
Senior Technology Risk – Audit Specialist
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Turkey.
• Enhance the security governance, risk, and compliance capabilities of Picus Security on a large scale.
• Conduct ongoing, evidence-based assurance in collaboration with engineering teams.
• Take ownership of global certification initiatives.
• Provide guidance to technology, business, and engineering teams on scalable, risk-aware procedures.
• Plan and implement risk-based IT and internal audits concentrating on secure SDLC, software engineering, cloud infrastructure, and AI security.
• Assess and refine security and governance controls while promoting continuous improvement.
• Oversee audit and security vulnerability findings through sustainable remediation efforts.
• Lead global compliance initiatives, including ISO/IEC 27001, 22301, 27701, 20000-1, SOC 2, NIST CSF, and CSA STAR.
• Assist in Third-Party Risk Management via SaaS security evaluations and vendor due diligence.
• Establish and monitor audit and compliance metrics, providing insights to leadership and stakeholders.
• Evaluate the risk and privacy implications of AI, ML, and automation, and advise engineering teams on secure incorporation.
• A minimum of 6 years of practical experience in IT audit, information security, risk, and compliance management.
• Ideally, experience within a SaaS, cloud-native, or rapidly expanding technology environment.
• Demonstrated capability to assess software engineering processes from an audit and assurance viewpoint.
• Familiarity with CI/CD pipeline controls, secure development practices, vulnerability management, software supply chain security, and SBOM governance.
• Knowledge of cloud infrastructure, IAM, SIEM, and CI/CD pipelines.
• Extensive, hands-on experience with ISO/IEC standards, especially 27001 and 27701.
• Comprehensive, hands-on experience with SOC 2 Type 2 and NIST frameworks, including preparation, audit coordination, and evidence management.
• Ability to translate international standards into actionable, scalable processes.
• Practical understanding of GDPR, KVKK, CCPA, and third-party risk management methodologies.
• Proficient in written and spoken English.
• Capability to create clear policies and advise cross-functional stakeholders.
• ISO/IEC 27001, 22301, 27701, 20000-1, and 42001 LA certifications are a plus.
• ISACA certifications such as CISA, CISM, CRISC, AAIA, AAISM, or AAIR are advantageous.
• Practical experience with SOC 2, NIST, and CSA STAR reporting frameworks is an asset.
• A team-oriented mindset.
• Engaging work with the opportunity to shape and lead an exciting, fast-growing cybersecurity sector.
• Opportunities for career development.
• Global exposure through interactions with customers worldwide.
• Work within a global remote team.
• Commitment to equal opportunity employment.
• Reference and identity checks conducted in accordance with local labor laws and company policy.
• Personal data will be processed in compliance with applicable data protection regulations.
Centene Corporation
Kindred
Sentry
Get handpicked remote jobs straight to your inbox weekly.