Internal Auditor, Technology

Payward, Inc.
United States
24 days ago
Apply on www.workingnomads.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$73,000.0 - $145,000.0
Working hours
Regular working hours

Tech stack

Artificial Intelligence Amazon Web Services Data Analysis Microsoft Azure Cloud Computing Control Objectives for Information and Related Technology (COBIT) Cyber Security Databases Data Auditing Data Governance Digital Assets Disaster Recovery
+11 more
Identity and Access Management Information Technology Audit Machine Learning Systems Development Life Cycle Blockchain Software Engineering Google Cloud Enterprise Software Applications IT General Controls (ITGC) Delivery Pipeline Software Version Control

Job description

Technology audit execution

  • Plan and execute technology audits across a broad IT environment - cybersecurity, cloud, identity and access management, the software development lifecycle (SDLC) and change management
  • Assess the security of core systems holding sensitive customer records and identity documentation - access controls, data protection, monitoring, and regulatory and policy compliance
  • Assess operational resilience (business continuity, disaster recovery, and resilience testing), incident management, technology risk management, and third-party technology oversight
  • Review data governance, privacy, and data-lake controls, and assess AI governance, security, and privacy across the organization’s use of AI and machine-learning systems
  • Test the design and operating effectiveness of IT general controls and application controls against frameworks such as ISO 27001, NIST CSF, SOC 2, or COBIT; identify gaps, perform root cause analysis, and assess business and financial-reporting impact
  • Apply AI-enabled workflows - AI-assisted testing, anomaly detection, and analytics - to expand coverage and efficiency, with human ownership of conclusions

Engagement & issue management

  • Lead multiple audit engagements concurrently, managing planning, fieldwork, and reporting end-to-end
  • Document audit findings, including control gaps and root cause, and draft clear, well-supported workpapers and reports
  • Track and validate remediation of identified issues, escalating delays or gaps to Internal Audit leadership
  • Contribute to the continuous improvement of audit methodologies and frameworks, and ensure conformance with the IIA Global Internal Audit Standards and the function’s quality assurance requirements
  • Lead engagement teams, including staffing and coordinating co-sourced specialists, to ensure quality and timely delivery across audits

Stakeholder engagement & reporting

  • Serve as a trusted point of contact for control owners across Engineering, Infrastructure, and Security teams to communicate audit results and advise on control improvements, while maintaining audit independence
  • Translate technical findings into clear, actionable conclusions for non-technical stakeholders and senior leadership
  • Partner with other Internal Audit team members and co-sourced resources to ensure coordinated coverage across the audit plan

Requirements

  • 5-8 years in IT audit, information security, or a related technology risk function, ideally within financial services, fintech, or crypto
  • Broad IT audit experience across several of: cybersecurity, identity and access management, ITGCs, cloud, SDLC and change management, data and privacy, operational resilience, and third-party technology risk
  • Strong grasp of control frameworks (ISO 27001, NIST CSF, SOC 2, or COBIT) and cloud environments (AWS, GCP, Azure)
  • Working knowledge of data governance and privacy (e.g., GDPR), with exposure to AI governance, security, and privacy
  • Technically fluent with enterprise technology (systems, databases, deployment pipelines) and able to translate findings clearly for engineers and senior leaders alike
  • Applies generative AI responsibly, with human oversight, to improve testing coverage and efficiency, * Relevant certifications: CISA, CISSP, CRISC, CIA, or equivalent
  • Familiarity with blockchain infrastructure, digital asset custody, or crypto-native technology environments
  • Experience with CI/CD pipelines, version control, and modern deployment practices.
  • Exposure to operational resilience and ISO 27001 certification environments

About the company

Payward - the parent company behind Kraken, NinjaTrader, Breakout, xStocks, Payward Services and CF Benchmarks - has spent the last 15 years building one of the most modern and globally accessible financial infrastructure platforms in the industry, built to advance an open, global financial system., Founded in 2011, Kraken is one of the world’s longest-standing crypto platforms, trusted by over 10 million individuals and institutions across the globe. It offers spot trading, margin, futures, staking, and OTC services, with products built for both individual investors and institutional clients.

Payward’s Audit & Risk function operates as an Integrated Assurance organization, bringing together Internal Audit and Enterprise Risk Management under a unified risk oversight strategy. The function spans Internal Audit, SOX Compliance, and Enterprise Risk Management across multiple regulated entities and jurisdictions. Internal Audit partners with co-sourced providers, maintains direct reporting lines to the Global and Local Audit Committees, and is building a technology-forward assurance capability at the forefront of crypto and financial innovation., You’ll partner with Internal Audit leadership to execute the technology audit program, evaluating the design and operating effectiveness of controls across a broad IT environment - cybersecurity, identity and access management, the software development lifecycle, data and privacy, operational resilience, and AI. This is a hands-on role with real ownership over scope, stakeholders, and outcomes - you’ll shape how safely Payward manages some of the highest-risks it carries. You’ll be doing it at a crypto exchange - where the infrastructure spans blockchain-native systems and digital asset custody, deployment cycles are fast, and client trust depends on getting the controls right. If you want technology audit work where the systems are genuinely complex and the stakes matter, this is it.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.workingnomads.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:44 min

Background and career journey in regulated software systems

Martin Hynie · Coffee With Developers

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

4:12 min

Using contract managers for blockchain operations

Soumaya Erradi · LIVE

6:10 min

Unlocking free learning credits via Google Cloud Innovators

Asrar Asrar · World Congress 2024

2:11 min

Addressing security audits and regional data compliance legislation

4:01 min

Managing application isolation via pluggable database models

Wei Hu Wei Hu · World Congress 2022

Videos

See all

Related articles

See all