Jobiglo

No results.

Information Systems Auditor

Picus Security · Ankara

New Remote
Remote Senior 🇬🇧 English
ISO/IEC 27001 SOC 2 NIST CSF CSA STAR Secure SDLC CI/CD pipeline controls vulnerability management software supply chain security SBOM governance TPRM GDPR CCPA

Job description

About the role

Picus Security is seeking an Information Systems Auditor to strengthen governance, risk and compliance capabilities across its fast‑growing cybersecurity platform. The role combines audit execution with strategic advisory to embed a proactive security and privacy mindset.

Key responsibilities

  • Plan and execute risk‑based IT and internal audits focusing on secure SDLC, cloud infrastructure and AI security.
  • Lead and oversee global compliance programs (ISO/IEC 27001, 22301, 27701, 20000‑1, SOC 2, NIST CSF, CSA STAR) to maintain continuous audit readiness.
  • Manage audit and security vulnerability findings end‑to‑end, ensuring sustainable remediation and measurable control improvements.
  • Support third‑party risk management by conducting SaaS security assessments and vendor due diligence.
  • Define and track audit and compliance metrics, reporting insights to leadership and relevant stakeholders.

Required profile

  • 5+ years of hands‑on experience in audit, compliance, risk management or information security, preferably in a SaaS or cloud‑native environment.
  • Proven experience evaluating product security and Secure Software Development Lifecycle practices, including CI/CD pipeline controls and software supply‑chain security.
  • Strong knowledge of international security and privacy regulations such as GDPR and CCPA.
  • Experience managing multiple audits and compliance initiatives simultaneously in a fast‑paced setting.
  • Excellent written and verbal communication skills in English.

Required skills

  • ISO/IEC 27001, 27701, 22301, 20000‑1 standards.
  • SOC 2 audit coordination and evidence management.
  • NIST Cybersecurity Framework.
  • CSA STAR reporting.
  • Secure SDLC, CI/CD pipeline controls, vulnerability management.
  • Software supply‑chain security and SBOM governance.
  • Cloud infrastructure security concepts (AWS, Azure, GCP).
  • Third‑party risk management (TPRM) and vendor due diligence.
  • GDPR and CCPA compliance knowledge.

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec Picus Security.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Explore further

Salaries, guides and searches in Türkiye.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

By continuing, you accept our terms of use.

Already have an account? Login

💬 Chat with us on Telegram Chat on WhatsApp

Published 4 saat önce

Expires 1 ay sonra

3 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

Picus Security

Ankara