--- title: 'Senior Security Research Engineer at Picus' canonical: 'https://feeny.ai/job/senior-security-research-engineer-picus-ankara-ss4nx65np32s' type: 'job' last_seen: '2026-09-07' --- # Senior Security Research Engineer at Picus - **Company:** Picus - **Location:** Ankara, Turkey - **Employment:** full-time - **Work type:** hybrid - **Posted:** 2026-08-03 - **Last confirmed live:** 2026-09-07 - **Apply:** https://jobs.lever.co/picus/de9126c4-3fcd-4ccf-aa6b-05b173627a6c ## Job description Are you passionate about technology and enjoy explaining complex solutions in a way that everybody gets excited? If so, read on! ## About Picus Picus Security, the leading exposure validation company, proves what attackers can exploit and what your defenses stop, then closes real gaps with ready-to-deploy fixes and revalidates to confirm at the machine speed that today’s AI threats demand. The Picus Platform spans Picus Autonomous Penetration Testing, Picus Breach and Attack Simulation, and Picus Exposure Validation, unified by Picus Swarm, a swarm of AI agents that runs the whole validation loop continuously with human oversight. With 75+ integrations, it reaches across on-prem, hybrid cloud, and endpoint environments. Trusted by many Fortune 500 enterprises, Picus was named a 2025 Gartner Peer Insights Customers’ Choice for Adversarial Exposure Validation and is recognized as an Innovation Leader in the Frost Radar for Automated Security Validation. ## About Role We're looking for a Senior Security Research Engineer to go deep on real-world threats and turn that research into high-impact technical content, including research papers, offensive and defensive security reports, whitepapers, blogs, solution and integration briefs, battlecards, webinars, demos, and conference presentations that showcase Picus's technical depth and competitive differentiation in exposure validation. It's a role that builds two things at once: your own name in the security community through published research and hands-on work, and Picus's growth as that content shapes how the market understands the category. Our research is regularly picked up and cited by the wider community, from major news organizations like Reuters, the Associated Press, and Forbes, to specialist security outlets including Dark Reading, BleepingComputer, Infosecurity Magazine, SCWorld, and Help Net Security, as well as community platforms like Hacker News. Our work has also been referenced by industry authorities such as MITRE ATT&CK and Gartner, and cited in high-impact academic journals. You'll have the opportunity to take your work on stage at industry conferences such as Black Hat and GovWare, and at local meetups and user groups. You'll be constantly challenged to develop your knowledge and skills in cybersecurity and share what you learn with the world, doing meaningful research for a fast-growing cybersecurity company. Are you a SOC analyst, security consultant, threat hunter, security engineer, or red/blue/purple team member looking to transition into a more research- and publication-focused role? Do you blog or contribute to the security community, speaking at conferences or user groups? Then this role is for you. This position is based in our Ankara office and follows a hybrid work model. ## What You’ll Do - Continuously research emerging threats, malware, threat actors, and vulnerability exploitation campaigns, translating your findings into timely, authoritative content, - Produce high-impact technical content, including research papers, offensive and defensive security reports, whitepapers, blogs, solution and integration briefs, battlecards, webinars, demos, and conference presentations, that demonstrates Picus’ technical depth and competitive differentiation, - Partner with Picus Labs, Product, and Engineering to translate new product capabilities into clear, compelling technical narratives that explain how they work, the problems they solve, and what sets Picus apart, - Stay ahead of market developments by monitoring analyst perspectives, category leaders, emerging product categories, and the competitive landscape. Turn these insights into differentiated content that strengthens Picus’ positioning, supports competitive conversations, and influences buyer decisions, - Drive discoverability across search and AI answer engines through SEO and AEO, optimizing technical content to generate organic inbound traffic and build long-term topical authority in the exposure validation market, - Map content across the full buyer journey, from top-of-funnel awareness to bottom-of-funnel decision-making, ensuring it not only educates but also engages prospects, supports evaluation, and drives conversion, - Collaborate closely with Growth, Threat Research, Red and Blue Teams, and Alliances to transform research, technical findings, and integrations into launch, campaign, and public-facing content that reaches and resonates with the market. ## What You Have - 5+ years of experience in offensive and/or defensive cybersecurity utilizing knowledge of the security/threat landscape, - A portfolio of published technical content or projects (blogs, papers, talks, or research), - Ability to translate complex technical concepts for different audiences, from practitioners to executives, - Strong proficiency in written and verbal English, - Technical expertise in penetration testing and pentest automation tooling, vulnerability management, and exposure or security control validation, and hands-on familiarity with blue-team tooling (SIEM, EDR/XDR, and similar detection and response platforms), - Autonomous/agentic