Senior Technology Risk & Audit Specialist

Picus Security Inc.

Çankaya

On-site

TRY 5,897,000 - 8,845,000

Full time

11 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Picus Security seeks a Senior Technology Risk & Audit Specialist to advance governance, risk, and compliance at scale. You will run ongoing assurance with engineering teams, own global certification programs, and advise business and tech units on scalable risk-aware processes in a cloud-native, AI-driven environment.

You will plan risk-based IT/audit activities, evaluate control effectiveness, manage findings end-to-end, and lead global compliance programs across ISO/IEC standards and SOC 2.

Qualifications

  • 6+ years of hands-on experience in IT audit, information security, risk and compliance.
  • Product Security & Secure SDLC: evaluate software engineering processes from an audit and assurance perspective.
  • Technical Fluency: understand cloud infrastructure, IAM, SIEM, and CI/CD pipelines.
  • Framework Expertise: ISO/IEC 27001, 27701, SOC 2 Type 2, NIST frameworks including audit coordination.
  • Strategic Execution: translate international standards into scalable processes.
  • Regulatory Knowledge: GDPR, KVKK, CCPA and third-party risk management.
  • Communication & Influence: strong English, write clear policies and influence stakeholders.
  • Nice to have: ISACA certifications (CISA, CISM, CRISC) and CSA STAR experience.

Responsibilities

  • Plan and execute risk-based IT and internal audits focusing on secure SDLC and AI security.
  • Evaluate and improve security controls and governance policies.
  • Manage audit findings end-to-end with sustainable remediation.
  • Lead global compliance programs (ISO/IEC 27001, 22301, 27701, SOC 2, NIST CSF) for audit readiness.
  • Support Third-Party Risk Management through SaaS security assessments.
  • Define and track audit/compliance metrics for leadership reporting.
  • Assess privacy and risk of emerging technologies (AI/ML) for secure adoption.

Skills

6+ years experience
Product Security
Secure SDLC
Cloud infrastructure
ISO/IEC 27001
SOC 2 Type 2
NIST frameworks
CISA
CISM
CRISC
CSA STAR

Job description

About The Role

Most traditional auditor roles ask you to prove a company is secure at least once a year. At Picus, continuous security validation is our product.


We are seeking a Senior Technology Risk & Audit Specialist to strengthen our security governance, risk, and compliance capabilities at scale. In this role, you will run assurance the way our customers run security: continuously, with evidence, and side-by-side dominantly with engineering teams. You will own our global certification programs, act as a strategic advisor to our technology teams, and help govern the AI agents at the heart of our platform. Beyond audit execution, you will act as a strategic advisor to business and technology teams, shaping scalable and risk-aware processes in a cloud-native and AI-driven environment. We want you to be the person teams come to before they build, not after.


What You Bring


  • 6+ years of hands-on experience in IT audit, information security, risk and compliance management, preferably within a SaaS, cloud-native, or fast-growing technology environment.

  • Product Security & Secure SDLC: Proven ability to evaluate software engineering processes from an audit and assurance perspective, covering CI/CD pipeline controls, secure development practices, vulnerability management, software supply chain security, and SBOM governance.

  • Technical Fluency: You understand how cloud infrastructure, IAM, SIEM, and CI/CD pipelines actually work, allowing you to collaborate effectively with engineers in their own language.

  • Framework Expertise: Deep, hands-on experience with ISO/IEC standards (particularly 27001 and 27701), SOC 2 Type 2 and NIST frameworks, including preparation, audit coordination, and evidence management.

  • Strategic Execution: The ability to turn international standards into practical, scalable processes that enable innovation rather than slowing it down.

  • Regulatory Knowledge: Practical understanding of international privacy regulations (e.g., GDPR, KVKK, CCPA) and third-party risk management (TPRM) practices.

  • Communication & Influence: Clear written and spoken English. You can write policies that are easy to understand and advise cross-functional stakeholders, driving control improvements without relying purely on formal authority.

  • ISO/IEC 27001, 22301, 27701, 20000-1 and 42001 LA certifications (nice to have),

  • ISACA certifications such as CISA (most preferred), CISM, or CRISC, AAIA, AAISM, or AAIR (nice to have),

  • Hands-on experience with SOC 2, NIST, and CSA STAR reporting frameworks (nice to have),

  • Last but not least, we expect you to bring the team spirit that we value the most!


