SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Internal Auditor, Technology

Kraken - United States - In-office - posted 2026-08-12

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Kraken, a leading crypto exchange and part of Payward, is seeking a Senior Internal Auditor to lead technology audit execution across a complex, globally distributed financial infrastructure platform. You'll partner with Internal Audit leadership to evaluate the design and operating effectiveness of controls spanning cybersecurity, identity and access management, software development lifecycle, data governance, privacy, operational resilience, and AI systems. This is a hands-on role with real ownership over scope, stakeholders, and outcomes. Key responsibilities include planning and executing technology audits across a broad IT environment; assessing security of core systems holding sensitive customer records and identity documentation; evaluating operational resilience including business continuity and disaster recovery; reviewing data governance and AI governance frameworks; and testing IT general controls and application controls against ISO 27001, NIST CSF, SOC 2, and COBIT standards. You'll lead multiple audit engagements concurrently, managing planning, fieldwork, and reporting end-to-end, while documenting findings and tracking remediation of identified issues. You'll serve as a trusted point of contact for control owners across Engineering, Infrastructure, and Security teams, translating technical findings into clear, actionable conclusions for non-technical stakeholders and senior leadership. The role involves applying AI-enabled workflows—AI-assisted testing, anomaly detection, and analytics—to expand coverage and efficiency while maintaining human ownership of conclusions. Required: 5–8 years in IT audit, information security, or related technology risk function, ideally within financial services, fintech, or crypto. Broad IT audit experience across cybersecurity, identity and access management, ITGCs, cloud, SDLC, data and privacy, operational resilience, and third-party technology risk. Strong grasp of control frameworks and cloud environments (AWS, GCP, Azure). Working knowledge of data governance, privacy (GDPR), and AI governance. Technical fluency with enterprise technology and ability to translate findings for engineers and leaders. Nice-to-haves: CISA, CISSP, CRISC, CIA certifications; familiarity with blockchain infrastructure or crypto-native technology; CI/CD pipeline and modern deployment practice experience; exposure to operational resilience and ISO 27001 certification environments.

Similar roles