Information Systems Auditor

18 hours, 49 minutes ago
Full-time
Senior
Cybersecurity
Picus Security

Picus Security

Picus Security offers a comprehensive security validation platform that continuously tests and optimizes security controls through automated attack simulations, enabling organizations to proactively identify vulnerabilities and enhance their overall cy...

Professional Services
51-250
Founded 2013
$32M raised

Description

  • Plan and execute risk-based IT and internal audits covering secure SDLC, software engineering, cloud infrastructure, and AI security.
  • Evaluate and improve security and governance controls, policies, and processes.
  • Manage audit and security vulnerability findings through sustainable remediation and measurable control improvements.
  • Lead global compliance programs including ISO/IEC 27001, 22301, 27701, 20000-1, SOC 2, NIST CSF, and CSA STAR.
  • Support Third-Party Risk Management through SaaS security assessments and vendor due diligence.
  • Define and track audit and compliance metrics and report insights to leadership and stakeholders.
  • Assess the risk and privacy impacts of AI, machine learning, and automation technologies.
  • Advise business and engineering teams on secure, risk-aware processes and technology adoption.

Requirements

  • 5+ years of experience in audit, compliance, risk management, or information security, preferably in SaaS, cloud-native, or technology environments.
  • Hands-on experience with ISO/IEC 27001, 27701, 22301, and 20000-1 and SOC 2, including audit preparation, coordination, and evidence management.
  • Experience advising cross-functional stakeholders and influencing control improvements.
  • Knowledge of international security and privacy regulations, including GDPR and CCPA.
  • Experience with Third-Party Risk Management, vendor due diligence, and customer-facing compliance processes.
  • Ability to manage multiple audits and compliance initiatives in a fast-paced environment.
  • Strong written and verbal English communication skills, including documentation and policy writing.
  • Preferred certifications include ISO/IEC Lead Auditor credentials, CISA, CISM, CRISC, or ITIL.
  • Experience with SOC 2, NIST, and CSA STAR reporting frameworks is preferred.

Benefits

  • Global remote-team work environment.
  • Career development opportunities and increasing responsibility in a fast-growing company.
  • Opportunity to work in an emerging cybersecurity market with global customer exposure.
  • Equal opportunity employer.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Regulatory and Start Up Specialist (Portuguese speaker)

Precision For Medicine 1K-5K Pharmaceuticals

Precision for Medicine is seeking a Spain-based Regulatory and Start Up Specialist to coordinate regulatory submissions, site activation, contracts, and budgets for clinical trials across therapeutic areas including rare diseases and oncology.

1 day, 18 hours ago

Compliance Analyst

Coins is seeking a Compliance Analyst in Brazil to manage customer and partner onboarding, strengthen AML/KYC operations, and support compliant expansion across current and future markets.

1 day, 19 hours ago

Compliance Analyst (Corporate Enhanced Due Diligence)

Binance 5K-10K Capital Markets

Binance is hiring an Enhanced Due Diligence professional to oversee high-risk customer reviews, AML/CFT risk assessments, and compliance enhancements across its global cryptocurrency and financial-services ecosystem.

Blockchain
2 days, 18 hours ago

Contract Due Diligence Compliance Analyst

Maxwell 251-1K Banks

Maxwell is seeking a remote Contract Due Diligence Compliance Analyst to review mortgage loan files and fees, validate regulatory compliance, and support accurate transitions to credit review.

2 days, 18 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers