Back to Jobs
Picus Security
Legal & HR Just now

Information Systems Auditor

Picus Security
AnkaraAnkara
Full-time
Not Disclosed
Mid-Level

Job Description

Key Skills Required

Master these to land this role

ComplianceRisk ManagementCybersecuritySOC 2ISO/IEC 27001

Want to know if you're a match for this job?

Calculate My Match Score

About Picus

Picus Security is an exposure validation company. One platform proves what attackers can exploit and what your defenses stop, turning every exposure into a defensible decision, autonomously and at the machine speed today's AI threats demand.

The Picus Platform spans Autonomous Penetration Testing, Exposure Validation, and Breach and Attack Simulation, unified by Picus Swarm, a swarm of AI agents that runs the whole validation loop continuously. It reaches across on-prem, hybrid cloud, and endpoint environments, with 75+ integrations that ingest from scanners like Tenable and Wiz and operationalize through your EDR, SIEM, firewall, and ticketing tools.

The pioneer of Breach and Attack Simulation, Picus proves and improves the security controls you already own, doubling control effectiveness within three months. Picus holds a 95% recommendation rate, 4.9 on G2, and 4.8 on Gartner Peer Insights, and is the #1 Leader on Frost Radar for Automated Security Validation.


About The Role

We are seeking an Information Systems Auditor to join our fast-growing cybersecurity company and strengthen our governance, risk, and compliance capabilities at scale. This role plays a critical part in maintaining global certification readiness, enhancing control maturity, and embedding a proactive security and privacy mindset across the organization. Beyond audit execution, you will act as a strategic advisor to business and technology teams, shaping scalable and risk-aware processes in a cloud-native and AI-driven environment. You will contribute to the continuous evolution of our governance framework, ensuring alignment with international standards while enabling innovation and sustainable growth. This position directly supports regulatory confidence and reinforces the trust our global customers place in Picus.


What You'll Do

  • Plan and execute risk-based IT and internal audits, with a strong focus on secure SDLC, software engineering processes, cloud infrastructure, and AI security domains,
  • Evaluate and enhance the effectiveness of security and governance controls, driving continuous improvement across policies and processes,
  • Manage audit and security vulnerability findings end-to-end, ensuring sustainable remediation and measurable control improvements,
  • Lead and oversee global compliance programs (ISO/IEC 27001, 22301, 27701, 20000-1, SOC 2, NIST CSF, CSA STAR) to maintain continuous audit readiness,
  • Actively support the Third-Party Risk Management (TPRM) program by participating in SaaS security assessments and vendor due diligence,
  • Define and track key audit and compliance metrics, reporting insights to leadership and relevant stakeholders,
  • Assess the risk and privacy impact of emerging technologies (AI, ML, and automation), guiding engineering teams on secure adoption practices.

What You Have

  • 5+ years of hands-on experience in audit, compliance, risk management, or information security, preferably within a SaaS, cloud-native, or technology-driven environment,
  • Hands-on experience with ISO/IEC standards (27001, 27701, 22301, 20000-1) and SOC 2, including preparation, audit coordination, and evidence management,
  • Experience advising cross-functional stakeholders and influencing control improvements in dynamic technology environments,
  • Practical knowledge of international security and privacy regulations (e.g., GDPR, CCPA) and related compliance practices,
  • Experience supporting or managing Third-Party Risk Management (TPRM), vendor due diligence, and customer-facing compliance processes,
  • Proven ability to manage multiple audits and compliance initiatives simultaneously in a fast-paced environment,
  • Strong verbal and written communication skills in English, including documentation and policy writing.

Preferred Certifications:

  • ISO 27001, 22301, 27701, 20000-1 LA
  • ISACA certifications such as CISA, CISM, or CRISC
  • Experience with SOC 2, NIST, CSA STAR reporting frameworks
  • ITIL certification (nice-to-have)

How would you rate this job post?

See what other professionals think about this role.

banner
logo

Picus Security

View Company Profile

Picus Security (operating at picussecurity.com) is a cybersecurity platform engineered for continuous security validation. Founded in 2013 by unknown founders and headquartered in Not specified, Picus Security helps enterprise security teams reduce cyber risk with the Picus Autonomous Exposure Validation Platform. Under the hood, the platform emulates adversaries, prioritizes exposures, verifies compensating controls, and provides a clear picture of cyber risk based on business context. This allows organizations to make informed decisions about their security posture. Backed by $74 million in funding.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More
Information Systems Auditor at Picus Security | HireSkys