Senior Technology Risk & Audit Specialist
SeniorOn-site (Ankara)Salary undisclosed
Required Skills
CI/CD
Job Description
About The Role
Most traditional auditor roles ask you to prove a company is secure at least once a year. At Picus, continuous security validation is our product.
We are seeking a Senior Technology Risk & Audit Specialist to strengthen our security governance, risk, and compliance capabilities at scale. In this role, you will run assurance the way our customers run security: continuously, with evidence, and side-by-side dominantly with engineering teams. You will own our global certification programs, act as a strategic advisor to our technology teams, and help govern the AI agents at the heart of our platform. Beyond audit execution, you will act as a strategic advisor to business and technology teams, shaping scalable and risk-aware processes in a cloud-native and AI-driven environment. We want you to be the person teams come to before they build, not after.
What You Bring
6+ years of hands-on experience in IT audit, information security, risk and compliance management, preferably within a SaaS, cloud-native, or fast-growing technology environment.
Product Security & Secure SDLC: Proven ability to evaluate software engineering processes from an audit and assurance perspective, covering CI/CD pipeline controls, secure development practices, vulnerability management, software supply chain security, and SBOM governance.
Technical Fluency: You understand how cloud infrastructure, IAM, SIEM, and CI/CD pipelines actually work, allowing you to collaborate effectively with engineers in their own language.
Framework Expertise: Deep, hands-on experience with ISO/IEC standards (particularly 27001 and 27701), SOC 2 Type 2 and NIST frameworks, including preparation, audit coordination, and evidence management.
Strategic Execution: The ability to turn international standards into practical, scalable processes that enable innovation rather than slowing it down.
Regulatory Knowledge: Practical understanding of international privacy regulations (e.g., GDPR, KVKK, CCPA) and third-party risk management (TPRM) practices.
Communication & Influence: Clear written and spoken English. You can write policies that are easy to understand and advise cross-functional stakeholders, driving control improvements without relying purely on formal authority.
ISO/IEC 27001, 22301, 27701, 20000-1 and 42001 LA certifications (nice to have),
ISACA certifications such as CISA (most preferred), CISM, or CRISC, AAIA, AAISM, or AAIR (nice to have),
Hands-on experience with SOC 2, NIST, and CSA STAR reporting frameworks (nice to have),
Last but not least, we expect you to bring the team spirit that we value the most!
What You'll Do
Plan and execute risk-based IT and internal audits, with a strong focus on secure SDLC, software engineering processes, cloud infrastructure, and AI security domains,
Evaluate and enhance the effectiveness of security and governance controls, driving continuous improvement across policies and processes,
Manage audit and security vulnerability findings end-to-end, ensuring sustainable remediation and measurable control improvements,
Lead and oversee global compliance programs (ISO/IEC 27001, 22301, 27701, 20000-1, SOC 2, NIST CSF, CSA STAR) to maintain continuous audit readiness,
Actively support the Third-Party Risk Management (TPRM) program by participating in SaaS security assessments and vendor due diligence,
Define and track key audit and compliance metrics, reporting insights to leadership and relevant stakeholders,
Assess the risk and privacy impact of emerging technologies (AI, ML, and automation), guiding engineering teams on secure adoption practices.
Ready to apply? Optimize your CV for this specific jobAI customizes your experience bullets and increases chances to get hired.