NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs
4 days ago
Apply with autofill
Apply with autofill
Ebury·Fintech·4 days ago
4 days ago

Senior Internal Audit Manager - IT & Information Security

Madrid, SpainHybridSenior · 5+ yearsAuditor

Sign up free to see how well your resume matches this role.

Boost your chances at Ebury

How you compare FREE

?
Your scoreYour score: not yet known
→
21
Top 10%Top 10%: 21 out of 100

Top 10% of NextRaise users matched against Auditor roles in Spain.

Must-have skills for this role

  • cisa
  • cissp
  • cism
  • crisc

PDF or DOCX · no account needed

Apply faster with autofill FREEEbury uses Greenhouse - autofill it instead of retyping.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Lead risk-based audits covering cloud infrastructure (AWS), network security, Identity & Access Management (IAM), privileged access, and containerized deployment environments.
  • Assess operational effectiveness of Cyber Defense controls, including SOC monitoring, Incident Response, SIEM integration (Splunk), and EDR deployments (CrowdStrike).
  • Perform audits of IT General Controls (ITGCs) and automated application controls (ITACs) integrated into CI/CD deployment pipelines.
  • Evaluate third-party vendor risk management frameworks, conducting hosted assurance reviews for critical SaaS platforms.
  • Oversee control assurance frameworks for third-party partnerships, ensuring compliance with DORA and FCA PS21/3 operational resilience guidelines.
  • Assess readiness and operational adherence to key regulatory regimes, including DORA, PRA Operational Resilience, SWIFT Customer Security Programme (CSP), and ECCTA/FTP regulations.
  • Conduct gap analyses and pre-assessment audits against ISO 27001 and PCI DSS standards.
  • Evaluate data governance frameworks, data lineage, and data quality controls across enterprise analytics and reporting platforms.
  • Audit data protection and privacy policies and mechanisms (such as GDPR/CCPA) applied within large-scale data storage and analytics environments.
  • Maintain strong relationships with technical stakeholders, including the CISO, Head of Engineering, CIO, and Chief Data Officer.
  • Formulate pragmatic, risk-ranked audit findings and present formal audit reports to Executive Committees and Board Audit Committees.

What they're looking for

  • 5+ years in IT/Cyber Audit within cloud-native Fintech platforms, financial institutions, or Big 4 tech practice.
  • CISA, CISSP, CISM, or CRISC required

Nice to have

  • dual ACA/CIA qualification preferred
  • Certified Internal Auditor (CIA) (highly advantageous)

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

Ebury helps ambitious businesses unlock global growth, and we take the same approach with our people. We encourage innovation and movement, collaboration and problem-solving, and foster an environment where everyone can feel they belong, are valued, supported and empowered to succeed.

If you’re a collaborator who wants to help transform how businesses operate globally, get in touch - we’d love to discuss how Ebury can accelerate your career so you can shape the future.

Senior Internal Audit Manager - IT & Information Security

Ebury Madrid Office - Hybrid: 4 days in the office, 1 day working from home per week

Role Overview

The Senior Audit Manager - IT & Information Security  is a technology risk expert responsible for evaluating and enhancing the internal control environment across cloud infrastructure, cyber security controls, third-party ecosystems, and engineering platforms used in the SDLC. This candidate combines deep technical expertise in cloud security and DevSecOps with financial technology regulations (e.g., DORA, FCA PS21/3, PRA Operational Resilience, ISO 27001).

Qualification Area

Ideal Candidate Specification

Target Experience

5+ years in IT/Cyber Audit within cloud-native Fintech platforms, financial institutions, or Big 4 tech practice.

Core Credentials

CISA, CISSP, CISM, or CRISC required; dual ACA/CIA qualification preferred.

Technical Stack

Cloud Infrastructure (AWS), Identity & Access Management, SIEM/SOC (Splunk, CrowdStrike, ReliaQuest), GRC (AuditBoard).

Regulatory Knowledge

DORA, FCA PS21/3, PRA Operational Resilience, ISO 27001, COBIT, NIST framework, and related.

Domain Focus

Payments lifecycle, treasury automation platforms, API security, third-party/BPO risk management.

Job Purpose

The Senior Audit Manager - IT & Information Security leads the design, execution, and delivery of the annual IT Audit Plan. Reporting to the Group Head of Internal Audit, the role provides independent assurance to executive stakeholders (CIO, CISO, COO, CRO, DPO) and the Audit Committee regarding platform resilience, cybersecurity maturity, data protection, and adherence to evolving international regulatory standards.

Key Responsibilities

Technology & Cyber Security Assurance

  • Lead risk-based audits covering cloud infrastructure (AWS), network security, Identity & Access Management (IAM), privileged access, and containerized deployment environments.
  • Assess operational effectiveness of Cyber Defense controls, including SOC monitoring, Incident Response, SIEM integration (Splunk), and EDR deployments (CrowdStrike).
  • Perform audits of IT General Controls (ITGCs) and automated application controls (ITACs) integrated into CI/CD deployment pipelines.

Third-Party Risk & Platform Operations

  • Evaluate third-party vendor risk management frameworks, conducting hosted assurance reviews for critical SaaS platforms.
  • Oversee control assurance frameworks for third-party partnerships, ensuring compliance with DORA and FCA PS21/3 operational resilience guidelines.

