Head of Internal Audit

Posted 11 Hours Ago
Be an Early Applicant
Hiring Remotely in Cyberjaya, Sepang, Selangor, MYS
Remote
Expert/Leader
Fintech • Financial Services • Cryptocurrency
The Role
Lead and build Deriv’s technology-centric Internal Audit function across finance, operations, technology, AI, cybersecurity, regulatory, and third-party risk. Develop risk-based audit strategies and plans, implement continuous control monitoring and automated testing, assess AI governance and model risk, review IT and cloud controls, and provide independent reporting to the Board, Audit Committee, and regulators. Recruit and develop a technically fluent team while maintaining audit independence and delivering commercially grounded recommendations.
Summary Generated by Built In
We're not hiring someone to sign off on quarterly checklists. We're hiring someone to architect an audit function for a company where AI already runs core operations — and prove that assurance can move as fast as the business it's meant to protect.

This is not a traditional audit leadership role built around periodic manual reviews or static accounting checks. You'll own the transformation of assurance itself: from sampling and hindsight to continuous, evidence-based, real-time insight.



Why This Matters

Deriv's mission is Trading for Anyone, Anywhere, Anytime. Serving millions of traders around the clock, across currencies and regulatory regimes, means transaction volumes that make manual sampling inadequate — you can't audit 1% and hope the other 99% is fine.

Our products, operations, risk controls, and decision-making are fundamentally driven by automation, advanced analytics, and AI at scale. Real money, real regulations, real consequences. Someone has to make sure that pace of innovation is matched by governance regulators trust and a Board can rely on. That's this role.


Why Deriv

We're already automating audit, not proposing to.
  • Continuous monitoring checking transactions in real time, not on a quarterly cycle
  • Dozens of fraud detection models running continuously in production — your function will need to audit these, not just the ledgers around them
  • Automated security review on every pull request, and multi-agent systems shipping code to production
  • 400+ internal users on our workflow orchestration platform, generating the process data your team will mine for risk signals
You won't be pitching automation that might get approved. You'll be extending a function that's already ahead of most audit departments in fintech — and setting the standard for what comes next.


Scope of Work

You'll own Internal Audit end-to-end for Deriv's entities, with department-wide accountability for:
  • Financial & Operational Audit — Balance sheet controls, accounting, reporting, and the automated processes behind them
  • Technology & AI Assurance — Governance over machine learning pipelines, model ownership, data provenance, explainability, and human oversight of automated decisions
  • Regulatory & Third-Party Risk — Compliance with applicable regulatory frameworks, and risk arising from vendors, cloud providers, and external AI services
  • Board & Committee Reporting — Independent, evidence-based assurance to the Board and Audit Committee
You'll build the audit universe, set the plan, and make the calls on where the function focuses its attention.


What You'll Do

Build the function
  • Develop and own a risk-based audit strategy aligned to Deriv's business objectives, regulatory obligations, and AI-first operating model
  • Build the annual audit plan from business, regulatory, operational, and real-time AI/data-risk intelligence
  • Introduce and scale continuous control monitoring, automated testing, anomaly detection, and risk-based sampling — replacing the annual cycle with something closer to always-on
Assure AI at scale
  • Assess governance and controls for AI systems: model ownership, data provenance, explainability, validation, human oversight, access management, monitoring, and incident response
  • Evaluate risk arising from generative AI, automated decision-making, machine learning models, LLM integrations, and externally supplied AI services
  • Make sure AI-generated audit insights are explainable, reproducible, and subject to accountable human judgement — not black-box conclusions the Board has to take on faith
Lead and influence
  • Lead audits spanning finance, operations, compliance, technology, cybersecurity, data privacy, third-party risk, and regulated activities
  • Review IT general controls, application controls, cloud environments, access, change management, and software development lifecycles
  • Present findings the Board and regulators can act on — clear, commercially grounded, and proportionate to the actual risk
  • Build a team with genuine tech and AI fluency, and hold them to a standard where controls enable innovation instead of policing it
  • Partner with Compliance, Risk, Finance, Legal, Technology, and Data Science, while protecting Internal Audit's independence from all of them


Who You Are

  • You've led audit or assurance in a technology-first business. Significant internal audit or assurance experience, including leading a regulated organisation's audit function inside a tech-led fintech, SaaS, or AI-driven platform.
  • You understand AI well enough to audit it, not just ask about it. Hands-on knowledge of AI architecture, machine learning model lifecycles, prompt engineering risk, algorithmic bias, and model risk. You've built or run continuous auditing, AI-driven anomaly detection, or automated control testing — not just read about it.
  • You know technology environments from the inside. ITGCs, application controls, cybersecurity, cloud systems (AWS/GCP), API integrations, CI/CD pipelines, and operational resilience aren't foreign concepts — you've audited them directly.
  • You separate signal from noise. You can tell material risk from theatre, and turn dense technical findings into recommendations executives will actually act on.
  • You hold your ground. Professional independence and the confidence to challenge senior decision-makers and technical architects constructively — even when the finding is unwelcome.
Qualifications: Degree in computer science, technology, data analytics, audit, accounting, finance, risk, or a related field. Professional qualification such as CISA, CRISC, CISM, ACA, ACCA, CIA, or CIMA.

