
51 - 200 employees
🔒 Cybersecurity
💰 Corporate Round on 2022-05
Cybersecurity
Picus Security is a company that specializes in security validation and exposure management solutions. Their platform conducts breach and attack simulations, automated penetration testing, and adversarial exposure validation to optimize and measure the effectiveness of security controls for detection and prevention. Picus helps organizations enhance their cybersecurity posture by providing a comprehensive analysis of vulnerabilities through continuous threat exposure management. They also offer educational resources on security operations and advanced threat intelligence to help teams stay ahead of evolving threats.
🔥 12 minutes ago
Improve your chances of getting an interview by checking your resume score before you apply.

51 - 200 employees
🔒 Cybersecurity
💰 Corporate Round on 2022-05
Cybersecurity
Picus Security is a company that specializes in security validation and exposure management solutions. Their platform conducts breach and attack simulations, automated penetration testing, and adversarial exposure validation to optimize and measure the effectiveness of security controls for detection and prevention. Picus helps organizations enhance their cybersecurity posture by providing a comprehensive analysis of vulnerabilities through continuous threat exposure management. They also offer educational resources on security operations and advanced threat intelligence to help teams stay ahead of evolving threats.
• Plan and execute risk-based IT and internal audits focused on secure SDLC, software engineering processes, cloud infrastructure, and AI security domains • Evaluate and enhance security and governance controls, driving continuous improvement across policies and processes • Manage audit and security vulnerability findings end-to-end, ensuring sustainable remediation and measurable control improvements • Lead and oversee global compliance programs including ISO/IEC 27001, 22301, 27701, 20000-1, SOC 2, NIST CSF, and CSA STAR • Maintain continuous audit readiness and global certification readiness • Support the Third-Party Risk Management program through SaaS security assessments and vendor due diligence • Define and track audit and compliance metrics and report insights to leadership and stakeholders • Assess the risk and privacy impact of emerging technologies, including AI, ML, and automation • Advise engineering teams on secure technology adoption practices • Strengthen governance, risk, and compliance capabilities, control maturity, and security and privacy practices across the organization
• 5+ years of hands-on experience in audit, compliance, risk management, or information security, preferably within a SaaS, cloud-native, or technology-driven environment • Hands-on experience with ISO/IEC standards (27001, 27701, 22301, 20000-1) and SOC 2, including preparation, audit coordination, and evidence management • Experience advising cross-functional stakeholders and influencing control improvements in dynamic technology environments • Practical knowledge of international security and privacy regulations, including GDPR and CCPA • Experience supporting or managing Third-Party Risk Management (TPRM), vendor due diligence, and customer-facing compliance processes • Ability to manage multiple audits and compliance initiatives simultaneously in a fast-paced environment • Strong verbal and written communication skills in English, including documentation and policy writing • Preferred certifications: ISO 27001, 22301, 27701, 20000-1 LA • Preferred certifications: CISA, CISM, or CRISC • Experience with SOC 2, NIST, and CSA STAR reporting frameworks • ITIL certification is nice-to-have • Candidates are required to complete reference and identity checks upon conditional offer in line with local labor laws and company policy
• Fascinating work and opportunity to shape and lead an exciting, fast-growing cybersecurity segment • Career development opportunities and increased responsibility • Global exposure and interaction with customers around the world • Global remote team environment • Equal opportunity employment • Reference and identity checks in line with local labor laws and company policy upon conditional offer • Candidate personal data processed in accordance with applicable data protection laws
Apply Now