Regulatory Alignment & Compliance

  • Assess readiness and operational adherence to key regulatory regimes, including DORA, PRA Operational Resilience, SWIFT Customer Security Programme (CSP), and ECCTA/FTP regulations.
  • Conduct gap analyses and pre-assessment audits against ISO 27001 and PCI DSS standards.

Data management and privacy

  • Evaluate data governance frameworks, data lineage, and data quality controls across enterprise analytics and reporting platforms.
  • Audit data protection and privacy policies and mechanisms (such as GDPR/CCPA) applied within large-scale data storage and analytics environments.

Stakeholder Management & Governance

  • Maintain strong relationships with technical stakeholders, including the CISO, Head of Engineering, CIO, and Chief Data Officer.
  • Formulate pragmatic, risk-ranked audit findings and present formal audit reports to Executive Committees and Board Audit Committees.

Technical Competencies & Experience Requirements

Professional Experience

  • Min 5 years experience auditing cloud-native digital architecture (microservices, containerization, API integrations).
  • Track record of building or executing an annual IT risk assessment and audit plan within an engineering-driven or fast-paced Fintech environment.
  • Proven capability in evaluating end-to-end payment processing controls (authorisation, clearing, settlement, reconciliation).

Certifications

  • Certified Information Systems Auditor (CISA)
  • Certified Information Systems Security Professional (CISSP)
  • Certified Internal Auditor (CIA) (highly advantageous)

Skills & Competencies

  • Ability to translate complex cybersecurity and technical risks into clear, business-focused insights for non-technical executives.
  • Pragmatic approach to control framework design, balancing rapid product innovation with regulatory compliance and robust risk management.
  • Strong collaborative mindset with experience in mentoring junior auditors and managing external co-source resource partners.

Why Ebury?

  • Competitive Starting Salary with an annual discretionary bonus that truly rewards your performance from day one.
  • Dedicated Mentorship: Learn directly from experienced managers who are invested in your success.
  • Cutting-Edge Technology: Leverage state-of-the-art tailor made tools and systems that enable you to perform at your best.
  • Clear, Accelerated Career Progression: Defined pathways to leadership and specialist roles within Ebury.
  • Dynamic & Supportive Culture: Work in a collaborative environment where teamwork and personal growth are prioritized.
  • Generous Benefits Package: Access competitive benefits tailored to your location, which typically include health care and social benefits.
  • Central Office: A fantastic location with excellent transport links.

Ready to launch your career with a global FinTech? Click the ‘Apply’ Today and discover your potential at Ebury!

About us

Ebury delivers sophisticated, integrated solutions — business accounts, hedging, and financing — on a single platform with a seamless workflow. Our success is built on a simple premise and singular purpose: To help businesses operate and scale globally. 

Since its founding in 2009, Ebury has always been a fast-growing leader in fintech. Today, we bring together 2000+ Eburians across nearly 70 cities and we’re always looking to add to our team. 

At the heart of our offering is a proprietary platform, purpose-built to help businesses seamlessly streamline and manage global cash flow. We focus on continuous product evolution and innovation to build the infrastructure for borderless growth and help our clients scale at every stage. 

The opportunities at Ebury are as diverse as our people, ranging from business development to engineering roles across our tech pillars.

We believe in inclusion. We stand against discrimination in all forms and are against the intolerance of differences that makes us a modern and successful organisation. At Ebury, you can be whoever you want to be and still feel a sense of belonging no matter your story.

 

 

 

Important Security Notice for Job Applicants:
Ebury only accepts applications via official Ebury channels. We will only contact you from an @ebury.com domain. Always check the emails you receive from us, and note that we will never request payment for any part of the recruitment process. Stay safe and report suspicious activity.

Notice to Recruitment Agencies and Search Firms:
Ebury does not accept unsolicited resumes, CVs, or candidate profiles from recruitment agencies or search firms without signed written Ebury recruitment terms in place for a specific role. Any unsolicited applications will be considered the sole property of Ebury. Ebury will not be responsible or liable for any placement fees or costs associated with unagreed candidate submissions or subsequent hires.

AI Transparency Statement:
Ebury uses Artificial Intelligence (AI) and automated tools to help streamline certain parts of our recruitment process, however, these tools are strictly for administrative efficiency. All hiring decisions, including application reviews, shortlisting, and final selections are evaluated and conducted by human talent acquisition professionals and hiring managers. 

Fintech

Company

EburyFintech
Madrid, Spain

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Ebury's careers site·first seen 18 Sept 2026·last verified 18 Sept 2026·How we source jobs

Similar jobs

  • Regional Audit Executive (m/f/d) at AllianzBarcelona, Spain–match not yet calculated
  • Internal Audit Internship at ferrovialMadrid, Spain–match not yet calculated
  • Assurance | Beca Auditoria Financiera FY27 Oviedo at PwCOviedo, Spain–match not yet calculated
  • Income Audit (November to April) - Hotel Arts Barcelona at Marriott InternationalBarcelona, Spain–match not yet calculated
  • Internal Audit & Certification Manager at HitachiMadrid, Spain–match not yet calculated

Browse more jobs

  • Auditor jobs in United States
  • Auditor jobs in United Kingdom
  • Auditor jobs in India
  • Retail Sales Associate jobs in United States