Log inPost your job
← All jobs
BY

IT Audit Manager

BybitVienna, Austria
FinanceMidOn-site

Bybit is seeking an experienced IT Audit Manager or Senior Manager to lead and execute risk-based technology audits across EU operations. Based in the EU region, preferably Austria, you will shape and deliver the EU technology audit programme, ensuring appropriate audit coverage of applicable regulatory requirements including DORA, MiCA, GDPR, NIS2, and relevant EBA guidelines. You will work closely with Technology, Engineering, Cybersecurity, Risk, Compliance, and other cross-functional teams to assess the design and effectiveness of ICT controls and provide independent, practical, and risk-based assurance across a fast-moving digital asset environment. You report to the EU Head of Audit with a dotted reporting line to the Global Head of IT Audit.

What you'll do

  • Lead and execute risk-based IT audits across EU operations, covering key technology, cybersecurity, ICT risk, operational resilience, data protection, and third-party risk areas
  • Assess the design and effectiveness of ICT governance and controls against applicable EU regulatory requirements, including DORA and related RTS and delegated regulations, MiCA, MiFID II, EMI and payment services requirements, GDPR, NIS2, and relevant EBA guidelines
  • Work closely with the Global IT Audit team on technology audits involving shared platforms, centralised infrastructure, and group-wide processes, adapting audit scope and testing to address EU-specific regulatory and licensing requirements while maintaining consistency with global methodology
  • Contribute to the EU risk assessment and annual IT audit plan, considering regulatory priorities, emerging technology risks, business developments, and changes to the ICT environment
  • Perform walkthroughs and risk assessments with Technology, Cybersecurity, Engineering, Risk, Compliance, and other stakeholders to understand key systems, processes, and control environments
  • Monitor relevant EU regulatory and technology developments and assess their impact on the audit universe and planned coverage
  • Develop well-supported audit findings with clear risk articulation, relevant regulatory references, root-cause analysis, and practical remediation recommendations
  • Prepare concise audit reports and management updates for senior management, the Audit Committee, and other governance forums
  • Monitor remediation progress and independently validate the implementation and effectiveness of agreed corrective actions
  • Support EU regulatory inspections, licensing and post-licensing reviews, and supervisory engagements relating to Bybit EU's MiCA, EMI and MiFID-regulated activities, where relevant to technology and ICT risk
  • Build effective relationships with Technology, Cybersecurity, Risk, Compliance, Legal, and business stakeholders across the EU and global organisation
  • Communicate complex technology and regulatory matters clearly to both technical and non-technical stakeholders
  • Collaborate with 2nd line functions such as Compliance and Risk on integrated assurance over ICT-related regulatory obligations, ensuring technology controls supporting regulatory compliance are appropriately assessed
  • Act as the EU focal point for the Global IT Audit team, jointly planning and executing technology audits on shared infrastructure and ensuring EU regulatory requirements are embedded in global audit scope
  • Stay current on developments in digital assets, emerging technologies, cybersecurity risks, and the EU regulatory environment; share insights with global IT audit peers to strengthen cross-regional coverage
  • Promote consistent audit methodologies, knowledge sharing, and a "One Team" approach across regions

What you bring

  • Bachelor's degree in Information Systems, Computer Science, Engineering, Business, Risk Management, or a related discipline
  • 8 to 12 years of experience in IT audit, technology risk, ICT risk, or technology assurance, preferably within financial services, fintech, payment services, or regulated digital asset environments
  • Strong experience leading technology audits independently, from risk assessment and audit planning through fieldwork, reporting, and remediation validation
  • Demonstrated experience working with cross-border teams and managing senior stakeholders across multiple functions and jurisdictions
  • Strong understanding of EU ICT and digital finance regulatory requirements, particularly DORA and associated RTS and delegated regulations, MiCA, MiFID II, EMI and payment services regulatory requirements, GDPR, NIS2, and relevant EBA ICT, security, and outsourcing guidelines
  • Broad knowledge of ICT governance, cybersecurity, identity and access management, cloud environments, third-party risk management, operational resilience, incident management, SDLC, and change management
  • Working knowledge of major cloud platforms such as AWS, sufficient to assess technology architecture, security controls, and governance arrangements
  • Proficiency in data analytics using SQL, Python, and AI-enabled tools to support audit planning, testing, continuous monitoring, and reporting; experience with bespoke analytics approaches is valued
  • Strong analytical and critical-thinking skills, with the ability to translate complex ICT and regulatory matters into clear business risk
  • Strong written and verbal communication skills, including the ability to produce concise, regulatory-quality audit reports
  • Effective stakeholder management across cultures, functions, and time zones
  • Self-directed and able to independently manage multiple audit engagements and priorities in a fast-moving environment
  • CISA or CISM certification required
  • High integrity, professional skepticism, sound judgement, and attention to detail
  • Proficiency in English required; German language capability is highly desirable; Chinese language skills are a plus
  • EU-based location, preferably Austria
  • Willingness to travel within Europe and internationally where required for audit engagements

Nice to have

  • Experience within an EU-regulated financial institution, payment or e-money institution, investment firm, or crypto-asset service provider, or direct experience working with EU financial regulators
  • Understanding of digital asset custody, wallet architecture, cryptographic key management, and blockchain technology
  • Additional certifications such as CRISC, CISSP, or equivalent
  • Additional qualifications or training relating to DORA, cybersecurity, operational resilience, or technology risk

What we offer

  • Study Growth Fund to support your professional development and continuous learning
  • Internal events including regular team-building activities, workshops, and events designed to promote collaboration and innovation
  • Global collaboration as part of a diverse, international team working alongside colleagues from around the world
  • Career advancement opportunities for growth within a rapidly expanding global company
  • Internal mobility with opportunities for long-term development and internal job opportunities to help build your career path

About Bybit

Established in 2018, Bybit is one of the world's leading cryptocurrency exchanges and digital financial platforms, serving over 80 million users across more than 200 countries and regions. Bybit delivers a seamless ecosystem across trading, payments, wealth management, custody, institutional services, and Web3, recognised as one of the most trusted and transparent platforms in the digital asset industry.

What finance roles in crypto pay

90 salaries · our own data
median $155k$112k$261k

Most finance roles in crypto pay between $112k and $261k, with a median of $155k.

IT Audit Manager | CryptoJobsHQ