What You'll Do
- Manage, support, and oversee compliance activities related to global certifications (e.g., ISO/IEC 27001, 22301, 27701, 20000-1, etc) and regulatory frameworks (i.e., SOC 2, NIST CSF, CSA Star, etc)
- Audit, monitor, and improve policies and processes related to: Information Security, Business Continuity, Privacy Governance and Risk Management
- IT service management
- Cloud application security and SaaS vendor compliance
- Participate in Cloud/SaaS security assessments, risk reviews, and vendor due diligence as part of the TPRM program
- Represent the company in second and third-party audits, including customer audits and cloud vendor evaluations
- Respond to RFPs and customer security questionnaires with accurate and comprehensive compliance input to ensure compliance and mitigate risk
- Maintain, evaluate, and expand upon existing certifications and frameworks to align with business needs and the technology landscape
- Define and track key compliance and audit metrics to measure control effectiveness and report findings to relevant stakeholders
- Support the development and delivery of privacy and information security awareness programs
- Conduct internal audits to assess compliance, identify potential gaps, and recommend and track corrective actions
- Shows genuine interest in emerging technologies such as AI, ML, and automation and stays informed on how these technologies impact risk, privacy, governance, and security frameworks
- Collaborate with business units to ensure process alignment with standards, contracts, and legal requirements.
What You Have
- 3+ years of hands-on experience in audit, compliance, risk management, or information security — ideally within a technology, SaaS, internal controls, or cloud-driven environment
- Experience with ISO/IEC standards (27001, 27701, 22301, 20000-1), ISACA CISA Domains and SOC 2, including preparation, audit coordination, and evidence management
- Familiarity with TPRM programs, vendor due diligence, and customer-facing compliance processes
- Familiarity with relevant international security and privacy related regulations, such as GDPR and CCPA, and compliance processes
- Demonstrated ability to manage multiple audits or compliance projects in parallel
- Strong verbal and written communication skills in English, including documentation and policy writing.
Similar Jobs
What We Do
Picus Security is the pioneer of Breach and Attack Simulation (BAS). The Picus Complete Security Control Validation Platform is trusted by leading organizations worldwide to continuously validate the effectiveness of security controls against cyber-attacks and supply actionable mitigation insights to optimize them.
Picus has offices in North America, Europe and APAC and is supported by a global network of channel and alliance partners.
The company is dedicated to helping security professionals become more threat-centric and via its Purple Academy offers free online training to share the latest offensive and defensive cybersecurity strategies.
Find more here: https://www.picussecurity.com/








