远程工作雷达

信息系统审计师

Information Systems Auditor

其他限定地区(需当地身份)
公司Picus
薪资未公开
工作地点Turkey
地域资格限定地区(需当地身份)
时区要求日间重叠约 4 小时,基本正常作息
用工类型Full Time
发布时间今天
数据来源Himalayas
前往 Himalayas 查看并投递 →
注意地域限制:该职位明确限定在 Turkey 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

你是否对技术充满热情,喜欢以让所有人都感到兴奋的方式解释复杂解决方案?如果是,继续阅读!

关于 Picus

Picus Security 是一家暴露验证公司。一个平台可以证明攻击者可以利用什么,你的防御能阻止什么,将每个暴露点转化为可辩护的决策,自主且以当今 AI 威胁所需的机器速度进行。

Picus 将攻击面、暴露点和安全控制作为持续循环进行验证:验证、决定、修复、重新验证。而不是按严重性评分对发现进行排序,Picus 会证明哪些暴露点在你的环境中确实可被利用,包括那些业务关键、受限和隔离的资产,这些资产无法安全地被实时利用,因此团队可以针对真正重要的问题采取行动,并将每个暴露点转化为明确的补丁、缓解、监控或接受的指令。

Picus 平台涵盖自主渗透测试、暴露验证和漏洞与攻击模拟,由 Picus Swarm(一群 AI 代理)统一运行整个验证循环。它覆盖本地、混合云和终端环境,拥有 75 多个集成,可以从 Tenable 和 Wiz 等扫描器中获取数据,并通过你的 EDR、SIEM、防火墙和工单工具进行操作。

作为漏洞与攻击模拟的先驱,Picus 证明并改进了你已有的安全控制,三个月内使控制效果翻倍。Picus 在 G2 上获得 95% 的推荐率,G2 评分为 4.9,Gartner Peer Insights 评分为 4.8,并在 Frost Radar 自动化安全验证领域排名第一。

关于该职位

我们正在寻找一名信息系统审计师加入我们快速发展的网络安全公司,扩大我们的治理、风险和合规能力。该职位在保持全球认证准备、提升控制成熟度以及在整个组织中嵌入主动的安全和隐私意识方面起着关键作用。除了执行审计外,你还将作为业务和技术团队的战略顾问,塑造在云原生和 AI 驱动环境中的可扩展且风险意识强的流程。你将参与我们治理框架的持续演进,确保符合国际标准,同时推动创新和可持续增长。该职位直接支持监管信心,并加强全球客户对 Picus 的信任。

你将负责

  • 制定并执行基于风险的审计计划
查看英文原文

Are you passionate about technology and enjoy explaining complex solutions in a way that everybody gets excited? If so, read on!

About Picus

Picus Security is an exposure validation company. One platform proves what attackers can exploit and what your defenses stop, turning every exposure into a defensible decision, autonomously and at the machine speed today's AI threats demand.

Picus validates attack surfaces, exposures, and security controls as one continuous loop: validate, decide, fix, re-validate. Instead of ranking findings by severity score, Picus proves which exposures are genuinely exploitable in your environment, including the business-critical, restricted, and air-gapped assets a live exploit can never safely touch, so teams act on what truly matters and resolve each exposure into a clear call to patch, mitigate, monitor, or accept with evidence.

The Picus Platform spans Autonomous Penetration Testing, Exposure Validation, and Breach and Attack Simulation, unified by Picus Swarm, a swarm of AI agents that runs the whole validation loop continuously. It reaches across on-prem, hybrid cloud, and endpoint environments, with 75+ integrations that ingest from scanners like Tenable and Wiz and operationalize through your EDR, SIEM, firewall, and ticketing tools.

The pioneer of Breach and Attack Simulation, Picus proves and improves the security controls you already own, doubling control effectiveness within three months. Picus holds a 95% recommendation rate, 4.9 on G2, and 4.8 on Gartner Peer Insights, and is the #1 Leader on Frost Radar for Automated Security Validation.

