Associate Security Research Engineer
Are you passionate about technology and enjoy explaining complex solutions in a way that everybody gets excited? If so, read on!
About Picus
Picus Security, the leading security validation company, gives organizations a clear picture of their cyber risk based on business context. Picus transforms security practices by correlating, prioritizing, and validating exposures across siloed findings so teams can focus on critical gaps and high-impact fixes. With Picus, security teams can quickly take action with one-click mitigations to stop more threats with less effort.
The Picus Security Validation Platform easily reaches across on-prem environments, hybrid clouds and endpoints coupled with Numi AI to provide exposure validation.
The pioneer of Breach and Attack Simulation, Picus delivers award-winning threat-centric technology that allows teams to pinpoint fixes worth pursuing, offering a 98% recommendation in Gartner Peer Review.
Picus is headquartered in Ankara, with a regional office in Istanbul, but our team is remote across Türkiye. Please note that all CVs must be submitted in English.
About Role
We're growing our Technical Marketing Team to support the high growth and global expansion plans of Picus, and we're opening the door for someone at the start of their research-and-content career. In this role, you'll learn to go deep on real-world threats and turn that research into technical content that shows the market what Picus can actually do, surfacing the platform's technical depth in exposure validation, all with the support and mentorship of an experienced team.
It's a role built for growth in two directions at once: you'll start building your own name in the security community through published work and hands-on research, while contributing to how the market understands the category.
Our research is regularly picked up and cited by the wider community, from major news organizations like Reuters, the Associated Press, and Forbes, to specialist security outlets including Dark Reading, BleepingComputer, Infosecurity Magazine, SCWorld, and Help Net Security, as well as community platforms like Hacker News. Our work has also been referenced by industry authorities such as MITRE ATT&CK and Gartner, and cited in high-impact academic journals. As you grow into the role, there will be opportunities to take your work on stage at industry conferences such as Black Hat and GovWare, and at local meetups and user groups.
You'll be constantly challenged to develop your knowledge and skills in cybersecurity and share what you learn with the world, doing meaningful research for a fast-growing cybersecurity company.
Are you an early-career SOC analyst, junior security consultant, aspiring threat hunter, security engineer, or red/blue/purple team member looking to move into a more research- and publication-focused path? Are you a recent graduate, career-changer, home-lab tinkerer, or CTF player who already writes, shares, or wants to start? Then this role is for you.
What You’ll Do
Continuously research emerging threats, malware, threat actors, and vulnerability exploitation campaigns, and turn your findings into timely, insightful content,
Contribute to technical content across blogs, whitepapers, demos, solution and integration briefs, offensive and defensive research reports, and research papers, developing your voice and building a strong portfolio along the way,
Develop a deep understanding of the Picus platform and collaborate with Picus Labs, Product, and Engineering to translate new capabilities into clear, compelling technical narratives,
Monitor market trends, analyst perspectives, category leaders, emerging product categories, and the competitive landscape, helping the team turn these insights into differentiated technical content,
Learn how technical content drives discoverability across search and AI answer engines through SEO and AEO, and how it supports audiences throughout the funnel, from awareness to purchase,
Collaborate with Growth, Threat Research, Red and Blue Teams, and Alliances to transform research, technical findings, and integrations into public-facing content that reaches and resonates with the market.
What You Have
1–2 years of experience (including internships, labs, CTFs, or academic/personal projects) in offensive and/or defensive cybersecurity, with a foundational understanding of the security/threat landscape,
Some technical writing, or a genuine eagerness to build a portfolio of published content or projects (blogs, notes, write-ups, talks, or research),
An ability, or strong willingness to develop the ability, to translate technical concepts for different audiences,
Strong proficiency in written and verbal English,
Curiosity and a drive to keep learning in a fast-moving field,
Exposure to penetration testing tooling, vulnerability management, or security control validation, and some hands-on familiarity with blue-team tooling such as SIEM or EDR/XDR (lab, coursework, or work experience all count),
Interest in autonomous/agentic security validation (an emerging area; exploration counts fully),
Early hands-on experience with adversarial techniques (home lab, CTF, or coursework all count),
Basic scripting or automation skills (Python, n8n, or comparable agent/workflow tooling),
Awareness of modern security problems,
Any contribution to the cybersecurity community, however small (blog, GitHub, forum, meetup),
Any exposure to public speaking or presenting,
Cybersecurity-related certifications, including entry-level ones (Security+, eJPT, BTL1, or similar; OSCP/CISSP-level not expected but a plus),
Awareness of SEO/AEO principles or content strategy.
Working at Picus
Fascinating work - a chance to shape and lead an exciting, fast-growing cyber security segment. Security Validation is a concept that helps organizations evaluate their security posture in a continuous, automated, and repeatable way. This approach allows for the identification of imminent threats, provides recommended actions, and produces valuable metrics about cyber-risk levels.
Unlimited opportunity! We are growing. At Picus, you'll be provided with as much responsibility as you can handle - new career development opportunities constantly arise given our rate of growth.
Global exposure - Get a lot of experience working not only in a fast-growing startup but also interact with customers all around the world.
Be part of a global remote team who is taking on Exposure Validation and a growing market segment.
We are an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to age, sex, race, color, national origin, religious belief, gender or gender reassignment, sexual orientation, marriage or civil partnership, pregnancy and maternity, disability, protected veteran status, or any other characteristic protected by International law. Upon conditional offer of employment, candidates are required to complete reference and identity checks in line with local labor laws and as per the Company’s employment policy.
Picus Security processes candidates' personal data in accordance with applicable data protection laws. For detailed information on how your personal data is processed during the recruitment process, please review our Candidate Privacy Notice