
Senior Internal Auditor, Technology
Posted 4 days ago

Posted 4 days ago
This is a fully remote position, open to applicants in United States.
• Strategize and implement technology audits in areas such as cybersecurity, cloud, identity and access management, software development lifecycle (SDLC), and change management.
• Evaluate controls related to systems that manage sensitive customer information and identity documentation.
• Analyze operational resilience, incident management, technology risk management, and oversight of third-party technologies.
• Examine data governance, privacy, data-lake controls, as well as governance, security, and privacy of AI systems.
• Assess IT general controls and application controls against standards including ISO 27001, NIST CSF, SOC 2, and COBIT.
• Discover control deficiencies, conduct root cause analysis, and evaluate the impact on business and financial reporting.
• Utilize AI-enabled workflows for testing, anomaly detection, and analytical purposes.
• Oversee multiple audit engagements from the planning phase through fieldwork and reporting.
• Document findings, create workpapers, and compile reports.
• Monitor and verify remediation efforts, escalating any delays or deficiencies.
• Enhance audit methodologies and frameworks while ensuring compliance with IIA Global Internal Audit Standards.
• Lead audit teams and coordinate with co-sourced specialists.
• Collaborate with Engineering, Infrastructure, and Security control owners.
• Interpret technical findings for non-technical stakeholders and senior management.
• Organize audit-plan coverage in coordination with Internal Audit team members and co-sourced resources.
• 5 to 8 years of experience in IT audit, information security, or a related technology risk area.
• Ideally, experience in financial services, fintech, or cryptocurrency sectors.
• Extensive IT audit experience encompassing cybersecurity, identity and access management, IT general controls (ITGCs), cloud, SDLC and change management, data privacy, operational resilience, and third-party technology risk.
• Strong understanding of standards such as ISO 27001, NIST CSF, SOC 2, or COBIT.
• Familiarity with cloud platforms including AWS, GCP, or Azure.
• Working knowledge of data governance and privacy regulations, including GDPR.
• Experience with AI governance, security, and privacy considerations.
• Technical proficiency with enterprise systems, databases, and deployment pipelines.
• Ability to communicate findings effectively to both engineers and senior leadership.
• Capability to responsibly apply generative AI with appropriate human oversight.
• Relevant certifications such as CISA, CISSP, CRISC, CIA, or equivalent are preferred.
• Familiarity with blockchain infrastructure, digital asset custody, or cryptocurrency-native technology environments is advantageous.
• Experience with CI/CD pipelines, version control, and contemporary deployment practices is a plus.
• Exposure to operational resilience and ISO 27001 certification environments is beneficial.
• Applicants may need to undergo job-related skills or work-style assessments.
• Must select a city and country of employment when applying.
• Must specify if work sponsorship is required.
• Participation in a bonus program.
• Equity participation plan.
• Wellness allowance.
• Comprehensive medical insurance.
• Dental insurance coverage.
• Vision insurance.
• 401(k) retirement plan.
• Requirement to use Kraken products upon hiring.
WellStreet Urgent Care
Blue Raven Solar
ProPharma
Get handpicked remote jobs straight to your inbox weekly.