security validation: interest or early hands-on research (emerging area; exploration counts as much as production experience), - Hands-on experience in adversarial techniques, - Scripting and agentic automation skills (Python, n8n, or comparable agent/workflow tooling), - Strong knowledge of modern security problems, - Community contribution to cybersecurity knowledge, - Presentations at industry events, - Cybersecurity-related certifications (OSCP, CISSP, CCSP, GPEN, GSEC, BTL1 & BTL2, or similar.), - Understanding of SEO/AEO principles and full-funnel content strategy. ## About Picus ## Company Overview - **One-liner**: Picus Security is a cybersecurity company that pioneered Breach and Attack Simulation (BAS) and now offers an Autonomous Exposure Validation Platform to continuously validate what attackers can actually exploit. - **Entity Type**: Private (Series C, $80M total funding per company; $104M per LinkedIn – conflicting reports) - **Headquarters**: San Francisco, California, United States - **Founded**: 2013 - **Founders**: H. Alper Memis (Co-founder & CEO), Suleyman Ozarslan (Co-founder, VP of Picus Labs) ## Core Business - Primary industry: Computer and Network Security (cybersecurity) - Target customers: B2B, enterprise organizations seeking to validate security controls and reduce cyber risk - Mission: Reduce cyber risk through continuous security validation, turning every exposure into a defensible decision. ## Products & Services - **Picus Autonomous Exposure Validation Platform**: A unified platform combining exposure assessment, security control validation, and adversarial exposure validation. It simulates real attack techniques across network, endpoint, and cloud to measure control performance and prioritize fixes. - **Picus Swarm™**: A team of specialized AI agents that converge automated penetration testing, exposure validation, and breach‑and‑attack simulation into one autonomous, context‑aware loop (tunable from manual to fully autonomous). ## Market Standing - **Valuation/Market Cap**: Not disclosed (private) - **Key Metric**: Annual Revenue of $85M (LinkedIn estimate); Total Funding of $80M (company) or $104M (LinkedIn – conflicting reports) - **Notable Investors/Partners**: Riverwood Capital (led Series C), Turkven (led Series B), Bek Ventures, Earlybird Digital East Fund, Mastercard - **Growth Signals**: 246 employees (+15.9% YoY), 500+ customers, recognized by Gartner Peer Insights with a 98% willingness to recommend (highest in Adversarial Exposure Validation category), global expansion across 15+ countries ## Competitive Advantages - First mover in Breach and Attack Simulation (BAS) since 2013 - Only company that brings together Automated Penetration Testing, BAS, and Rule Validation in an open platform - Evidence‑based prioritization reduces patch backlogs by 86% and MTTR from 74 to 14 days - High customer satisfaction and industry recognition (Gartner Cool Vendor, Peer Insights leader) ## Strategic Focus - Expanding AI‑driven autonomous validation capabilities (Picus Swarm) - Continuing global growth (offices in US, Turkey, UK, and presence in Middle East, Asia, Europe) - Modernizing security budgets and raising ROI on existing security tools - Deprioritizing low‑value patching by focusing on what is actually exploitable ## Why Work Here - Culture: “Strong sense of belonging where uniqueness enhances team effectiveness” – global, collaborative, innovation‑driven - Remote/hybrid policy: Remote work is offered (“Flexible location, same impact”); some roles are hybrid (e.g., Ankara, Turkey) - Benefits: Stock options, annual leave, competitive local packages - Employer rating: 4.4/5.0 on LinkedIn (87 reviews), with 4.2 for work‑life balance, 4.3 for compensation and culture - Engineering culture: Emphasis on building new things, pushing out of comfort zone, and taking on challenges as a team ## Sources 1. [picussecurity.com](https://www.picussecurity.com/) 2. [picussecurity.com/about-us](https://www.picussecurity.com/about-us) 3. [picussecurity.com/careers](https://www.picussecurity.com/careers-at-picus) 4. [jobs.lever.co/picus](https://jobs.lever.co/picus) 5. [linkedin.com/company/picus-security](https://www.linkedin.com/company/picus-security) ## Other roles at Picus - [Senior Product Marketing Manager](https://feeny.ai/job/senior-product-marketing-manager-picus-united-states-x4hrevh6s6mt) — United States - [Principal Product Marketing Manager](https://feeny.ai/job/principal-product-marketing-manager-picus-united-states-5d52aedf8tpg) — United States - [Associate Security Research Engineer](https://feeny.ai/job/associate-security-research-engineer-picus-ankara-a1jjtfrce1yr) — Ankara, Turkey - [Field Marketing Manager](https://feeny.ai/job/field-marketing-manager-picus-united-states-wcqya6qjan5z) — United States - [Enterprise Account Executive](https://feeny.ai/job/enterprise-account-executive-picus-new-york-hffhc7dvbz9p) — New York, NY - [Enterprise Account Executive](https://feeny.ai/job/enterprise-account-executive-picus-london-p5qjxcbqrqx6) — London, United Kingdom - [Channel Account Manager](https://feeny.ai/job/channel-account-manager-picus-new-york-4n44twhh4ckx) — New York, NY - [Senior Security Research Engineer](https://feeny.ai/job/senior-security-research-engineer-elastic-spain-tqf4why6kc7d) — Spain - [Senior Security Research Engineer](https://feeny.ai/job/senior-security-research-engineer-elastic-canada-kd0f60nynh8r) — Canada - [Senior Security Research Engineer](https://feeny.ai/job/senior-security-research-engineer-elastic-united-states-nbcj4yh2tnw9) — United States