Good to have:
  • Deep knowledge of AI governance frameworks and standards — EU AI Act, NIST AI RMF, ISO/IEC 42001, or financial model-risk regulation
  • Practical experience coding or querying databases (SQL, Python, R), or deploying AI agents for audit and automation
  • FCA approval, or eligibility for approval, to perform the SMF5 Internal Audit function
  • Experience in an FCA-regulated fintech, algorithmic trading, payments, brokerage, financial-services, or digital-assets business
  • Experience across multiple legal entities, jurisdictions, and regulatory regimes
  • Big Four or similarly rigorous external-audit, technology-risk, or AI-risk assurance background


What Success Looks Like

Within your first year, you'll have stood up a clear, tech-centric audit universe, secured Board approval for a risk-based plan centred on AI and digital infrastructure, and moved Internal Audit from periodic manual reviews toward continuous, AI-assisted monitoring. Leadership gets earlier warning of material risk, remediation becomes measurable, and Deriv gets to keep moving fast as an AI-first company with more confidence, not less.


The Honest Reality

This is demanding work. You'll own department-wide outcomes — the successes and the misses. You'll build systems and culture at scale, anticipate problems before they show up in a report, and deliver findings your colleagues won't always want to hear. You'll trust AI to flag issues humans overlooked, then defend that call to a Board that's never had to think about model risk before.

But you'll define what audit looks like at a company where AI already runs the business, not one still debating whether to adopt it. You'll build something that outlasts your tenure and sets the template for how fintechs audit AI.

If you want to manage a checklist, this isn't it. If you want to architect the function, it might be.

Skills Required

  • Significant internal audit or assurance experience, including leadership of a regulated organization’s audit function in a technology-led fintech, SaaS, or AI-driven platform
  • Hands-on knowledge of AI architecture, machine learning model lifecycles, prompt engineering risk, algorithmic bias, and model risk
  • Experience building or running continuous auditing, AI-driven anomaly detection, or automated control testing
  • Experience auditing IT general controls, application controls, cybersecurity, cloud systems, API integrations, CI/CD pipelines, and operational resilience
  • Ability to assess material risk, communicate technical findings clearly, and challenge senior decision-makers while maintaining professional independence
  • Degree in computer science, technology, data analytics, audit, accounting, finance, risk, or a related field
  • Professional qualification such as CISA, CRISC, CISM, ACA, ACCA, CIA, or CIMA
  • Deep knowledge of AI governance frameworks and standards, including EU AI Act, NIST AI RMF, ISO/IEC 42001, or financial model-risk regulation
  • Practical experience coding or querying databases using SQL, Python, or R, or deploying AI agents for audit and automation
  • FCA approval or eligibility for approval to perform the SMF5 Internal Audit function
  • Experience in an FCA-regulated fintech, algorithmic trading, payments, brokerage, financial-services, or digital-assets business
  • Experience across multiple legal entities, jurisdictions, and regulatory regimes
  • Big Four or similarly rigorous external-audit, technology-risk, or AI-risk assurance background
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
2,702 Employees
Year Founded: 1999

What We Do

Deriv is a regulated online brokerage group that connects millions of customers in more than 150 countries to global financial markets. It offers contracts for difference (CFDs) and other derivatives covering forex, stocks and indices, cryptocurrencies, commodities, and Derived Indices. The company also provides online trading platforms and tools, including mobile trading, TradingView, Deriv MT5, cTrader, Deriv Trader, and Deriv Bot.

Similar Jobs

Mondelēz International Logo Mondelēz International

SEA BU MDS Director

Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Remote or Hybrid
3 Locations
90000 Employees

Mastercard Logo Mastercard

Manager, Security Solutions (SSO) Product Lead

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Remote or Hybrid
Selangor, MYS
38800 Employees

Expedia Group Logo Expedia Group

Account Manager

AdTech • eCommerce • Information Technology • Software • Travel • Generative AI
Remote or Hybrid
Subang Jaya, Petaling, Selangor, MYS
16000 Employees

Mastercard Logo Mastercard

Counsel

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Remote or Hybrid
Selangor, MYS
38800 Employees

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account