We're not hiring someone to sign off on quarterly checklists. We're hiring someone to architect an audit function for a company where AI already runs core operations — and prove that assurance can move as fast as the business it's meant to protect.
- Continuous monitoring checking transactions in real time, not on a quarterly cycle
- Dozens of fraud detection models running continuously in production — your function will need to audit these, not just the ledgers around them
- Automated security review on every pull request, and multi-agent systems shipping code to production
- 400+ internal users on our workflow orchestration platform, generating the process data your team will mine for risk signals
- Financial & Operational Audit — Balance sheet controls, accounting, reporting, and the automated processes behind them
- Technology & AI Assurance — Governance over machine learning pipelines, model ownership, data provenance, explainability, and human oversight of automated decisions
- Regulatory & Third-Party Risk — Compliance with applicable regulatory frameworks, and risk arising from vendors, cloud providers, and external AI services
- Board & Committee Reporting — Independent, evidence-based assurance to the Board and Audit Committee
- Develop and own a risk-based audit strategy aligned to Deriv's business objectives, regulatory obligations, and AI-first operating model
- Build the annual audit plan from business, regulatory, operational, and real-time AI/data-risk intelligence
- Introduce and scale continuous control monitoring, automated testing, anomaly detection, and risk-based sampling — replacing the annual cycle with something closer to always-on
- Assess governance and controls for AI systems: model ownership, data provenance, explainability, validation, human oversight, access management, monitoring, and incident response
- Evaluate risk arising from generative AI, automated decision-making, machine learning models, LLM integrations, and externally supplied AI services
- Make sure AI-generated audit insights are explainable, reproducible, and subject to accountable human judgement — not black-box conclusions the Board has to take on faith
- Lead audits spanning finance, operations, compliance, technology, cybersecurity, data privacy, third-party risk, and regulated activities
- Review IT general controls, application controls, cloud environments, access, change management, and software development lifecycles
- Present findings the Board and regulators can act on — clear, commercially grounded, and proportionate to the actual risk
- Build a team with genuine tech and AI fluency, and hold them to a standard where controls enable innovation instead of policing it
- Partner with Compliance, Risk, Finance, Legal, Technology, and Data Science, while protecting Internal Audit's independence from all of them
- You've led audit or assurance in a technology-first business. Significant internal audit or assurance experience, including leading a regulated organisation's audit function inside a tech-led fintech, SaaS, or AI-driven platform.
- You understand AI well enough to audit it, not just ask about it. Hands-on knowledge of AI architecture, machine learning model lifecycles, prompt engineering risk, algorithmic bias, and model risk. You've built or run continuous auditing, AI-driven anomaly detection, or automated control testing — not just read about it.
- You know technology environments from the inside. ITGCs, application controls, cybersecurity, cloud systems (AWS/GCP), API integrations, CI/CD pipelines, and operational resilience aren't foreign concepts — you've audited them directly.
- You separate signal from noise. You can tell material risk from theatre, and turn dense technical findings into recommendations executives will actually act on.
- You hold your ground. Professional independence and the confidence to challenge senior decision-makers and technical architects constructively — even when the finding is unwelcome.
- Deep knowledge of AI governance frameworks and standards — EU AI Act, NIST AI RMF, ISO/IEC 42001, or financial model-risk regulation
- Practical experience coding or querying databases (SQL, Python, R), or deploying AI agents for audit and automation
- FCA approval, or eligibility for approval, to perform the SMF5 Internal Audit function
- Experience in an FCA-regulated fintech, algorithmic trading, payments, brokerage, financial-services, or digital-assets business
- Experience across multiple legal entities, jurisdictions, and regulatory regimes
- Big Four or similarly rigorous external-audit, technology-risk, or AI-risk assurance background
Skills Required
- Significant internal audit or assurance experience, including leadership of a regulated organization’s audit function in a technology-led fintech, SaaS, or AI-driven platform
- Hands-on knowledge of AI architecture, machine learning lifecycles, prompt engineering risk, algorithmic bias, and model risk
- Experience building or operating continuous auditing, AI-driven anomaly detection, or automated control testing
- Direct experience auditing IT general controls, application controls, cybersecurity, cloud systems, API integrations, CI/CD pipelines, and operational resilience
- Degree in computer science, technology, data analytics, audit, accounting, finance, risk, or a related field
- Professional qualification such as CISA, CRISC, CISM, ACA, ACCA, CIA, or CIMA
- Knowledge of AI governance frameworks and standards, including EU AI Act, NIST AI RMF, or ISO/IEC 42001
- Practical coding or database-querying experience using SQL, Python, or R, or experience deploying AI agents for audit and automation
- FCA approval or eligibility for approval to perform the SMF5 Internal Audit function
- Experience in an FCA-regulated fintech, algorithmic trading, payments, brokerage, financial-services, or digital-assets business
- Experience across multiple legal entities, jurisdictions, and regulatory regimes
- Big Four or similarly rigorous external-audit, technology-risk, or AI-risk assurance background
What We Do
Deriv is a regulated online brokerage group that connects millions of customers in more than 150 countries to global financial markets. It offers contracts for difference (CFDs) and other derivatives covering forex, stocks and indices, cryptocurrencies, commodities, and Derived Indices. The company also provides online trading platforms and tools, including mobile trading, TradingView, Deriv MT5, cTrader, Deriv Trader, and Deriv Bot.








