SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Kraken, one of the world's longest-standing crypto platforms with over 10 million users, is seeking a Senior Internal Auditor to lead technology audit execution across its complex IT environment. Reporting to Internal Audit leadership, you will evaluate the design and operating effectiveness of controls spanning cybersecurity, identity and access management, software development lifecycle, data and privacy, operational resilience, and AI governance.
Key responsibilities include planning and executing technology audits across a broad IT environment; assessing security of core systems holding sensitive customer records and identity documentation; evaluating operational resilience including business continuity and disaster recovery; reviewing data governance and privacy controls; and assessing AI governance, security, and privacy. You will test IT general controls and application controls against frameworks such as ISO 27001, NIST CSF, SOC 2, and COBIT, identifying gaps and performing root cause analysis.
You will lead multiple audit engagements concurrently, managing planning, fieldwork, and reporting end-to-end. This includes documenting findings, drafting workpapers and reports, tracking remediation, and leading engagement teams including co-sourced specialists. You will serve as a trusted advisor to control owners across Engineering, Infrastructure, and Security teams, translating technical findings into actionable conclusions for non-technical stakeholders while maintaining audit independence.
The role emphasizes applying AI-enabled workflows—AI-assisted testing, anomaly detection, and analytics—to expand coverage and efficiency, with human ownership of conclusions. You will contribute to continuous improvement of audit methodologies and ensure conformance with IIA Global Internal Audit Standards.
Required: 5-8 years in IT audit, information security, or related technology risk function, ideally in financial services, fintech, or crypto. Broad IT audit experience across cybersecurity, IAM, ITGCs, cloud, SDLC, data and privacy, operational resilience, and third-party technology risk. Strong grasp of control frameworks and cloud environments (AWS, GCP, Azure). Working knowledge of data governance, privacy (GDPR), and AI governance. Technical fluency with enterprise technology and ability to translate findings for engineers and leaders. Responsible application of generative AI with human oversight.
Nice-to-haves: CISA, CISSP, CRISC, CIA certifications; familiarity with blockchain infrastructure and crypto-native technology; CI/CD and modern deployment practices; operational resilience and ISO 27001 certification experience.