Senior Internal Audit Manager - IT & Information Security
<div class="content-intro"><p>Ebury helps ambitious businesses unlock global growth, and we take the same approach with our people. We encourage innovation and movement, collaboration and problem-solving, and foster an environment where everyone can feel they belong, are valued, supported and empowered to succeed.</p>
<p>If you’re a collaborator who wants to help transform how businesses operate globally, get in touch - we’d love to discuss how Ebury can accelerate your career so you can shape the future.</p></div><p><span style="text-decoration: underline;"><strong>Senior Internal Audit Manager - IT & Information Security</strong></span></p>
<p><span style="font-size: 10pt;"><strong>Ebury Madrid Office - Hybrid: 4 days in the office, 1 day working from home per week</strong></span></p>
<h1><span style="font-size: 10pt;"><strong>Role Overview</strong></span></h1>
<p><span style="font-size: 10pt;">The <strong>Senior Audit Manager - IT & Information Security </strong> is a technology risk expert responsible for evaluating and enhancing the internal control environment across cloud infrastructure, cyber security controls, third-party ecosystems, and engineering platforms used in the SDLC. This candidate combines deep technical expertise in cloud security and DevSecOps with financial technology regulations (e.g., DORA, FCA PS21/3, PRA Operational Resilience, ISO 27001).</span></p>
<table>
<thead>
<tr>
<th>
<p><span style="font-size: 10pt;"><strong>Qualification Area</strong></span></p>
</th>
<th>
<p><span style="font-size: 10pt;"><strong>Ideal Candidate Specification</strong></span></p>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p><span style="font-size: 10pt;"><strong>Target Experience</strong></span></p>
</td>
<td>
<p><span style="font-size: 10pt;">5+ years in IT/Cyber Audit within cloud-native Fintech platforms, financial institutions, or Big 4 tech practice.</span></p>
</td>
</tr>
<tr>
<td>
<p><span style="font-size: 10pt;"><strong>Core Credentials</strong></span></p>
</td>
<td>
<p><span style="font-size: 10pt;">CISA, CISSP, CISM, or CRISC required; dual ACA/CIA qualification preferred.</span></p>
</td>
</tr>
<tr>
<td>
<p><span style="font-size: 10pt;"><strong>Technical Stack</strong></span></p>
</td>
<td>
<p><span style="font-size: 10pt;">Cloud Infrastructure (AWS), Identity & Access Management, SIEM/SOC (Splunk, CrowdStrike, ReliaQuest), GRC (AuditBoard).</span></p>
</td>
</tr>
<tr>
<td>
<p><span style="font-size: 10pt;"><strong>Regulatory Knowledge</strong></span></p>
</td>
<td>
<p><span style="font-size: 10pt;">DORA, FCA PS21/3, PRA Operational Resilience, ISO 27001, COBIT, NIST framework, and related.</span></p>
</td>
</tr>
<tr>
<td>
<p><span style="font-size: 10pt;"><strong>Domain Focus</strong></span></p>
</td>
<td>
<p><span style="font-size: 10pt;">Payments lifecycle, treasury automation platforms, API security, third-party/BPO risk management.</span></p>
</td>
</tr>
</tbody>
</table>
<h1><span style="font-size: 10pt;"><strong>Job Purpose</strong></span></h1>
<p><span style="font-size: 10pt;">The <strong>Senior Audit Manager - IT & Information Security</strong> leads the design, execution, and delivery of the annual IT Audit Plan. Reporting to the Group Head of Internal Audit, the role provides independent assurance to executive stakeholders (CIO, CISO, COO, CRO, DPO) and the Audit Committee regarding platform resilience, cybersecurity maturity, data protection, and adherence to evolving international regulatory standards.</span></p>
<h1><span style="font-size: 10pt;"><strong>Key Responsibilities</strong></span></h1>
<h2><span style="font-size: 10pt;"><strong>Technology & Cyber Security Assurance</strong></span></h2>
<ul>
<li style="font-size: 10pt;"><span style="font-size: 10pt;">Lead risk-based audits covering cloud infrastructure (AWS), network security, Identity & Access Management (IAM), privileged access, and containerized deployment environments.</span></li>
<li style="font-size: 10pt;"><span style="font-size: 10pt;">Assess operational effectiveness of Cyber Defense controls, including SOC monitoring, Incident Response, SIEM integration (Splunk), and EDR deployments (CrowdStrike).</span></li>
<li style="font-size: 10pt;"><span style="font-size: 10pt;">Perform audits of IT General Controls (ITGCs) and automated application controls (ITACs) integrated into CI/CD deployment pipelines.</span></li>
</ul>
<h2><span style="font-size: 10pt;"><strong>Third-Party Risk & Platform Operations</strong></span></h2>
<ul>
<li style="font-size: 10pt;"><span style="font-size: 10pt;">Evaluate third-party vendor risk management frameworks, conducting hosted assurance reviews for critical SaaS platforms.</span></li>
<li style="font-size: 10pt;"><span style="font-size: 10pt;">Oversee control assurance frameworks for third-party partnerships, ensuring compliance with DORA and FCA PS21/3 operational resilience guidelines.</span></li>
</ul>
<h2><span style="font-size: 10pt;"><strong>Regulatory Alignment & Compliance</strong></span></h2>
<ul>
<li style="font-size: 10pt;"><span style="font-size: 10pt;">Assess readiness and operational adherence to key regulatory regimes, including DORA, PRA Operational Resilience, SWIFT Customer Security Programme (CSP), and ECCTA/FTP regulations.</span></li>
<li style="font-size: 10pt;"><span style="font-size: 10pt;">Conduct gap analyses and pre-assessment audits against ISO 27001 and PCI DSS standards.</span></li>
</ul>
<h2><span style="font-size: 10pt;"><strong>Data management and privacy</strong></span></h2>
<ul>
<li style="font-size: 10pt;"><span style="font-size: 10pt;">Evaluate data governance frameworks, data lineage, and data quality controls across enterprise analytics and reporting platforms.</span></li>
<li style="font-size: 10pt;"><span style="font-size: 10pt;">Audit data protection and privacy policies and mechanisms (such as GDPR/CCPA) applied within large-scale data storage and analytics environments.</span></li>
</ul>
<h2><span style="font-size: 10pt;"><strong>Stakeholder Management & Governance</strong></span></h2>
<ul>
<li style="font-size: 10pt;"><span style="font-size: 10pt;">Maintain strong relationships with technical stakeholders, including the CISO, Head of Engineering, CIO, and Chief Data Officer.</span></li>
<li style="font-size: 10pt;"><span style="font-size: 10pt;">Formulate pragmatic, risk-ranked audit findings and present formal audit reports to Executive Committees and Board Audit Committees.</span></li>
</ul>
<h1><span style="font-size: 10pt;"><strong>Technical Competencies & Experience Requirements</strong></span></h1>
<h2><span style="font-size: 10pt;"><strong>Professional Experience</strong></span></h2>
<ul>
<li style="font-size: 10pt;"><span style="font-size: 10pt;">Min 5 years experience auditing cloud-native digital architecture (microservices, containerization, API integrations).</span></li>
<li style="font-size: 10pt;"><span style="font-size: 10pt;">Track record of building or executing an annual IT risk assessment and audit plan within an engineering-driven or fast-paced Fintech environment.</span></li>
<li style="font-size: 10pt;"><span style="font-size: 10pt;">Proven capability in evaluating end-to-end payment processing controls (authorisation, clearing, settlement, reconciliation).</span></li>
</ul>
<h2><span style="font-size: 10pt;"><strong>Certifications</strong></span></h2>
<ul>
<li style="font-size: 10pt;"><span style="font-size: 10pt;"><strong>Certified Information Systems Auditor (CISA)</strong></span></li>
<li style="font-size: 10pt;"><span style="font-size: 10pt;"><strong>Certified Information Systems Security Professional (CISSP)</strong></span></li>
<li style="font-size: 10pt;"><span style="font-size: 10pt;"><strong>Certified Internal Auditor (CIA)</strong> (highly advantageous)</span></li>
</ul>
<h2><span style="font-size: 10pt;"><strong>Skills & Competencies</strong></span></h2>
<ul>
<li style="font-size: 10pt;"><span style="font-size: 10pt;">Ability to translate complex cybersecurity and technical risks into clear, business-focused insights for non-technical executives.</span></li>
<li style="font-size: 10pt;"><span style="font-size: 10pt;">Pragmatic approach to control framework design, balancing rapid product innovation with regulatory compliance and robust risk management.</span></li>
<li style="font-size: 10pt;"><span style="font-size: 10pt;">Strong collaborative mindset with experience in mentoring junior auditors and managing external co-source resource partners.</span></li>
</ul>
<p><span style="font-size: 10pt;"><strong>Why Ebury?</strong></span></p>
<ul>
<li style="font-size: 10pt;"><span style="font-size: 10pt;"><strong>Competitive Starting Salary</strong> with an <strong>annual discretionary bonus</strong><strong> </strong>that truly rewards your performance from day one.</span></li>
<li style="font-size: 10pt;"><span style="font-size: 10pt;"><strong>Dedicated Mentorship: </strong>Learn directly from experienced managers who are invested in your success.</span></li>
<li style="font-size: 10pt;"><span style="font-size: 10pt;"><strong>Cutting-Edge Technology: </strong>Leverage state-of-the-art tailor made tools and systems that enable you to perform at your best.</span></li>
<li style="font-size: 10pt;"><span style="font-size: 10pt;"><strong>Clear, Accelerated Career Progression: </strong>Defined pathways to leadership and specialist roles within Ebury.</span></li>
<li style="font-size: 10pt;"><span style="font-size: 10pt;"><strong>Dynamic & Supportive Culture: </strong>Work in a collaborative environment where teamwork and personal growth are prioritized.</span></li>
<li style="font-size: 10pt;"><span style="font-size: 10pt;"><strong>Generous Benefits Package: </strong>Access competitive benefits tailored to your location, which typically include health care and social benefits.</span></li>
<li style="font-size: 10pt;"><span style="font-size: 10pt;"><strong>Central</strong><st
Este anuncio proviene de Greenhouse. Ver anuncio original ↗