- Location
- Ankara, Turkey
- Workplace
- Remote
- Type
- Full-time
- Department
- Technology - Tech Office
- Seniority
- Senior
- Source
- Lever
Description
About The Role
Most traditional auditor roles ask you to prove a company is secure at least once a year. At Picus, continuous security validation is our product.
We are seeking a Senior Technology Risk & Audit Specialist to strengthen our security governance, risk, and compliance capabilities at scale. In this role, you will run assurance the way our customers run security: continuously, with evidence, and side-by-side dominantly with engineering teams. You will own our global certification programs, act as a strategic advisor to our technology teams, and help govern the AI agents at the heart of our platform. Beyond audit execution, you will act as a strategic advisor to business and technology teams, shaping scalable and risk-aware processes in a cloud-native and AI-driven environment. We want you to be the person teams come to before they build, not after.
What You Bring
- 6+ years of hands-on experience in IT audit, information security, risk and compliance management, preferably within a SaaS, cloud-native, or fast-growing technology environment.
- Product Security & Secure SDLC: Proven ability to evaluate software engineering processes from an audit and assurance perspective, covering CI/CD pipeline controls, secure development practices, vulnerability management, software supply chain security, and SBOM governance.
- Technical Fluency: You understand how cloud infrastructure, IAM, SIEM, and CI/CD pipelines actually work, allowing you to collaborate effectively with engineers in their own language.
- Framework Expertise: Deep, hands-on experience with ISO/IEC standards (particularly 27001 and 27701), SOC 2 Type 2 and NIST frameworks, including preparation, audit coordination, and evidence management.
- Strategic Execution: The ability to turn international standards into practical, scalable processes that enable innovation rather than slowing it down.
- Regulatory Knowledge: Practical understanding of international privacy regulations (e.g., GDPR, KVKK, CCPA) and third-party risk management (TPRM) practices.
- Communication & Influence: Clear written and spoken English. You can write policies that are easy to understand and advise cross-functional stakeholders, driving control improvements without relying purely on formal authority.
- ISO/IEC 27001, 22301, 27701, 20000-1 and 42001 LA certifications (nice to have),
- ISACA certifications such as CISA (most preferred), CISM, or CRISC, AAIA, AAISM, or AAIR (nice to have),
- Hands-on experience with SOC 2, NIST, and CSA STAR reporting frameworks (nice to have),
- Last but not least, we expect you to bring the team spirit that we value the most!
- Plan and execute risk-based IT and internal audits, with a strong focus on secure SDLC, software engineering processes, cloud infrastructure, and AI security domains,
- Evaluate and enhance the effectiveness of security and governance controls, driving continuous improvement across policies and processes,
- Manage audit and security vulnerability findings end-to-end, ensuring sustainable remediation and measurable control improvements,
- Lead and oversee global compliance programs (ISO/IEC 27001, 22301, 27701, 20000-1, SOC 2, NIST CSF, CSA STAR) to maintain continuous audit readiness,
- Actively support the Third-Party Risk Management (TPRM) program by participating in SaaS security assessments and vendor due diligence,
- Define and track key audit and compliance metrics, reporting insights to leadership and relevant stakeholders,
- Assess the risk and privacy impact of emerging technologies (AI, ML, and automation), guiding engineering teams on secure adoption practices.