
Senior Internal Auditor, Technology
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Canada, +1 more state.
• Plan and implement technology audits in areas including cybersecurity, cloud computing, identity and access management, software development lifecycle (SDLC), and change management.
• Evaluate security measures for systems that store sensitive customer information and identity documents.
• Analyze operational resilience, incident management, technology risk management, and oversight of third-party technologies.
• Review data governance, privacy policies, controls for data lakes, and governance, security, and privacy related to AI.
• Conduct tests on IT general controls and application controls in accordance with standards such as ISO 27001, NIST CSF, SOC 2, or COBIT.
• Identify gaps in controls, carry out root cause analysis, and evaluate the impact on business and financial reporting.
• Utilize AI-driven workflows for testing, anomaly detection, and analytics while ensuring human ownership of outcomes.
• Manage multiple audit engagements simultaneously from the planning phase through to fieldwork and reporting.
• Document findings, control deficiencies, root causes, workpapers, and audit reports.
• Monitor and validate the remediation of issues while escalating any delays or gaps.
• Enhance audit methodologies and frameworks to ensure compliance with IIA Global Internal Audit Standards and quality assurance requirements.
• Lead audit teams and coordinate with co-sourced specialists.
• Act as a liaison for Engineering, Infrastructure, and Security control owners.
• Communicate audit findings and provide recommendations for control enhancements while upholding audit independence.
• Convert technical findings into actionable insights for non-technical stakeholders and senior leadership.
• Collaborate with Internal Audit team members and co-sourced resources to ensure comprehensive audit-plan coverage.
• 5–8 years of experience in IT audit, information security, or a related technology risk role.
• Preferably experience in financial services, fintech, or cryptocurrency sectors.
• Extensive IT audit background encompassing cybersecurity, identity and access management, IT general controls (ITGCs), cloud computing, SDLC and change management, data privacy, operational resilience, and third-party technology risk.
• Strong understanding of control frameworks such as ISO 27001, NIST CSF, SOC 2, or COBIT.
• Experience with cloud platforms including AWS, GCP, or Azure.
• Familiarity with data governance and privacy regulations, including GDPR.
• Exposure to AI governance, security, and privacy matters.
• Technical proficiency with enterprise systems, databases, and deployment pipelines.
• Ability to convey technical findings to engineers and senior management.
• Responsible use of generative AI with appropriate human oversight.
• Relevant certifications like CISA, CISSP, CRISC, CIA, or equivalent are advantageous.
• Knowledge of blockchain infrastructure, digital asset custody, or crypto-native technology environments is a plus.
• Experience with CI/CD pipelines, version control, and contemporary deployment practices is beneficial.
• Familiarity with operational resilience and ISO 27001 certification environments is desirable.
• Applicants may choose to redact age, date of birth, and educational attendance or graduation dates from their resumes.
• Must complete any necessary job-related skills or work-style assessments.
• Must indicate the city and country from which they will be working.
• Must disclose whether work authorization sponsorship is required.
• Flexible remote work options.
• Opportunity to collaborate with a globally distributed team.
• Consistent application of job-related skills or work-style assessments across all candidates.
• Commitment to equal opportunity employment.
COREnglish
COREnglish
United Franchise Group
Symbotic
Get handpicked remote jobs straight to your inbox weekly.