
Senior Internal Auditor, Technology
KrakenUSAFull Time1d ago
Job description
com.
About the role
The role centers on technology audit execution within Payward's Integrated Assurance organization. You will partner directly with Internal Audit leadership to own the planning and execution of the technology audit program. The position grants you real ownership over scope, stakeholders, and outcomes for some of the highest-risk areas within the organization. You will operate within a crypto exchange environment where infrastructure spans blockchain-native systems and digital asset custody. Fast deployment cycles and the reliance on client trust demand rigorous control validation. If you seek technology audit work with genuinely complex systems and material stakes, this position defines that scope.
Key facts
What you'll do
- Plan and execute technology audits across a broad IT environment, including cybersecurity, cloud infrastructure, identity and access management, the software development lifecycle (SDLC) and change management, data governance, privacy, and data-lake controls.
- Assess the security posture of core systems that hold sensitive customer records and identity documentation, focusing on access controls, data protection mechanisms, monitoring capabilities, and adherence to regulatory and policy compliance requirements.
- Evaluate operational resilience practices, encompassing business continuity, disaster recovery strategies, and resilience testing, along with incident management, technology risk management, and oversight of third-party technology relationships.
- Review data governance, privacy frameworks, and data-lake controls, while assessing artificial intelligence governance, security, and privacy practices across the organization's use of AI and machine-learning systems.
- Test the design and operating effectiveness of IT general controls and application controls by mapping them against recognized frameworks such as ISO 27001, NIST CSF, SOC 2, or COBIT; identify gaps, perform root cause analysis, and assess potential business and financial-reporting impact.
- Apply AI-enabled workflows, including AI-assisted testing, anomaly detection, and analytics, to expand audit coverage and operational efficiency, while retaining human ownership of conclusions and audit quality.
- Lead multiple audit engagements concurrently, managing the full lifecycle from initial planning through fieldwork execution and final reporting delivery.
- Document audit findings with precision, detailing control gaps and root causes, and drafting clear, well-supported workpapers and reports that communicate risk and implications.
- Track the remediation status of identified issues and validate corrective actions, escalating persistent delays or control gaps to Internal Audit leadership for timely resolution.
- Contribute to the continuous improvement of audit methodologies, frameworks, and quality assurance processes, ensuring strict conformance with the IIA Global Internal Audit Standards.
- Lead engagement teams by coordinating staffing efforts and managing co-sourced specialists to ensure quality and timely delivery across the audit portfolio.
- Serve as a trusted technical and strategic point of contact for control owners within Engineering, Infrastructure, and Security teams, communicating audit results and advising on control enhancements while preserving audit independence.
- Translate intricate technical findings into clear, actionable conclusions tailored for non-technical stakeholders and senior leadership audiences.
- Partner with other Internal Audit team members and co-sourced resources to ensure integrated and coordinated coverage across the enterprise audit plan.
Requirements
- 5-8 years of cumulative experience in IT audit, information security, or a related technology risk function, ideally within financial services, fintech, or crypto sectors.
- Demonstrated broad IT audit experience spanning multiple domains, including but not limited to cybersecurity, identity and access management, IT general controls (ITGCs), cloud computing, software development lifecycle (SDLC) and change management, data and privacy, operational resilience, and third-party technology risk.
- Solid understanding of core information security principles, technology controls, and risk management practices as applied to complex, distributed, and cloud-based environments.
- Familiarity with financial services regulatory expectations and the operational risks inherent in fintech and digital asset platforms.
- Strong analytical and problem-solving capabilities, with the ability to dissect complex system architectures, assess control effectiveness, and draw sound conclusions.
- Effective written and verbal communication skills, enabling the translation of technical jargon into clear narratives for diverse audiences, including senior management and technical specialists.
- Demonstrated ability to work autonomously and manage multiple priorities in a fast-paced, dynamic, and regulated environment.
- Commitment to professional standards, including adherence to the IIA Global Internal Audit Standards and the maintenance of a robust quality assurance mindset.
- Willingness to engage with evolving technologies, including AI and machine learning, both in the context of audit methodologies and the systems under review.
- Ability to collaborate effectively with co-sourced providers and third-party specialists, ensuring seamless integration of external resources into the audit function.
- Understanding of blockchain-native systems and digital asset custody considerations is advantageous given the nature of the platform.
- Flexibility to travel as required for engagement purposes and compliance with organizational policies.
Nice to have
- Preferred experience with AI-enabled audit workflows, anomaly detection, and data analytics tools to enhance audit efficiency and depth.
- Knowledge of specific regulatory frameworks relevant to crypto-assets and digital financial products.
Practical notes
- Travel may be required as needed for audit engagements.
- Compliance with visa and work authorization requirements is mandatory for employment.
- Applicants must meet the outlined experience and skill criteria without exception.