Kraken Digital Asset Exchange Logo

Kraken Digital Asset Exchange

Senior Internal Auditor, Technology

Posted Yesterday
Be an Early Applicant
Remote
Hiring Remotely in United States
73K-145K Annually
Senior level
Remote
Hiring Remotely in United States
73K-145K Annually
Senior level
Lead and execute technology audits across cybersecurity, cloud, IGA, SDLC, data/privacy, operational resilience, third-party risk, and AI governance. Plan, test, document findings, manage remediation, coordinate co-sourced specialists, and advise stakeholders while applying AI-enabled testing and established frameworks (ISO27001, NIST, SOC2, COBIT).
The summary above was generated by AI
Building the Future of Open Finance

Payward - the parent company behind Kraken, NinjaTrader, Breakout, xStocks, Payward Services and CF Benchmarks - has spent the last 15 years building one of the most modern and globally accessible financial infrastructure platforms in the industry, built to advance an open, global financial system.


Before you apply, we encourage you to explore our culture page to understand what drives us and how we work.

The team

Founded in 2011, Kraken is one of the world's longest-standing crypto platforms, trusted by over 10 million individuals and institutions across the globe. It offers spot trading, margin, futures, staking, and OTC services, with products built for both individual investors and institutional clients.

Payward's Audit & Risk function operates as an Integrated Assurance organization, bringing together Internal Audit and Enterprise Risk Management under a unified risk oversight strategy. The function spans Internal Audit, SOX Compliance, and Enterprise Risk Management across multiple regulated entities and jurisdictions. Internal Audit partners with co-sourced providers, maintains direct reporting lines to the Global and Local Audit Committees, and is building a technology-forward assurance capability at the forefront of crypto and financial innovation.

 
The opportunity

You'll partner with Internal Audit leadership to execute the technology audit program, evaluating the design and operating effectiveness of controls across a broad IT environment - cybersecurity, identity and access management, the software development lifecycle, data and privacy, operational resilience, and AI. This is a hands-on role with real ownership over scope, stakeholders, and outcomes - you'll shape how safely Payward manages some of the highest-risks it carries. You'll be doing it at a crypto exchange - where the infrastructure spans blockchain-native systems and digital asset custody, deployment cycles are fast, and client trust depends on getting the controls right. If you want technology audit work where the systems are genuinely complex and the stakes matter, this is it.

Responsibilities span the following areas:

Technology audit execution

  • Plan and execute technology audits across a broad IT environment - cybersecurity, cloud, identity and access management, the software development lifecycle (SDLC) and change management

  • Assess the security of core systems holding sensitive customer records and identity documentation - access controls, data protection, monitoring, and regulatory and policy compliance

  • Assess operational resilience (business continuity, disaster recovery, and resilience testing), incident management, technology risk management, and third-party technology oversight

  • Review data governance, privacy, and data-lake controls, and assess AI governance, security, and privacy across the organization's use of AI and machine-learning systems

  • Test the design and operating effectiveness of IT general controls and application controls against frameworks such as ISO 27001, NIST CSF, SOC 2, or COBIT; identify gaps, perform root cause analysis, and assess business and financial-reporting impact

  • Apply AI-enabled workflows - AI-assisted testing, anomaly detection, and analytics - to expand coverage and efficiency, with human ownership of conclusions

Engagement & issue management

  • Lead multiple audit engagements concurrently, managing planning, fieldwork, and reporting end-to-end

  • Document audit findings, including control gaps and root cause, and draft clear, well-supported workpapers and reports

  • Track and validate remediation of identified issues, escalating delays or gaps to Internal Audit leadership

  • Contribute to the continuous improvement of audit methodologies and frameworks, and ensure conformance with the IIA Global Internal Audit Standards and the function's quality assurance requirements

  • Lead engagement teams, including staffing and coordinating co-sourced specialists, to ensure quality and timely delivery across audits

Stakeholder engagement & reporting

  • Serve as a trusted point of contact for control owners across Engineering, Infrastructure, and Security teams to communicate audit results and advise on control improvements, while maintaining audit independence

  • Translate technical findings into clear, actionable conclusions for non-technical stakeholders and senior leadership

  • Partner with other Internal Audit team members and co-sourced resources to ensure coordinated coverage across the audit plan

 
What you bring
  • 5-8 years in IT audit, information security, or a related technology risk function, ideally within financial services, fintech, or crypto

  • Broad IT audit experience across several of: cybersecurity, identity and access management, ITGCs, cloud, SDLC and change management, data and privacy, operational resilience, and third-party technology risk

  • Strong grasp of control frameworks (ISO 27001, NIST CSF, SOC 2, or COBIT) and cloud environments (AWS, GCP, Azure)

  • Working knowledge of data governance and privacy (e.g., GDPR), with exposure to AI governance, security, and privacy

  • Technically fluent with enterprise technology (systems, databases, deployment pipelines) and able to translate findings clearly for engineers and senior leaders alike

  • Applies generative AI responsibly, with human oversight, to improve testing coverage and efficiency

 
 
Nice to haves
  • Relevant certifications: CISA, CISSP, CRISC, CIA, or equivalent

  • Familiarity with blockchain infrastructure, digital asset custody, or crypto-native technology environments

  • Experience with CI/CD pipelines, version control, and modern deployment practices.

  • Exposure to operational resilience and ISO 27001 certification environments

 
 
 

Unless a specific application deadline is stated in the job posting, applications are accepted on an ongoing basis.

Please note, applicants are permitted to redact or remove information on their resume that identifies age, date of birth, or dates of attendance at or graduation from an educational institution.

We consider qualified applicants with criminal histories for employment on our team, assessing candidates in a manner consistent with the requirements of the San Francisco Fair Chance Ordinance.

Our commitment

Payward is powered by people from around the world and we celebrate the diverse talents, backgrounds, contributions, and unique perspectives that everyone brings to the table. We hire based on merit, seeking out people with the right abilities, knowledge, and skills for the job. We encourage you to apply for roles where you don't fully meet the listed requirements, especially if you're passionate or knowledgeable about crypto.

We may ask candidates to complete job-related skills or work-style assessments as part of our hiring process. These assessments evaluate competencies relevant to the role and are applied consistently across candidates for similar positions. Results are considered alongside experience and interviews, and are not the sole basis for any employment decision.

As an equal opportunity employer, we don't tolerate discrimination or harassment of any kind, whether based on race, ethnicity, age, gender identity, citizenship, religion, sexual orientation, disability, pregnancy, veteran status, or any other protected characteristic as outlined by federal, state, or local laws.

Stay connected

Follow us on Twitter

Learn on the Kraken Blog

Connect on LinkedIn


Candidate Privacy Notice

Similar Jobs

20 Days Ago
Easy Apply
Remote
United States
Easy Apply
86K-146K Annually
Senior level
86K-146K Annually
Senior level
Cloud • Security • Software • Cybersecurity • Automation
Lead and execute technology audits across cloud, application, and cybersecurity domains to support SOX compliance. Design and test IT general, application, and entity-level controls; perform risk-based planning, testing, and reporting; drive remediation with process owners; and apply data analytics, automation, and generative AI to improve audit quality and efficiency.
Top Skills: AgileAmazon Web ServicesAudit AutomationCobitCosoData AnalyticsDevOpsDevsecopsEncryptionGenerative AiGoogle Cloud PlatformIdentity And Access ManagementIso 27001ItilNetwork SecurityNistSoc 1Soc 2SoxVulnerability ManagementZero Trust
23 Days Ago
In-Office or Remote
2 Locations
Senior level
Senior level
Industrial • Automation
Lead and execute IT and technology-focused audit engagements, assessing AI governance, DevSecOps, IP protection, data governance, third-party risks, and controls. Develop audit plans, perform reviews, recommend corrective actions, and communicate findings to stakeholders.
Top Skills: Ai ToolsAutomated TestingCi/CdDevsecopsExternal Ai ServicesGenerative AiMl SystemsOpen-Source SoftwareSource Code RepositoriesThird-Party Libraries
23 Days Ago
Remote or Hybrid
NE, USA
Senior level
Senior level
Software
Evaluate complex IT systems and controls, plan and execute IT audit engagements, perform control walkthroughs and testing, analyze evidence, report findings, and collaborate with stakeholders. Requires background investigation and hybrid on-site work in Elkhorn.
Top Skills: Business Intelligence SoftwareCaattsMS OfficeStatistical Analysis Software

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account