What You'll Do


  • Plan and execute risk-based IT and internal audits, with a strong focus on secure SDLC, software engineering processes, cloud infrastructure, and AI security domains,

  • Evaluate and enhance the effectiveness of security and governance controls, driving continuous improvement across policies and processes,

  • Manage audit and security vulnerability findings end-to-end, ensuring sustainable remediation and measurable control improvements,

  • Lead and oversee global compliance programs (ISO/IEC 27001, 22301, 27701, 20000-1, SOC 2, NIST CSF, CSA STAR) to maintain continuous audit readiness,

  • Actively support the Third-Party Risk Management (TPRM) program by participating in SaaS security assessments and vendor due diligence,

  • Define and track key audit and compliance metrics, reporting insights to leadership and relevant stakeholders,

  • Assess the risk and privacy impact of emerging technologies (AI, ML, and automation), guiding engineering teams on secure adoption practices.




About Picus

Picus Security is an exposure validation company. One platform proves what attackers can exploit and what your defenses stop, turning every exposure into a defensible decision, autonomously and at the machine speed today's AI threats demand.


Picus validates attack surfaces, exposures, and security controls as one continuous loop: validate, decide, fix, re-validate. Instead of ranking findings by severity score, Picus proves which exposures are genuinely exploitable in your environment, including the business-critical, restricted, and air-gapped assets a live exploit can never safely touch, so teams act on what truly matters and resolve each exposure into a clear call to patch, mitigate, monitor, or accept with evidence.


The Picus Platform spans Autonomous Penetration Testing, Exposure Validation, and Breach and Attack Simulation, unified by Picus Swarm, a swarm of AI agents that runs the whole validation loop continuously. It reaches across on-prem, hybrid cloud, and endpoint environments, with 75+ integrations that ingest from scanners like Tenable and Wiz and operationalize through your EDR, SIEM, firewall, and ticketing tools.


The pioneer of Breach and Attack Simulation, Picus proves and improves the security controls you already own, doubling control effectiveness within three months. Picus holds a 95% recommendation rate, 4.9 on G2, and 4.8 on Gartner Peer Insights, and is the #1 Leader on Frost Radar for Automated Security Validation.




Working at Picus

Fascinating work - a chance to shape and lead an exciting, fast-growing cybersecurity segment. Security Validation is a concept that helps organizations evaluate their security posture in a continuous, automated, and repeatable way. This approach allows for the identification of imminent threats, provides recommended actions, and produces valuable metrics about cyber-risk levels.


Unlimited opportunity! We are growing. At Picus, you'll be provided with as much responsibility as you can handle - new career development opportunities constantly arise given our rate of growth.


Global exposure - Get a lot of experience working not only in a fast-growing startup but also interacting with customers all around the world.


Be part of a global remote team that is taking on Exposure Validation and a growing market segment.


We are an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to age, sex, race, color, national origin, religious belief, gender or gender reassignment, sexual orientation, marriage or civil partnership, pregnancy and maternity, disability, protected veteran status, or any other characteristic protected by International law. Upon conditional offer of employment, candidates are required to complete reference and identity checks in line with local labor laws and as per the Company’s employment policy.


Picus Security processes candidates' personal data in accordance with applicable data protection laws. For detailed information on how your personal data is processed during the recruitment process, please review our Candidate Privacy Notice.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Solution Architect
Solution Architect

Picus Security Inc. • Çankaya

On-site
TRY 600,000 - 900,000
Solution Architect
Solution Architect

Picus Security Inc. • Çankaya

Remote
TRY 400,000 - 700,000
Senior Tech Risk & Audit Leader (Remote)
Senior Tech Risk & Audit Leader (Remote)

Picus Security Inc. • Çankaya

Remote
TRY 5,897,000 - 8,845,000
Information Security Engineer - (Remote)
Information Security Engineer - (Remote)

Insider One • Turkey

Remote
TRY 300,000 - 540,000
Monthly meal allowance
Private health insurance
Learning resources access
Information Security Engineer - (Remote)
Information Security Engineer - (Remote)

insiderOne • Turkey

Remote
TRY 450,000 - 750,000
Monthly meal allowance
Private health insurance
Learning & development access
+6
Senior Security Engineer - Red Team (Remote)
Senior Security Engineer - Red Team (Remote)

Insider One • Fatih

Remote
TRY 600,000 - 900,000
Monthly meal allowance
Private health insurance
ESOP program
+1
Senior Cyber Security Specialist
Senior Cyber Security Specialist

GİZLİ • Fatih

On-site
TRY 350,000 - 650,000
Cyber Security Architect
Cyber Security Architect

Aygaz AS • Fatih

On-site
TRY 400,000 - 700,000
Senior Cybersecurity Solutions Architect (Pre-Sales)
Senior Cybersecurity Solutions Architect (Pre-Sales)

Picus Security Inc. • Çankaya

On-site
TRY 600,000 - 900,000
Lead GCP DevOps Engineer at EPAM Systems
Lead GCP DevOps Engineer at EPAM Systems

EPAM Systems Inc • Turkey

On-site
TRY 5,897,000 - 8,845,000
Extra leave days
Referral bonuses
Private health insurance
+1