About The Role

We are seeking an Information Systems Auditor to join our fast-growing cybersecurity company and strengthen our governance, risk, and compliance capabilities at scale. This role plays a critical part in maintaining global certification readiness, enhancing control maturity, and embedding a proactive security and privacy mindset across the organization. Beyond audit execution, you will act as a strategic advisor to business and technology teams, shaping scalable and risk-aware processes in a cloud-native and AI-driven environment. You will contribute to the continuous evolution of our governance framework, ensuring alignment with international standards while enabling innovation and sustainable growth. This position directly supports regulatory confidence and reinforces the trust our global customers place in Picus.

What You'll Do

  • Plan and execute risk-based IT and internal audits, with a strong focus on secure SDLC, software engineering processes, cloud infrastructure, and AI security domains,
  • Evaluate and enhance the effectiveness of security and governance controls, driving continuous improvement across policies and processes,
  • Manage audit and security vulnerability findings end-to-end, ensuring sustainable remediation and measurable control improvements,
  • Lead and oversee global compliance programs (ISO/IEC 27001, 22301, 27701, 20000-1, SOC 2, NIST CSF, CSA STAR) to maintain continuous audit readiness,
  • Actively support the Third-Party Risk Management (TPRM) program by participating in SaaS security assessments and vendor due diligence,
  • Define and track key audit and compliance metrics, reporting insights to leadership and relevant stakeholders,
  • Assess the risk and privacy impact of emerging technologies (AI, ML, and automation), guiding engineering teams on secure adoption practices.

What You Have

  • 5+ years of hands-on experience in audit, compliance, risk management, or information security, preferably within a SaaS, cloud-native, or technology-driven environment,
  • Hands-on experience with ISO/IEC standards (27001, 27701, 22301, 20000-1) and SOC 2, including preparation, audit coordination, and evidence management,
  • Experience advising cross-functional stakeholders and influencing control improvements in dynamic technology environments,
  • Practical knowledge of international security and privacy regulations (e.g., GDPR, CCPA) and related compliance practices,
  • Experience supporting or managing Third-Party Risk Management (TPRM), vendor due diligence, and customer-facing compliance processes,
  • Proven ability to manage multiple audits and compliance initiatives simultaneously in a fast-paced environment,
  • Strong verbal and written communication skills in English, including documentation and policy writing.

Preferred Certifications:

  • ISO 27001, 22301, 27701, 20000-1 LA
  • ISACA certifications such as CISA, CISM, or CRISC
  • Experience with SOC 2, NIST, CSA STAR reporting frameworks
  • ITIL certification (nice-to-have)

Working at Picus

Fascinating work - a chance to shape and lead an exciting, fast-growing cyber security segment. Security Validation is a concept that helps organizations evaluate their security posture in a continuous, automated, and repeatable way. This approach allows for the identification of imminent threats, provides recommended actions, and produces valuable metrics about cyber-risk levels.

Unlimited opportunity! We are growing. At Picus, you'll be provided with as much responsibility as you can handle - new career development opportunities constantly arise given our rate of growth.

Global exposure - Get a lot of experience working not only in a fast-growing startup but also interact with customers all around the world.

Be part of a global remote team who is taking on Exposure Validation and a growing market segment.

We are an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to age, sex, race, color, national origin, religious belief, gender or gender reassignment, sexual orientation, marriage or civil partnership, pregnancy and maternity, disability, protected veteran status, or any other characteristic protected by International law. Upon conditional offer of employment, candidates are required to complete reference and identity checks in line with local labor laws and as per the Company’s employment policy.

Picus Security processes candidates' personal data in accordance with applicable data protection laws. For detailed information on how your personal data is processed during the recruitment process, please review our Candidate Privacy Notice

Originally posted on Himalayas

本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

← 返回全部职位