The opportunity
We are seeking an Internal IT Auditor to conduct the full IT audit cycle, ensuring operational effectiveness, reliability, and regulatory compliance across our internal IT environments and critical ICT third-party ecosystems. Our Internal Audit team provides independent…
What you'll do
Execute the full audit cycle: Perform comprehensive risk and control management over IT operations to ensure effectiveness, reliability, and adherence to established professional and regulatory standards.
Audit critical ICT services & vendors: Lead audits of third-party vendors, outsourced service providers, and cloud infrastructures, evaluating their control environments and how internal processes govern these external services.
Analyze data and IT processes: Obtain and evaluate documentation, flowcharts, and data using data-driven audit approaches for system development, IT security, and vendor management.
Deliver impactful reporting: Prepare detailed Internal Audit reports that translate complex technical findings into business-relevant insights and actionable recommendations for senior management.
Drive continuous improvement: Continuously monitor the IT and ICT vendor risk landscape, facilitate alignment discussions, and advise management on best practices and risk remediation actions.
years of significant experience functioning as an Internal IT Auditor at an: international company within a regulated environment (preferably a bank, financial institution, fintech, or an audit/consulting firm).
What they're looking for
- Holding professional certifications such as Certified Information Systems: Auditor (CISA), ISO 27001 Lead Auditor, CISSP, or comparable qualifications, are a plus.
- Deep understanding of IT General Controls (ITGC), modern IT/cloud: architectures, operational resilience frameworks, and ICT Third-Party Risk Management (TPRM).
- Solid understanding of European financial regulatory frameworks relevant to: IT and outsourcing, particularly DORA, and MaRisk.
- Experience in data-driven audit approaches, including large-scale data: evaluation, and proficiency in modern audit tools and platforms.