Picus Security
Technology
SeniorInformationSystemsAuditor
Neural analysis suggests this role is
optimal for Senior candidates.
“Senior Information Systems Auditor at Picus Security. Skills: Information Systems Audit, Compliance Programs, Risk Management. Lead global compliance programs. Maintain continuous audit readiness”
What You'll Achieve.
Sustainable remediation; Measurable control improvements
Industry & Context.
What They're Looking For.
Must Have
3+ years of hands-on experience in audit, compliance, risk management, or information security, Hands-on experience with ISO/IEC standards (27001, 27701, 22301, 20000-1) and SOC 2, Experience advising cross-functional stakeholders, Practical knowledge of international security and privacy regulations (e.g., GDPR, CCPA), Experience supporting or managing Third-Party Risk Management (TPRM), Proven ability to manage multiple audits and compliance initiatives simultaneously, Verbal and written communication skills in English
Nice to Have
ISO 27001, 22301, 27701, 20000-1 LA, ISACA certifications such as CISA, CISM, or CRISC, Experience with SOC 2, NIST, CSA STAR reporting frameworks, ITIL certification
What You'll Do.
Lead global compliance programs
Maintain continuous audit readiness
Plan IT and internal audits
Execute IT and internal audits
Focus on software engineering processes
Focus on cloud infrastructure
Focus on AI security domains
Evaluate security controls
Enhance security controls
Drive continuous improvement
Provide security and compliance input
Manage audit findings
Manage security vulnerability findings
Ensure sustainable remediation
Ensure measurable control improvements
Support Third-Party Risk Management program
Participate in SaaS security assessments
Participate in vendor due diligence
Define compliance metrics
Track compliance metrics
Report insights to leadership
Assess risk impact of emerging technologies
Assess privacy impact of emerging technologies
Guide engineering teams on secure adoption
How You'll Work.
Team & Collaboration
Cross-functional stakeholders; Engineering teams
Communication Scope
Written communication; Verbal communication; Policy writing
Full Job Description
## Description Are you passionate about technology and enjoy explaining complex solutions in a way that everybody gets excited? If so, read on! About Picus Picus Security, the leading security validation company, gives organizations a clear picture of their cyber risk based on business context. Picus transforms security practices by correlating, prioritizing, and validating exposures across siloed findings so teams can focus on critical gaps and high-impact fixes. With Picus, security teams can quickly take action with one-click mitigations to stop more threats with less effort. The Picus Security Validation Platform easily reaches across on-prem environments, hybrid clouds and endpoints coupled with Numi AI to provide exposure validation. The pioneer of Breach and Attack Simulation, Picus delivers award-winning threat-centric technology that allows teams to pinpoint fixes worth pursuing, offering a 98% recommendation in Gartner Peer Review. Picus is headquartered in Ankara, with a regional office in Istanbul, but our team is remote across Türkiye. Please note that all CVs must be submitted in English. ## What You'll Do Lead and oversee global compliance programs (ISO/IEC 27001, 22301, 27701, 20000-1, SOC 2, NIST CSF, CSA STAR) to maintain continuous audit readiness Plan and execute risk-based IT and internal audits, with a strong focus on secure SDLC, software engineering processes, cloud infrastructure, and AI security domains Evaluate and enhance the effectiveness of security and governance controls, driving continuous improvement across policies and processes Contribute to RFPs and security questionnaires with accurate and strategic security and compliance input Manage audit and security vulnerability findings end-to-end, ensuring sustainable remediation and measurable control improvements Actively support the Third-Party Risk Management (TPRM) program by participating in SaaS security assessments and vendor due diligence Define and track key audit and
Applying for this Senior Information Systems Auditor role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Lever
- Lever uses a streamlined one-page form — apply in under 5 minutes.
- LinkedIn import works well; review parsed data before submitting.
- The cover letter field is optional but visible to reviewers — use it to differentiate.
- Referral codes from employees can significantly boost visibility of your application.
ANONYMOUS · UNFILTERED
What do employees actually say about Picus Security?
Real rants from real employees. Read before you apply.