Associate Security Research Engineer
TLDR
Research emerging threats and translate findings into published reports, blogs, demos, and presentations alongside security and engineering teams.
Continuously research emerging threats, malware, threat actors, and vulnerability exploitation campaigns, and turn your findings into timely, insightful content,
Contribute to technical content across blogs, whitepapers, demos, solution and integration briefs, offensive and defensive research reports, and research papers, developing your voice and building a strong portfolio along the way,
Develop a deep understanding of the Picus platform and collaborate with Picus Labs, Product, and Engineering to translate new capabilities into clear, compelling technical narratives,
Monitor market trends, analyst perspectives, category leaders, emerging product categories, and the competitive landscape, helping the team turn these insights into differentiated technical content,
Learn how technical content drives discoverability across search and AI answer engines through SEO and AEO, and how it supports audiences throughout the funnel, from awareness to purchase,
Collaborate with Growth, Threat Research, Red and Blue Teams, and Alliances to transform research, technical findings, and integrations into public-facing content that reaches and resonates with the market.
1–2 years of experience (including internships, labs, CTFs, or academic/personal projects) in offensive and/or defensive cybersecurity, with a foundational understanding of the security/threat landscape,
Some technical writing, or a genuine eagerness to build a portfolio of published content or projects (blogs, notes, write-ups, talks, or research),
An ability, or strong willingness to develop the ability, to translate technical concepts for different audiences,
Strong proficiency in written and verbal English,
Curiosity and a drive to keep learning in a fast-moving field,
Exposure to penetration testing tooling, vulnerability management, or security control validation, and some hands-on familiarity with blue-team tooling such as SIEM or EDR/XDR (lab, coursework, or work experience all count),
Interest in autonomous/agentic security validation (an emerging area; exploration counts fully),
Early hands-on experience with adversarial techniques (home lab, CTF, or coursework all count),
Basic scripting or automation skills (Python, n8n, or comparable agent/workflow tooling),
Awareness of modern security problems,
Any contribution to the cybersecurity community, however small (blog, GitHub, forum, meetup),
Any exposure to public speaking or presenting,
Cybersecurity-related certifications, including entry-level ones (Security+, eJPT, BTL1, or similar; OSCP/CISSP-level not expected but a plus),
Awareness of SEO/AEO principles or content strategy.
Working at Picus
Fascinating work - a chance to shape and lead an exciting, fast-growing cyber security segment. Security Validation is a concept that helps organizations evaluate their security posture in a continuous, automated, and repeatable way. This approach allows for the identification of imminent threats, provides recommended actions, and produces valuable metrics about cyber-risk levels.
Unlimited opportunity! We are growing. At Picus, you'll be provided with as much responsibility as you can handle - new career development opportunities constantly arise given our rate of growth.
Global exposure - Get a lot of experience working not only in a fast-growing startup but also interact with customers all around the world.
Be part of a global remote team who is taking on Exposure Validation and a growing market segment.
We are an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to age, sex, race, color, national origin, religious belief, gender or gender reassignment, sexual orientation, marriage or civil partnership, pregnancy and maternity, disability, protected veteran status, or any other characteristic protected by International law. Upon conditional offer of employment, candidates are required to complete reference and identity checks in line with local labor laws and as per the Company’s employment policy.
Benefits
Learning Budget
new career development opportunities constantly arise given our rate of growth.
Remote-Friendly
Be part of a global remote team who is taking on Exposure Validation and a growing market segment.
Picus Security provides organizations with a comprehensive view of their cyber risk by validating and prioritizing security exposures in the context of their business. Their platform allows security teams to focus on the most critical vulnerabilities and implement effective, one-click mitigations, streamlining the process of threat management.