~/bugra-kanmaz/profile.sh
SESSION: AVAILABLE SESSION: VERFÜGBAR
BUGRA_KANMAZ
Based in Germany
Sitz in Deutschland
$ whoami bugra_kanmaz — product_owner / regulatory_security_compliance / ai $ systemctl status compliance-frameworks 7 loaded, 7 active $ whoami bugra_kanmaz — product_owner / regulatorische_sicherheits_compliance / ki $ systemctl status compliance-frameworks 7 geladen, 7 aktiv

Bridging the gap between complex regulatory frameworks and product delivery.

Die Brücke zwischen komplexen regulatorischen Rahmenwerken und Produktlieferung.

Product Owner for Regulatory & Security Compliance and AI. I build the AI agents, dashboards, and traceability systems that collapse compliance work from months of paperwork into minutes of reviewable output — without cutting corners on ISO 21434, UN R155, China GB 44495, ISO 27001, ISO 42001 or the EU AI Act.

Product Owner für Regulatory & Security Compliance und KI. Ich baue die KI-Agenten, Dashboards und Traceability-Systeme, die Compliance-Arbeit von Monaten an Papierkram auf Minuten prüfbarer Ergebnisse verkürzen — ohne Kompromisse bei ISO 21434, UN R155, China GB 44495, ISO 27001, ISO 42001 oder dem EU AI Act.

[OK]ISO 21434 [OK]ISO 27001 [OK]ISO 42001 [OK]EU AI Act [OK]NIS-2 [OK]NIST CSF [OK]ASPICE [OK]UN R155 [OK]GB 44495
[OK]ISO 21434 [OK]ISO 27001 [OK]ISO 42001 [OK]EU AI Act [OK]NIS-2 [OK]NIST CSF [OK]ASPICE [OK]UN R155 [OK]GB 44495
$ journey --log

Compliance-as-code, step by step.

$ werdegang --log

Compliance-as-Code, Schritt für Schritt.

YESTERDAYReactive

The Spreadsheet Era

Evidence lived in shared drives. Audit readiness meant a 6-week scramble before every review, pulling screenshots into Word.

2023Measured

Dashboards & Traceability

I built real-time Splunk & trace systems turning SLAs, incidents and controls into live signals — not quarterly deliverables.

2024Accelerated

AI-Drafted Work Products

CSMS Coach proved an LLM can guide engineers through ISO 21434 work products, generating first-pass artefacts a reviewer can refine in minutes.

2025 →Autonomous

Autonomous Compliance Agents

Agents that watch incidents, draft regulator reports, tailor CVs, score evidence — human-in-the-loop at every gate. Fast, accurate, auditable.

GESTERNReaktiv

Die Tabellen-Ära

Nachweise lagen auf Netzlaufwerken. Auditbereitschaft hieß 6 Wochen Panik vor jedem Review — Screenshots in Word kopieren.

2023Messbar

Dashboards & Traceability

Ich habe Splunk-Dashboards und Trace-Systeme gebaut, die SLAs, Vorfälle und Kontrollen in Live-Signale verwandeln — statt in Quartalsberichte.

2024Beschleunigt

KI-gestützte Work Products

CSMS Coach zeigt: ein LLM kann Ingenieure durch ISO-21434-Work-Products führen und Erstentwürfe liefern, die in Minuten freigegeben werden.

2025 →Autonom

Autonome Compliance-Agenten

Agenten, die Vorfälle beobachten, Meldungen entwerfen, Lebensläufe anpassen, Evidenzen bewerten — Mensch an jedem Gate. Schnell, genau, auditierbar.

$ ps --project-list

The receipts — AI + compliance, shipping.

$ ps --projekt-liste

Die Nachweise — KI + Compliance, im Einsatz.

01/GH

VaultISO27 — On-Prem ISO 27001 Generator

A 10-clause demo of an on-premises ISO 27001:2022 ISMS document generator. Runs entirely on local LLMs via Ollama + ChromaDB RAG — no cloud, no API keys, your data never leaves the machine.

OLLAMACHROMADBRAGISO 27001LOCAL LLM
0%
CLOUD DATA EXPOSURE
2026
RUN →
02/GH

CSMS Coach — ISO 21434 AI Agent

A guided AI assistant that walks trainees through generating cybersecurity work products for automotive components — step-by-step, aligned to the CSMS process. Built for MS Copilot; portable to any LLM. Actively extending it to cover the type-approval regulations that make CSMS mandatory: UN R155 and China GB 44495.

LLM AGENTISO 21434UN R155GB 44495CSMSCOPILOT
10×
FASTER DRAFTS
2024–26
RUN →
03/DG

VW D³ Project — Security Compliance

Security Compliance Engineer on VW's D³ project, a secure cloud-to-edge pipeline distributing encrypted diagnostic assets and firmware to independent automotive networks. Ran TARA risk analyses, tracked applicable regulations, and managed IT-security vendor transitions to stay aligned with UNECE R155/R156.

