Назад
Company hidden
4 дня назад

Senior Technology Risk & Audit Specialist (Cybersecurity)

Формат работы
remote (только Turkey)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Turkey
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Technology Risk & Audit Specialist (Cybersecurity): Leading continuous technology risk, audit, and compliance programs for a cloud-native, AI-driven security validation platform with an accent on secure SDLC, cloud infrastructure, privacy, and global certification readiness. Focus on evaluating AI and software engineering risks, managing findings through remediation, and building scalable controls with engineering and business teams.

Location: Remote, associated with Ankara, Turkey

Company

hirify.global develops an exposure validation platform that continuously tests attack surfaces and security controls using autonomous penetration testing, breach and attack simulation, and AI agents.

What you will do

  • Plan and execute risk-based IT and internal audits covering secure SDLC, software engineering, cloud infrastructure, and AI security.
  • Evaluate security and governance controls and drive measurable improvements across policies and processes.
  • Manage audit and vulnerability findings from identification through sustainable remediation.
  • Lead global compliance programs covering ISO/IEC standards, SOC 2, NIST CSF, and CSA STAR.
  • Support third-party risk management through SaaS security assessments and vendor due diligence.
  • Assess the risk and privacy impact of AI, ML, and automation and advise engineering teams on secure adoption.

Requirements

  • 6+ years of hands-on experience in IT audit, information security, risk, and compliance management.
  • Experience evaluating CI/CD controls, secure development practices, vulnerability management, software supply chain security, and SBOM governance.
  • Technical understanding of cloud infrastructure, IAM, SIEM, and CI/CD pipelines.
  • Hands-on expertise with ISO/IEC 27001 and 27701, SOC 2 Type 2, and NIST frameworks.
  • Practical knowledge of GDPR, KVKK, CCPA, and third-party risk management.
  • Clear written and spoken English is required.

Nice to have

  • ISO/IEC 27001, 22301, 27701, 20000-1, or 42001 lead auditor certifications.
  • ISACA certifications such as CISA, CISM, or CRISC, or AAIA, AAISM, or AAIR.
  • Hands-on experience with SOC 2, NIST, and CSA STAR reporting frameworks.

Culture & Benefits

  • Remote work within a global team.
  • Opportunity to shape a growing cybersecurity and exposure validation segment.
  • Broad responsibility and ongoing career development opportunities in a fast-growing company.
  • Interaction with customers and stakeholders around the world.

Hiring process

  • Reference and identity checks are required after a conditional offer, in accordance with local labor laws and company policy.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →