Most traditional auditor roles ask you to prove a company is secure at least once a year. At Picus, continuous security validation is our product.
We are seeking a Senior Technology Risk & Audit Specialist to strengthen our security governance, risk, and compliance capabilities at scale. In this role, you will run assurance the way our customers run security: continuously, with evidence, and side-by-side dominantly with engineering teams. You will own our global certification programs, act as a strategic advisor to our technology teams, and help govern the AI agents at the heart of our platform. Beyond audit execution, you will act as a strategic advisor to business and technology teams, shaping scalable and risk-aware processes in a cloud-native and AI-driven environment. We want you to be the person teams come to before they build, not after.
Picus Security is an exposure validation company. One platform proves what attackers can exploit and what your defenses stop, turning every exposure into a defensible decision, autonomously and at the machine speed today's AI threats demand.
Picus validates attack surfaces, exposures, and security controls as one continuous loop: validate, decide, fix, re-validate. Instead of ranking findings by severity score, Picus proves which exposures are genuinely exploitable in your environment, including the business-critical, restricted, and air-gapped assets a live exploit can never safely touch, so teams act on what truly matters and resolve each exposure into a clear call to patch, mitigate, monitor, or accept with evidence.
The Picus Platform spans Autonomous Penetration Testing, Exposure Validation, and Breach and Attack Simulation, unified by Picus Swarm, a swarm of AI agents that runs the whole validation loop continuously. It reaches across on-prem, hybrid cloud, and endpoint environments, with 75+ integrations that ingest from scanners like Tenable and Wiz and operationalize through your EDR, SIEM, firewall, and ticketing tools.
The pioneer of Breach and Attack Simulation, Picus proves and improves the security controls you already own, doubling control effectiveness within three months. Picus holds a 95% recommendation rate, 4.9 on G2, and 4.8 on Gartner Peer Insights, and is the #1 Leader on Frost Radar for Automated Security Validation.
Fascinating work - a chance to shape and lead an exciting, fast-growing cybersecurity segment. Security Validation is a concept that helps organizations evaluate their security posture in a continuous, automated, and repeatable way. This approach allows for the identification of imminent threats, provides recommended actions, and produces valuable metrics about cyber-risk levels.
Unlimited opportunity! We are growing. At Picus, you'll be provided with as much responsibility as you can handle - new career development opportunities constantly arise given our rate of growth.
Global exposure - Get a lot of experience working not only in a fast-growing startup but also interacting with customers all around the world.
Be part of a global remote team that is taking on Exposure Validation and a growing market segment.
We are an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to age, sex, race, color, national origin, religious belief, gender or gender reassignment, sexual orientation, marriage or civil partnership, pregnancy and maternity, disability, protected veteran status, or any other characteristic protected by International law. Upon conditional offer of employment, candidates are required to complete reference and identity checks in line with local labor laws and as per the Company’s employment policy.
Picus Security processes candidates' personal data in accordance with applicable data protection laws. For detailed information on how your personal data is processed during the recruitment process, please review our Candidate Privacy Notice.

Picus Security is the pioneer of Breach and Attack Simulation (BAS) and Adversarial Exposure Validation (AEV).
We enable organizations to validate effectiveness, prioritize real risk, and act faster with evidence, giving defenders clarity on what attackers can actually exploit and helping them strengthen resilience and improve performance.
Our unified exposure platform combines exposure assessment, security control validation, and exposure validation to provide a complete view of security effectiveness. Picus safely simulates real attack techniques and adversarial TTPs across network, endpoint, and cloud environments, enabling organizations to measure control performance and prioritize what truly matters.
Through our Exposure Score, teams can instantly identify the <2% of vulnerabilities that remain exploitable while deprioritizing the rest. This evidence-based approach helps organizations cut patch backlogs by 86%, reduce mean time to remediate (MTTR) from 74 to 14 days, and strengthen resilience through continuous validation.
Recognized by Gartner Peer Insights™ with a 98% willingness to recommend (the highest in the Adversarial Exposure Validation category), Picus Security is trusted by enterprises worldwide to validate effectiveness, optimize investments, and prove cyber readiness with confidence.
Visit picussecurity.com to explore how Picus Security redefines exposure management through validation.