TARAUNECE R155UNECE R156CLOUD-TO-EDGEVW D³
Risk
ANALYSIS & TRACKING
2025–26
CONFIDENTIAL
04/DG

ISO 9001 Audit Support — VW ADMT

Supported a Volkswagen ADMT ISO 9001 quality-management audit by scripting an AI-assisted review of 400+ internal policies, mapping each to audit requirements for fast gap analysis.

ISO 9001AI-ASSISTED REVIEWVW ADMTGAP ANALYSIS
400+
POLICIES REVIEWED
2025
CONFIDENTIAL
05/DG

GBT Security Regulation — CARIAD

Evaluated China GB/T automotive cybersecurity regulation across Volkswagen platforms with CARIAD — built end-to-end traceability, ran stakeholder communication, and coordinated homologation testing for regulatory alignment.

CHINA GB/TGB 44495CARIADHOMOLOGATIONTRACEABILITY
E2E
TRACEABILITY BUILT
2022–24
CONFIDENTIAL
06/GH

governAIzer — AI Governance RAG Tool

A Streamlit tool for AI-governance document work: ingests policy/compliance documents, builds a RAG index, cross-references requirements, and summarizes findings — keeps ISO 42001 and EU AI Act documentation reviewable.

STREAMLITLANGCHAINCHROMADBGEMINIISO 42001
RAG
DOCS CROSS-REF'D
2026
RUN →
07/GH

JobPilot — AI job-application pipeline

Local desktop tool: scrape → AI-score → review → tailor CV → apply. Gemini rates each listing against your CV, outputs ATS-clean DOCX. 100% local, human-in-the-loop — no auto-submit.

PYTHONGEMINISTREAMLITPLAYWRIGHTDOCX
1,500/d
AI CALLS, FREE TIER
2025
RUN →
08/LI

UN R155 vs. GB 44495 — Regulation Comparison

A side-by-side breakdown of UN R155 and China's GB 44495-2024 — CSMS requirements, implementation timelines, and where the two regulations' technical test methods diverge, mapped against ISO/SAE 21434.

UN R155GB 44495CSMSISO/SAE 21434TYPE APPROVAL
8/27
GAP-ANALYZED REQUIREMENTS
2025
RUN →
09/LI

Automotive Cybersecurity — Regulations Overview

A practitioner-oriented walkthrough of the global regulations and standards shaping automotive cybersecurity — written for engineers moving from policy into day-to-day delivery.

ARTICLEUNECER155R156
Guide
FOR PRACTITIONERS
2024
RUN →
01/GH

VaultISO27 — On-Prem ISO-27001-Generator

Eine 10-Klausel-Demo eines On-Premises-ISMS-Dokumentgenerators für ISO 27001:2022. Läuft vollständig auf lokalen LLMs via Ollama + ChromaDB RAG — keine Cloud, keine API-Keys, Daten verlassen nie das Gerät.

OLLAMACHROMADBRAGISO 27001LOKALES LLM
0%
CLOUD-EXPOSITION
2026
AUSFÜHREN →
02/GH

CSMS Coach — ISO 21434 KI-Agent

Ein geführter KI-Assistent, der Anwender Schritt für Schritt durch die Erstellung von Cybersecurity-Work-Products für Automotive-Komponenten leitet. Gebaut für MS Copilot; auf jede LLM-Plattform übertragbar. Wird aktuell um die Typgenehmigungsvorschriften erweitert, die CSMS verpflichtend machen: UN R155 und China GB 44495.

LLM AGENTISO 21434UN R155GB 44495CSMSCOPILOT
10×
SCHNELLERE ENTWÜRFE
2024–26
AUSFÜHREN →
03/DG

VW D³ Project — Security Compliance

Security Compliance Engineer im VW-D³-Projekt, einer sicheren Cloud-to-Edge-Pipeline für die Verteilung verschlüsselter Diagnose-Assets und Firmware an unabhängige Automotive-Netzwerke. Führte TARA-Risikoanalysen durch, verfolgtes geltende Vorschriften und koordinierte IT-Sicherheits-Vendor-Übergänge für die Einhaltung von UNECE R155/R156.

TARAUNECE R155UNECE R156CLOUD-TO-EDGEVW D³
Risiko
ANALYSE & VERFOLGUNG
2025–26
CONFIDENTIAL
04/DG

ISO-9001-Audit-Support — VW ADMT

Unterstützte ein Volkswagen-ADMT-Audit zur ISO 9001 Qualitätsmanagementsystem durch die Automatisierung einer KI-gestützten Überprüfung von 400+ internen Richtlinien, mit Zuordnung zu Audit-Anforderungen für schnelle Lücken-Analyse.

