Log inPost your job
← All jobs
KR

Senior Internal Auditor, Technology

KrakenCanada
SecuritySeniorRemote
🌍 Fully remote

As a Senior Internal Auditor, Technology at Payward (parent company of Kraken), you'll execute the technology audit program for one of the world's longest-standing crypto platforms, trusted by over 10 million individuals and institutions. You'll evaluate the design and operating effectiveness of controls across a broad IT environment spanning cybersecurity, identity and access management, software development lifecycle, data and privacy, operational resilience, and AI. This is hands-on work with real ownership over scope, stakeholders, and outcomes, shaping how safely Payward manages some of its highest risks in an environment where infrastructure spans blockchain-native systems, digital asset custody, and fast deployment cycles.

What you'll do

  • Plan and execute technology audits across a broad IT environment including cybersecurity, cloud, identity and access management, and software development lifecycle and change management
  • Assess the security of core systems holding sensitive customer records and identity documentation, including access controls, data protection, monitoring, and regulatory and policy compliance
  • Assess operational resilience such as business continuity, disaster recovery, resilience testing, incident management, technology risk management, and third-party technology oversight
  • Review data governance, privacy, and data-lake controls, and assess AI governance, security, and privacy across the organization's use of AI and machine-learning systems
  • Test the design and operating effectiveness of IT general controls and application controls against frameworks such as ISO 27001, NIST CSF, SOC 2, or COBIT; identify gaps, perform root cause analysis, and assess business and financial-reporting impact
  • Apply AI-enabled workflows such as AI-assisted testing, anomaly detection, and analytics to expand coverage and efficiency, with human ownership of conclusions
  • Lead multiple audit engagements concurrently, managing planning, fieldwork, and reporting end-to-end
  • Document audit findings, including control gaps and root cause, and draft clear, well-supported workpapers and reports
  • Track and validate remediation of identified issues, escalating delays or gaps to Internal Audit leadership
  • Contribute to the continuous improvement of audit methodologies and frameworks, and ensure conformance with the IIA Global Internal Audit Standards and the function's quality assurance requirements
  • Lead engagement teams, including staffing and coordinating co-sourced specialists, to ensure quality and timely delivery across audits
  • Serve as a trusted point of contact for control owners across Engineering, Infrastructure, and Security teams to communicate audit results and advise on control improvements, while maintaining audit independence
  • Translate technical findings into clear, actionable conclusions for non-technical stakeholders and senior leadership
  • Partner with other Internal Audit team members and co-sourced resources to ensure coordinated coverage across the audit plan

What you bring

  • 5-8 years in IT audit, information security, or a related technology risk function, ideally within financial services, fintech, or crypto
  • Broad IT audit experience across several of cybersecurity, identity and access management, ITGCs, cloud, software development lifecycle and change management, data and privacy, operational resilience, and third-party technology risk
  • A strong grasp of control frameworks such as ISO 27001, NIST CSF, SOC 2, or COBIT and cloud environments such as AWS, GCP, and Azure
  • Working knowledge of data governance and privacy such as GDPR, with exposure to AI governance, security, and privacy
  • Technical fluency with enterprise technology including systems, databases, and deployment pipelines, and the ability to translate findings clearly for engineers and senior leaders alike
  • Ability to apply generative AI responsibly, with human oversight, to improve testing coverage and efficiency

Nice to have

  • Relevant certifications such as CISA, CISSP, CRISC, CIA, or equivalent
  • Familiarity with blockchain infrastructure, digital asset custody, or crypto-native technology environments
  • Experience with CI/CD pipelines, version control, and modern deployment practices
  • Exposure to operational resilience and ISO 27001 certification environments

About Payward

Payward is the parent company behind Kraken, NinjaTrader, Breakout, xStocks, Payward Services, and CF Benchmarks. Founded in 2011, Kraken is one of the world's longest-standing crypto platforms, offering spot trading, margin, futures, staking, and OTC services built for both individual investors and institutional clients. Payward's Audit and Risk function operates as an Integrated Assurance organization, bringing together Internal Audit and Enterprise Risk Management across multiple regulated entities and jurisdictions.

What security roles in crypto pay

112 salaries · our own data
median $195k$141k$264k

Most security roles in crypto pay between $141k and $264k, with a median of $195k.

Senior Internal Auditor, Technology | CryptoJobsHQ