Senior IT Auditor (f/m/d)
Job description
About the role
Solaris is Europe's leading embedded finance platform operating with a full German banking license and a proprietary modular B2B tech stack. The Senior IT Auditor (f/m/d) will own the independent preparation and execution of IT audit engagements across the organization. You will be responsible for checking the implementation of legal and regulatory requirements such as BAIT and ISO Standards including ISO 27001. This role provides the opportunity to actively participate in crafting the overall Audit value and strategy within Solaris. You will work closely with business units to ensure transparent reporting and effective follow-up on identified findings. The position requires comfort with AI governance frameworks including explainability, fairness, model lifecycle management, and emerging regulatory expectations. This is an exciting opportunity to shape the audit function and influence the control environment across the entire company.
Key facts
What you'll do
- Independently prepare and conduct IT-audits, producing detailed audit reports and coordinating directly with business units.
- Participate in the review and assurance of the internal control system, compliance, security, and operational efficiency of processes and systems.
- Conduct independent reviews of internal and external audit findings as part of the structured follow-up process.
- Provide independent support to internal projects aligned with relevant regulatory requirements such as MaRisk, DORA, KWG, and emerging AI regulatory frameworks.
- Actively contribute to the development and enhancement of auditing methods and standardized procedures.
- Evaluate the effectiveness of information security controls across people, processes, and technologies using a risk-based approach.
- Assess cloud environments, outsourcing arrangements, and software development processes including testing, approval, and authorization management.
- Monitor incident and problem management capabilities to ensure alignment with business continuity and resilience objectives.
- Collaborate with internal stakeholders to validate audit scopes, findings, and remediation action plans.
- Maintain up-to-date knowledge of regulatory standards and translate requirements into practical audit procedures.
- Support the definition and evolution of the internal audit universe and risk assessment methodologies.
- Demonstrate critical thinking when working with AI tools and contribute to a culture of responsible AI use.
- Communicate audit results clearly and professionally to technical and non-technical audiences in both English and German.
- Manage multiple audit workstreams simultaneously while adhering to strict deadlines and quality standards.
- Document all audit activities, evidence, and conclusions in a clear, structured, and reproducible manner.
Requirements
- Possess 5+ years of experience in the field of auditing IT requirements covering MaRisk, DORA, IT Grundschutz, or ISO 2700X standards.
- Hold an educational degree, preferably in IT, Cyber Security, Information Security, or any other related fields.
- Bring experience as an auditor or consultant in auditing techniques, in particular with Testing of Controls (ToD) and Evaluation of Controls (ToE).
- Demonstrate good knowledge of fundamental processes especially BCM, incident- and problem management, clouds, outsourcing, software and development processes including testing and approval, and authorization management.
- Show familiarity with AI governance frameworks, including explainability, fairness, model lifecycle management, and emerging regulatory expectations such as the EU AI Act.
- Exhibit comfort when working with AI tools, thinking critically about AI outputs, and contributing to a culture of responsible AI use within the organization.
- Maintain very good knowledge of the relevant regulatory standards affecting financial services and technology environments.
- Prove the ability to work effectively in a team and exercise a high degree of decision-making autonomy.
- Display confident and excellent social skills with a hands-on mentality and a high level of self-motivation.
- Communicate fluently in both English and German, ensuring clarity and precision in all interactions.
- Understand the importance of confidentiality and demonstrate integrity when handling sensitive banking information.
- Be prepared to engage in continuous learning and professional development in line with Solaris' learning framework.
Nice to have
- Comfort working with AI tools and the ability to critically assess AI-generated outputs in an audit context.
- Experience contributing to the development and implementation of AI governance frameworks.
- Familiarity with the concepts of explainability, fairness, and model lifecycle management for AI systems.
- Knowledge of emerging regulatory expectations related to AI, such as the EU AI Act.
- Willingness to demonstrate comfort with AI-assisted workflows and actively develop AI capabilities over time.
Practical notes
This role is based in Frankfurt and requires availability for travel as needed for audit engagements. The position is open to candidates who can commit to the necessary working hours and support internal project timelines. No specific visa information or deadlines are provided at this stage; interested candidates should refer to official application procedures for further details.