ISO 9001KI-UNTERSTÜTZTE ÜBERPRÜFUNGVW ADMTLÜCKEN-ANALYSE
400+
RICHTLINIEN ÜBERPRÜFT
2025
CONFIDENTIAL
05/DG

GBT-Sicherheitsregulierung — CARIAD

Evaluierte die chinesische GB/T-Automotive-Cybersecurity-Regulierung auf Volkswagen-Plattformen mit CARIAD — baute durchgehende Traceability, führte Stakeholder-Kommunikation durch und koordinierte Homologations-Tests für regulatorische Angleichung.

CHINA GB/TGB 44495CARIADHOMOLOGATIONTRACEABILITY
E2E
TRACEABILITY AUFGEBAUT
2022–24
CONFIDENTIAL
06/GH

governAIzer — KI-Governance-RAG-Tool

Ein Streamlit-Tool für KI-Governance-Dokumente: erfasst Richtlinien- und Compliance-Dokumente, baut einen RAG-Index, referenziert Anforderungen dokumentübergreifend — hält ISO-42001- und EU-AI-Act-Dokumentation prüfbar.

STREAMLITLANGCHAINCHROMADBGEMINIISO 42001
RAG
DOKUMENTE REFERENZIERT
2026
AUSFÜHREN →
07/GH

JobPilot — KI-Bewerbungspipeline

Lokales Desktop-Tool: Scraping → KI-Bewertung → Review → CV-Anpassung → Bewerbung. Gemini bewertet jede Stelle gegen deinen Lebenslauf, liefert ATS-saubere DOCX. 100 % lokal, Mensch an jedem Gate.

PYTHONGEMINISTREAMLITPLAYWRIGHTDOCX
1.500/T
KI-AUFRUFE, FREE TIER
2025
AUSFÜHREN →
08/LI

UN R155 vs. GB 44495 — Regulierungsvergleich

Ein direkter Vergleich von UN R155 und Chinas GB 44495-2024 — CSMS-Anforderungen, Umsetzungsfristen und wo sich die technischen Testmethoden beider Regulierungen unterscheiden, abgeglichen mit ISO/SAE 21434.

UN R155GB 44495CSMSISO/SAE 21434TYPENGENEHMIGUNG
8/27
GAP-ANALYSIERTE ANFORDERUNGEN
2025
AUSFÜHREN →
09/LI

Automotive Cybersecurity — Regulatorik-Überblick

Praxisorientierter Überblick zu den globalen Regulierungen und Standards der Automotive Cybersecurity — geschrieben für Ingenieure, die von Policy in den täglichen Delivery-Alltag wechseln.

ARTIKELUNECER155R156
Guide
FÜR PRAKTIKER
2024
AUSFÜHREN →
$ modules --list

Four disciplines, one operating system.

$ module --liste

Vier Disziplinen, ein Betriebssystem.

MODULE 01

Compliance Engineering — traceable systems.

NIST, ISO 21434, ISO 27001, UN R155, China GB 44495. Traceability spines and real-time dashboards that make continuous audit readiness a default, not a scramble.

MODULE 02

AI Governance — aligned to the Act.

AI-driven compliance tooling that streamlines complex work products and stays aligned with ISO 42001 and the EU AI Act — documentation that writes itself, reviewed by humans.

MODULE 03

Product Management — whole lifecycle.

Release planning, change management, and multi-level backlog alignment for global platforms. Governance ships alongside the feature, not six sprints later.

MODULE 04

Requirements & Traceability — one source of truth.

ASPICE-grade backlog management for mission-critical automotive systems. Stakeholders and engineers work from the same linked, auditable record.

MODUL 01

Compliance Engineering — nachverfolgbare Systeme.

NIST, ISO 21434, ISO 27001, UN R155, China GB 44495. Traceability-Rückgrat und Echtzeit-Dashboards, die kontinuierliche Auditbereitschaft zum Standard machen — nicht zum Stressfall.

MODUL 02

KI-Governance — im Einklang mit dem Act.

KI-getriebenes Compliance-Tooling, das komplexe Work Products schlank macht und sich an ISO 42001 und dem EU AI Act ausrichtet — Dokumentation, die sich selbst schreibt, von Menschen geprüft.

MODUL 03

Produktmanagement — kompletter Lifecycle.

Release-Planung, Change Management und mehrschichtige Backlog-Abstimmung für globale Plattformen. Governance geht gemeinsam mit dem Feature in Produktion — nicht sechs Sprints später.

MODUL 04

Anforderungen & Traceability — eine Source of Truth.

ASPICE-Backlog-Management für sicherheitskritische Automotive-Systeme. Stakeholder und Entwickler arbeiten auf demselben verlinkten, auditierbaren Datenbestand.

