The opportunity
About the Role The Technology Audit team within Internal Audit provides independent assurance over Binance's technology environment — IT general controls, application and infrastructure controls, cloud and platform security, cybersecurity, and change and access management. As a…
What you'll do
Assist in the planning and execution of technology audits covering IT general: controls (ITGC), application controls, infrastructure, cloud, and cybersecurity.
Support testing of key controls such as logical access and identity: management, change management, system development lifecycle (SDLC), and IT operations.
Help review cloud and platform configurations (e.g., AWS/GCP/Alibaba Cloud),: CI/CD pipelines, and DevOps practices against control and security expectations.
Design and implement scripts/tools to automate audit procedures, continuous: control monitoring, and data analysis.
Extract, clean, and analyze data from logs, systems, and databases to: identify control gaps, anomalies, and areas of risk.
Prepare clear workpapers, reports, and presentations summarizing audit: findings and recommendations for the Internal Audit team.
What they're looking for
- Working towards a Bachelor's or Master's degree in Computer Science,: Information Systems, Cybersecurity, Data Science, Engineering, or a related field.
- Strong interest in technology risk, information security, and IT/technology auditing.
- Foundational understanding of IT concepts such as operating systems,: databases, networks, cloud computing, and the software development lifecycle.
- Familiarity with data analysis and scripting tools (e.g., Python, SQL);: ability to work with logs and large datasets.
- Ability to interpret technical information and synthesize clear, actionable insights.
- Strong written and verbal communication skills; ability to explain technical: concepts to non-technical stakeholders.
- High attention to detail, ethics, and personal integrity.
- Bilingual English/Mandarin is required to be able to coordinate with overseas partners and stakeholders.