acted as the primary security contact for enterprise client due diligence and vendor risk assessments, directly supporting the sales pipeline
Fractional CISO
Kort
- Served as external CISO and ISO 27001 lead for a digital media company in Turkey; advised on information security governance and compliance obligations
- Designed and implemented a sustainability platform for a UK biofuels company, enabling fuel traceability and supporting regulatory and ESG reporting requirements
Head of Information Security
Causaly
- Built the security function for a venture-backed AI/biotech start-up, including policy framework, risk register, asset inventory, and incident response
- Achieved ISO 27001 certification within 12 months, building the ISMS from first policy to certification
Senior Vice President
AlixPartners
- Advised within digital and cybersecurity engagements across carve-out and post-merger scenarios for PE-backed and corporate clients
- Led cybersecurity engagements for multiple organisations undergoing insolvency and administration processes.
Manager, Technology Risk
Protiviti
- Ran IAM transformation programmes and security assessments for investment banking clients, covering role-based access control, privileged access management, eDiscovery and trade surveillance
- Delivered GDPR readiness and data privacy assessments for clients across insurance and manufacturing
Assistant Manager, Advisory
KPMG
- Advised major insurers on Solvency II and data governance; coordinated forensic response and a BaFin-led regulatory investigation following a client data leakage event.
Technology Consultant
Accenture
- Worked across major IT transformation and outsourcing programmes in banking and automotive, covering project management, incident management and business continuity.
Industry experience
See where this freelancer has spent most of their professional time.
Experienced in Banking and Finance, Insurance, Professional Services, Automotive, Manufacturing, and Energy.
Business area experience
See which departments and functions this freelancer has contributed to most.
Experienced in Information Technology, Legal, Finance, Operations, Project Management, and Strategy.
Summary
CISO with over 18 years of international experience across technology startups, higher education, and regulated financial services. Proven track record of building security functions from the ground up, managing and influencing security investment across a €30m portfolio and leading teams of up to 20 across Germany, the UK, Austria and Turkey.
Extensive experience delivering ISO 27001 certifications from a zero baseline, leading SOC 2 programmes, and executing security workstreams for M&A transactions exceeding £2bn. Brings a hands-on approach with a strong focus on scalable, cost-efficient security solutions.
Skills
- Security Function Build-Out
- Board And C-Suite Advisory
- Cloud Security (Aws, Azure, Gcp)
- Zero Trust Architecture
- M&A Cyber Due Diligence
- Incident Response And Crisis Management
- Grc Programme Delivery (E.G. Vanta)
- Vendor And Third-Party Risk
- Regulatory And Compliance Advisory
- Iso 27001
- 27017
- 27005
- 42001 (Ai Governance)
- Soc 2 Type I And Ii
- Gdpr
- Nis2
- Dora
- Nist Csf
- Pci Dss
- Hipaa
- Solvency Ii
Languages
Education
Universität des Saarlandes
MSc · Computer Science · Saarbrücken, Germany
Universität des Saarlandes
BSc · Computer Science · Saarbrücken, Germany
Deutsche Schule Istanbul
Abitur · Gymnasium · İstanbul, Turkey
Certifications & licenses
Statistics
Experience
Global experience
Expertise
Qualifications
Profile
Frequently asked questions
Have questions? Find more information here.
Can is based in London, United Kingdom.
Can speaks the following languages: Turkish (Native), German (Advanced), English (Advanced), French (Intermediate).
Can has at least 18 years of experience. During this time, Can has worked in at least 7 different roles and for 8 different companies. The average length of individual experience is 2 years and 4 months. Note that Can may not have shared all experience and actually has more experience.
Based on recent experience, Can would be well-suited for roles such as: Chief Information Security Officer, Head of Information Security, Fractional CISO.
Can's most recent position is Chief Information Security Officer at Universität Salzburg.
In recent years, Can has worked for Universität Salzburg, Validis, Kort, and Causaly.
Can is most experienced in industries like Banking and Finance, Insurance, and Professional Services. Can also has some experience in Automotive, Manufacturing, and Energy.
Can is most experienced in business areas like Information Technology, Legal, and Operations. Can also has some experience in Project Management, Finance, and Audit.
Can has recently worked in industries like Energy, Media and Entertainment, and Biotechnology.
Can has recently worked in business areas like Information Technology, Legal, and Sustainability Management.
Can holds a Master in Computer Science from Universität des Saarlandes and a Bachelor in Computer Science from Universität des Saarlandes.
Can has 5 certificates. Among them, these include: CISM, Vanta, and ISO 27001 Senior Lead Implementer.
Can will be available from October 2026.
Daily rate distribution
The rates shown represent the typical market range for freelancers in this position based on recent contracts on our platform.
Average rates for similar positions
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 31 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
Similar freelancers
Discover other experts with similar qualifications and experience
Experts recently working on similar projects
Freelancers with hands-on experience in comparable project as a Chief Information Security Officer
Nearby freelancers
Professionals working in or nearby London, United Kingdom