$ experience --log
Diconium
Product Owner | Compliance — Nov 2022–Present — Nürnberg (Remote)
Owns compliance tooling and cybersecurity audits for VW vehicle platforms — ISO 21434, ISO 27001, UN R155/R156, China GB 44495 — building the AI-driven traceability that keeps CSMS and ISMS audits on schedule.
Luxoft
Senior Business Analyst — Dec 2021–Oct 2022 — Ingolstadt
Ran requirements traceability for ADAS programs across 5+ stakeholders, aligning Codebeamer, Enterprise Architect and DevOps into one auditable toolchain.
DAIICHI Electronic
Software Requirements Engineer — Jan 2021–Jan 2022 — Bursa
Derived roughly 2,500 software and system requirements per project for Stellantis embedded platforms, running the ASPICE SWE.1 process end to end.
BorgWarner Inc.
Systems Support Expert — Sep 2017–Jan 2021 — İzmir
Managed configuration and change control and delivered around 40 SW documentation packages a year across VW, Daimler, Hyundai and Renault embedded-software industrialization programs.
$ erfahrung --log
Diconium
Product Owner | Compliance — Nov 2022–Present — Nürnberg (Remote)
Verantwortet Compliance-Tools und Cybersecurity-Audits für VW-Fahrzeugplattformen — ISO 21434, ISO 27001, UN R155/R156, China GB 44495 — und baut KI-gestützte Nachverfolgbarkeit für termingerechte CSMS- und ISMS-Audits.
Luxoft
Senior Business Analyst — Dec 2021–Oct 2022 — Ingolstadt
Steuerte die Anforderungsverfolgung für ADAS-Programme über mehr als 5 Stakeholder hinweg und verzahnte Codebeamer, Enterprise Architect und DevOps zu einer durchgängig prüfbaren Toolchain.
DAIICHI Electronic
Software Requirements Engineer — Jan 2021–Jan 2022 — Bursa
Leitete pro Projekt rund 2.500 Software- und Systemanforderungen für eingebettete Stellantis-Plattformen ab und führte den ASPICE-SWE.1-Prozess vollständig durch.
BorgWarner Inc.
Systems Support Expert — Sep 2017–Jan 2021 — İzmir
Verantwortete Konfigurations- und Änderungsmanagement und lieferte jährlich rund 40 SW-Dokumentationspakete für Industrialisierungsprogramme eingebetteter Software bei VW, Daimler, Hyundai und Renault.
$ certs --verify

Recent credentials — proof, not just a list.

$ zertifikate --prüfen

Aktuelle Zertifizierungen — Nachweis, keine Liste.

[✓]2026ISC2 — Certified in Cybersecurity (CC)Foundational cybersecurity certification, ISC2.
[✓]2026Proofpoint — Certified AI Agent Security SpecialistAI agent risk, governance & secure collaboration.
[✓]2026ISO 31000:2018 — Risk ManagementStructured risk evaluation training.
[✓]2026BSI — IT-Grundschutz-PraktikerFirst certification completed fully in German.
[✓]2026ISC2 — Certified in Cybersecurity (CC)Grundlagenzertifikat Cybersecurity, ISC2.
[✓]2026Proofpoint — Certified AI Agent Security SpecialistRisiko, Governance und sichere Zusammenarbeit bei KI-Agenten.
[✓]2026ISO 31000:2018 — Risk ManagementTraining zur strukturierten Risikobewertung.
[✓]2026BSI — IT-Grundschutz-PraktikerErstes Zertifikat komplett auf Deutsch absolviert.
$ archive --list

Earlier work — data, regions, academia.

$ archiv --liste

Frühere Arbeiten — Daten, Regionen, Akademia.

./market-analysis

Statistical periodicals & regional economic reports for Bursa and Eskişehir, 2009–2015.

./modeling

Regression analysis, estimation, and applied case studies.

./marktanalyse

Statistische Periodika und regionale Wirtschaftsberichte für Bursa und Eskişehir, 2009–2015.

./modellierung

Regressionsanalyse, Schätzung und angewandte Fallstudien.

$ contact --list
$ kontakt --liste

Got a compliance program that should ship like a product? Let's build it.

Ein Compliance-Programm, das wie ein Produkt ausgeliefert werden soll? Lass uns bauen.

$contact --schedule calendly.com/mborakanmazBOOK → $contact --connect linkedin.com/in/bknmzOPEN → $contact --code github.com/BKnmzOPEN →
$kontakt --termin calendly.com/mborakanmazBUCHEN → $kontakt --vernetzen linkedin.com/in/bknmzÖFFNEN → $kontakt --code github.com/BKnmzÖFFNEN →
bugra_kanmaz@compliance-as-code:~$ status ok © 2026 · Bugra Kanmaz EN C1 · DE B2 · TR C2 · RU A2 Sprachen: EN C1 · DE B2 · TR C2 · RU A2