Logo for Picus Security

Associate Security Research Engineer

Role overview

Qualifications

  • 1–2 years of experience in offensive and/or defensive cybersecurity
  • Some technical writing or a genuine eagerness to build a portfolio
  • Strong proficiency in written and verbal English
  • Curiosity and a drive to keep learning

Responsibilities

  • Continuously research emerging threats, malware, and vulnerability exploitation campaigns
  • Contribute to technical content across blogs, whitepapers, and research papers
  • Develop a deep understanding of the Picus platform and collaborate with various teams
  • Monitor market trends and help turn insights into differentiated technical content

About the company

Picus Security logo

Picus Security

Cybersecurity

Picus Security is the pioneer of Breach and Attack Simulation (BAS). The Picus Complete Security Control Validation Platform is trusted by leading organizations worldwide to continuously validate the effectiveness of security controls against cyber-attacks and supply actionable mitigation insights to optimize them. Picus has offices in North America, Europe and APAC and is supported by a global network of channel and alliance partners. The company is dedicated to helping security professionals become more threat-centric and via its Purple Academy offers free online training to share the latest offensive and defensive cybersecurity strategies. Find more here: https://www.picussecurity.com/

Company details

Company typeScaleup
IndustryCybersecurity
Company size51 - 200

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Are you passionate about technology and enjoy explaining complex solutions in a way that everybody gets excited? If so, read on!
 
About Picus
Picus Security, the leading security validation company, gives organizations a clear picture of their cyber risk based on business context. Picus transforms security practices by correlating, prioritizing, and validating exposures across siloed findings so teams can focus on critical gaps and high-impact fixes. With Picus, security teams can quickly take action with one-click mitigations to stop more threats with less effort.
 
The Picus Security Validation Platform easily reaches across on-prem environments, hybrid clouds and endpoints coupled with Numi AI to provide exposure validation. 
 
The pioneer of Breach and Attack Simulation, Picus delivers award-winning threat-centric technology that allows teams to pinpoint fixes worth pursuing, offering a 98% recommendation in Gartner Peer Review.
 
Picus is headquartered in Ankara, with a regional office in Istanbul, but our team is remote across TΓΌrkiye. Please note that all CVs must be submitted in English.

About Role

We're growing our Technical Marketing Team to support the high growth and global expansion plans of Picus, and we're opening the door for someone at the start of their research-and-content career. In this role, you'll learn to go deep on real-world threats and turn that research into technical content that shows the market what Picus can actually do, surfacing the platform's technical depth in exposure validation, all with the support and mentorship of an experienced team.

It's a role built for growth in two directions at once: you'll start building your own name in the security community through published work and hands-on research, while contributing to how the market understands the category.

Our research is regularly picked up and cited by the wider community, from major news organizations like Reuters, the Associated Press, and Forbes, to specialist security outlets including Dark Reading, BleepingComputer, Infosecurity Magazine, SCWorld, and Help Net Security, as well as community platforms like Hacker News. Our work has also been referenced by industry authorities such as MITRE ATT&CK and Gartner, and cited in high-impact academic journals. As you grow into the role, there will be opportunities to take your work on stage at industry conferences such as Black Hat and GovWare, and at local meetups and user groups.

You'll be constantly challenged to develop your knowledge and skills in cybersecurity and share what you learn with the world, doing meaningful research for a fast-growing cybersecurity company.

Are you an early-career SOC analyst, junior security consultant, aspiring threat hunter, security engineer, or red/blue/purple team member looking to move into a more research- and publication-focused path? Are you a recent graduate, career-changer, home-lab tinkerer, or CTF player who already writes, shares, or wants to start? Then this role is for you.


What You’ll Do
  • Continuously research emerging threats, malware, threat actors, and vulnerability exploitation campaigns, and turn your findings into timely, insightful content,

  • Contribute to technical content across blogs, whitepapers, demos, solution and integration briefs, offensive and defensive research reports, and research papers, developing your voice and building a strong portfolio along the way,

  • Develop a deep understanding of the Picus platform and collaborate with Picus Labs, Product, and Engineering to translate new capabilities into clear, compelling technical narratives,

  • Monitor market trends, analyst perspectives, category leaders, emerging product categories, and the competitive landscape, helping the team turn these insights into differentiated technical content,

  • Learn how technical content drives discoverability across search and AI answer engines through SEO and AEO, and how it supports audiences throughout the funnel, from awareness to purchase,

  • Collaborate with Growth, Threat Research, Red and Blue Teams, and Alliances to transform research, technical findings, and integrations into public-facing content that reaches and resonates with the market.


  • What You Have
  • 1–2 years of experience (including internships, labs, CTFs, or academic/personal projects) in offensive and/or defensive cybersecurity, with a foundational understanding of the security/threat landscape,

  • Some technical writing, or a genuine eagerness to build a portfolio of published content or projects (blogs, notes, write-ups, talks, or research),

  • An ability, or strong willingness to develop the ability, to translate technical concepts for different audiences,

  • Strong proficiency in written and verbal English,

  • Curiosity and a drive to keep learning in a fast-moving field,

  • Exposure to penetration testing tooling, vulnerability management, or security control validation, and some hands-on familiarity with blue-team tooling such as SIEM or EDR/XDR (lab, coursework, or work experience all count),

  • Interest in autonomous/agentic security validation (an emerging area; exploration counts fully),

  • Early hands-on experience with adversarial techniques (home lab, CTF, or coursework all count),

  • Basic scripting or automation skills (Python, n8n, or comparable agent/workflow tooling),

  • Awareness of modern security problems,

  • Any contribution to the cybersecurity community, however small (blog, GitHub, forum, meetup),

  • Any exposure to public speaking or presenting,

  • Cybersecurity-related certifications, including entry-level ones (Security+, eJPT, BTL1, or similar; OSCP/CISSP-level not expected but a plus),

  • Awareness of SEO/AEO principles or content strategy.

  • Working at Picus
    Fascinating work - a chance to shape and lead an exciting, fast-growing cyber security segment. Security Validation is a concept that helps organizations evaluate their security posture in a continuous, automated, and repeatable way. This approach allows for the identification of imminent threats, provides recommended actions, and produces valuable metrics about cyber-risk levels.
     
    Unlimited opportunity! We are growing. At Picus, you'll be provided with as much responsibility as you can handle - new career development opportunities constantly arise given our rate of growth.
     
    Global exposure - Get a lot of experience working not only in a fast-growing startup but also interact with customers all around the world.
     
    Be part of a global remote team who is taking on Exposure Validation and a growing market segment.
     
     
    We are an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to age, sex, race, color, national origin, religious belief, gender or gender reassignment, sexual orientation, marriage or civil partnership, pregnancy and maternity, disability, protected veteran status, or any other characteristic protected by International law.  Upon conditional offer of employment, candidates are required to complete reference and identity checks in line with local labor laws and as per the Company’s employment policy. 
     
    Picus Security processes candidates' personal data in accordance with applicable data protection laws. For detailed information on how your personal data is processed during the recruitment process, please review our Candidate Privacy Notice

    Apply once. Then go straight to the hiring manager.

    After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

    MR

    Marcus Rivera

    Chief Revenue Officer

    m.rivera@company.com
    linkedin.com/in/marcusrivera
    Unlocked after you apply
    Β·

    Security Analyst Related jobs

    Other jobs at Picus Security

    Premium

    Reach out to the hiring manager directly.

    Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

    • Full match report with fit score and gaps
    • Career diagnostics on how recruiters read you
    • Curated company matches and warm intros
    • 48h early access to new roles

    Cancel anytime.