
51 - 200 employees
🔒 Cybersecurity
💰 Corporate Round on 2022-05
Cybersecurity
Picus Security is a company that specializes in security validation and exposure management solutions. Their platform conducts breach and attack simulations, automated penetration testing, and adversarial exposure validation to optimize and measure the effectiveness of security controls for detection and prevention. Picus helps organizations enhance their cybersecurity posture by providing a comprehensive analysis of vulnerabilities through continuous threat exposure management. They also offer educational resources on security operations and advanced threat intelligence to help teams stay ahead of evolving threats.
🔥 15 hours ago
Improve your chances of getting an interview by checking your resume score before you apply.

51 - 200 employees
🔒 Cybersecurity
💰 Corporate Round on 2022-05
Cybersecurity
Picus Security is a company that specializes in security validation and exposure management solutions. Their platform conducts breach and attack simulations, automated penetration testing, and adversarial exposure validation to optimize and measure the effectiveness of security controls for detection and prevention. Picus helps organizations enhance their cybersecurity posture by providing a comprehensive analysis of vulnerabilities through continuous threat exposure management. They also offer educational resources on security operations and advanced threat intelligence to help teams stay ahead of evolving threats.
• Strengthen Picus Security’s security governance, risk, and compliance capabilities at scale • Run continuous, evidence-based assurance alongside engineering teams • Own global certification programs • Advise technology, business, and engineering teams on scalable, risk-aware processes • Plan and execute risk-based IT and internal audits focused on secure SDLC, software engineering, cloud infrastructure, and AI security • Evaluate and improve security and governance controls and drive continuous improvement • Manage audit and security vulnerability findings through sustainable remediation • Lead global compliance programs including ISO/IEC 27001, 22301, 27701, 20000-1, SOC 2, NIST CSF, and CSA STAR • Support Third-Party Risk Management through SaaS security assessments and vendor due diligence • Define and track audit and compliance metrics and report insights to leadership and stakeholders • Assess risk and privacy impacts of AI, ML, and automation and guide engineering teams on secure adoption
• 6+ years of hands-on experience in IT audit, information security, risk and compliance management • Preferably experience within a SaaS, cloud-native, or fast-growing technology environment • Proven ability to evaluate software engineering processes from an audit and assurance perspective • Knowledge of CI/CD pipeline controls, secure development practices, vulnerability management, software supply chain security, and SBOM governance • Understanding of cloud infrastructure, IAM, SIEM, and CI/CD pipelines • Deep, hands-on experience with ISO/IEC standards, particularly 27001 and 27701 • Deep, hands-on experience with SOC 2 Type 2 and NIST frameworks, including preparation, audit coordination, and evidence management • Ability to turn international standards into practical, scalable processes • Practical understanding of GDPR, KVKK, CCPA, and third-party risk management practices • Clear written and spoken English • Ability to write understandable policies and advise cross-functional stakeholders • ISO/IEC 27001, 22301, 27701, 20000-1 and 42001 LA certifications are nice to have • ISACA certifications such as CISA, CISM, CRISC, AAIA, AAISM, or AAIR are nice to have • Hands-on experience with SOC 2, NIST, and CSA STAR reporting frameworks is nice to have • Team spirit
• Fascinating work and opportunity to shape and lead an exciting, fast-growing cybersecurity segment • Career development opportunities • Global exposure through interaction with customers around the world • Global remote team • Equal opportunity employment • Reference and identity checks in line with local labor laws and company policy • Personal data processed in accordance with applicable data protection laws
Apply Now🕒 Yesterday
Shopper Risk Operations Team Lead overseeing fraud prevention and chargeback operations. Managing team performance and improving risk processes for Sezzle’s interest-free installment payments platform.
🕒 September 25
Corporate Governance SME managing entity records, filings, resolutions, and IP administration for World Business Lenders. Supporting governance, structuring, audits, and multinational expansion remotely.