Senior Technology Risk – Audit Specialist

Posted 1 day ago

This is a fully remote position, open to applicants in Turkey.

📋 Description

• Enhance the security governance, risk, and compliance capabilities of Picus Security on a large scale.

• Conduct ongoing, evidence-based assurance in collaboration with engineering teams.

• Take ownership of global certification initiatives.

• Provide guidance to technology, business, and engineering teams on scalable, risk-aware procedures.

• Plan and implement risk-based IT and internal audits concentrating on secure SDLC, software engineering, cloud infrastructure, and AI security.

• Assess and refine security and governance controls while promoting continuous improvement.

• Oversee audit and security vulnerability findings through sustainable remediation efforts.

• Lead global compliance initiatives, including ISO/IEC 27001, 22301, 27701, 20000-1, SOC 2, NIST CSF, and CSA STAR.

• Assist in Third-Party Risk Management via SaaS security evaluations and vendor due diligence.

• Establish and monitor audit and compliance metrics, providing insights to leadership and stakeholders.

• Evaluate the risk and privacy implications of AI, ML, and automation, and advise engineering teams on secure incorporation.


⛳️ Requirements

• A minimum of 6 years of practical experience in IT audit, information security, risk, and compliance management.

• Ideally, experience within a SaaS, cloud-native, or rapidly expanding technology environment.

• Demonstrated capability to assess software engineering processes from an audit and assurance viewpoint.

• Familiarity with CI/CD pipeline controls, secure development practices, vulnerability management, software supply chain security, and SBOM governance.

• Knowledge of cloud infrastructure, IAM, SIEM, and CI/CD pipelines.

• Extensive, hands-on experience with ISO/IEC standards, especially 27001 and 27701.

• Comprehensive, hands-on experience with SOC 2 Type 2 and NIST frameworks, including preparation, audit coordination, and evidence management.

• Ability to translate international standards into actionable, scalable processes.

• Practical understanding of GDPR, KVKK, CCPA, and third-party risk management methodologies.

• Proficient in written and spoken English.

• Capability to create clear policies and advise cross-functional stakeholders.

• ISO/IEC 27001, 22301, 27701, 20000-1, and 42001 LA certifications are a plus.

• ISACA certifications such as CISA, CISM, CRISC, AAIA, AAISM, or AAIR are advantageous.

• Practical experience with SOC 2, NIST, and CSA STAR reporting frameworks is an asset.

• A team-oriented mindset.


🏝️ Benefits

• Engaging work with the opportunity to shape and lead an exciting, fast-growing cybersecurity sector.

• Opportunities for career development.

• Global exposure through interactions with customers worldwide.

• Work within a global remote team.

• Commitment to equal opportunity employment.

• Reference and identity checks conducted in accordance with local labor laws and company policy.

• Personal data will be processed in compliance with applicable data protection regulations.

People also viewed

Centene Corporation22 hours ago

Manager, Risk Adjustment, MLTC-MAP

US flagNew York OnlyFull-timeRisk$87.7k – $157.8k/year
ApplyView job
Kindred23 hours ago

Trust & Safety Manager, Policy & Risk Insights

US flagUnited States OnlyFull-timeRisk$115k – $165k/year
ApplyView job
Sezzle1 day ago

Chief Risk Officer

US flagNevada, +1 more stateFull-timeRisk
ApplyView job
Sentry1 day ago

Risk Control Consultant

US flagNorth Carolina, +1 more stateFull-timeRisk$68.1k – $123.6k/year
ApplyView job
American Cancer Society1 day ago

Principal, Corporate Governance – Board Engagement

US flagIllinois OnlyFull-timeRisk$138k – $150k/year
ApplyView job
knowmad mood1 day ago

Ingeniero/a Cloud Senior, Azure – Cloud Governance

ES flagSpain OnlyFull-timeRisk
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers