Deriv.com logo
Deriv.comPosted 1 month ago

Internal IT Auditor (Regulated Fintech)

On-siteCyberjaya, Selangor, Malaysia

Full TimeSenior LevelLarge

Job Summary

Conduct technology risk-based regulatory audits across banking, virtual assets, and investment service entities, evaluating internal controls in cloud environments, containerized applications, and cryptographic key management systems. Identify infrastructure vulnerabilities and security gaps within DevOps pipelines and core platforms to prevent breaches and regulatory penalties. Collaborate directly with engineering and InfoSec teams to embed robust technical controls into daily operations and drive remediation plans to completion. Report cyber posture insights and audit findings to senior management and audit committees while tracking global standards like DORA and ISO 27001.

Required Qualifications

  • 5+ years in IT audit or technology compliance
  • experience gained inside a regulated fintech, banking, investment services, or VASP environment
  • Deep understanding of IT regulatory frameworks
  • knowledge of technology risk guidelines, cybersecurity mandates, and frameworks like DORA
  • proven experience auditing cloud environments (AWS/GCP)
  • proven experience auditing containerized systems (Kubernetes/Docker)
  • experience auditing IAM
  • experience auditing encryption standards
  • experience auditing blockchain tech
  • a degree in CS, Cybersecurity, or IT
  • CISA certification
  • Excellent spoken and written English
  • integrity and discretion required to handle sensitive compliance matters

Desired Qualifications

  • experience gained inside a regulated fintech, banking, investment services, or VASP environment
  • CRISC certification
  • CISM certification
  • CISSP certification

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce