We're not
hiring someone to run a controls checklist. We're hiring someone to audit the
technology the whole group runs on — including the AI we're building — and
prove whether it holds up before a regulator, an attacker or an outage proves
it doesn't.
Scope
of Work
Five things
sit with you. All of them cover the whole group — every entity, regulated and
unregulated, every jurisdiction:
Technology
& Security Audit — Auditing the infrastructure and
applications the group actually runs on: cloud environments (AWS/GCP), DevOps
pipelines, identity and access management, encryption and key management,
trading platforms, payment systems, and many more.
IT Governance
& Regulatory Assurance — Assessing whether
technology governance, change management, resilience and data protection meet
both internal standards and external requirements and keeping that view
consistent across jurisdictions.
AI &
Agent Assurance — Auditing the AI systems and autonomous
agents being built and deployed across the group: how models are governed, what
data and systems they can reach, whether their permissions are contained,
whether their output is reliable, and accountability for what they do.
AI-Driven
Audit Transformation — Building the tools. Designing and deploying
the automation, analytics and agents the audit function itself runs on,
embedding them into daily audit workflow, and testing full populations instead
of samples.
Findings,
Reporting & Remediation — Producing findings
that hold up under challenge, reporting technology risk to management and the Board
in language they can act on, and driving remediation until the exposure is
measurably smaller.
What
You'll Do
Audit the technology the group
runs on
• Audit cloud environments, applications, DevOps
pipelines, IAM, encryption and key management — hands on, in the environment,
not from a control description
• Audit the core systems the business depends
on: trading platforms, payment and settlement flows, client data stores.
• Identify security and configuration weaknesses
before they become a breach, a penalty or an outage, and say what the actual
exposure is rather than logging an observation
Assure governance and regulatory
compliance across jurisdictions
• Assess IT governance, change management,
third-party technology dependency, data protection and operational resilience
against internal standards and regulatory requirements
• Keep a clear view of what global standards and
licensing rules require in each jurisdiction, and where the group is short
• Track technology regulation as it develops and
say what has to change, early enough to act on it
Audit the AI we're building
• Audit in-house AI tools and agents: model
governance, data access, system permissions, escalation limits, human oversight
and audit trail
• Test whether an agent can reach data or take
actions beyond what it was authorised to do, and whether anyone would know if
it did
• Assess output reliability and model
performance over time, and challenge deployments where accountability for a
decision isn't clear
Build the AI the audit function
runs on
• Design and deploy automation, analytics and
agents yourself — this is a build role, not a role that uses someone else's
tools
• Embed them into the audit workflow so testing
runs continuously across full populations, and auditor time goes to judgment
instead of evidence gathering
• Govern what you build to the same standard you
hold the business to: validation, monitoring, and knowing when the output is
wrong
Report it, then drive it down
• Write findings that stand up to challenge from
engineers and from senior management — criteria, condition, cause, consequence
and correction, every time
• Report technology and cyber risk to management
and the Board so they can act on it, and defend a finding to people who'd
rather it weren't true
• Drive remediation to closure and verify the
risk actually fell, rather than accepting that a ticket was closed
Who
You Are
You've
audited technology in a regulated environment, not just reviewed documentation. 5+ years in IT audit, ideally gained inside fintech, banking,
investment services or a VASP. You can dissect a technical architecture, form a
view on where it's weak, and defend that view to the engineers who built it.
You're
genuinely technical. Proven experience auditing cloud (AWS/GCP),
IAM, encryption standards, CI/CD pipelines or blockchain technology. You can
read configuration and code well enough to test a control yourself rather than
relying on what you were told.
You know the
regulation and the standards behind it. Technology
risk guidelines, cybersecurity mandates and frameworks such as DORA, ISO 27001
and SOC 2, across multiple jurisdictions. You work to IIA Standards and you
know what makes a finding defensible. Degree in Computer Science, Cybersecurity
or IT, with CISA required; CRISC, CISM or CISSP are strong advantages.
You build AI,
you don't just use it. You've built or deployed
something that runs in production — automation, an analytics pipeline, a
testing agent — and embedded it into how a team works, not left it as a proof
of concept. You're comfortable in large datasets and confident with the statistics
behind a model.
You can audit
AI, which is not the same as using it. You
understand where models fail, how agent permissions sprawl, what an AI system's
audit trail should look like, and how to hold a deployment to account when
nobody wants to own the output. You can challenge an engineering decision and
keep the relationship, and you communicate clearly to engineers and to the Board
alike.
Skills Required
- 5+ years of experience in IT audit or technology compliance
- Degree in Computer Science, Cybersecurity, or Information Technology
- CISA certification
- Experience with IT regulatory frameworks and technology risk guidelines, including DORA
- Technical auditing experience with cloud environments such as AWS or GCP
- Technical auditing experience with containerized systems such as Kubernetes or Docker
- Experience auditing IAM, encryption standards, or blockchain technology
- Experience in regulated fintech, banking, investment services, or VASP environments
- CRISC, CISM, or CISSP certification
- Excellent spoken and written English
- Strong analytical, collaborative, communication, and discretion skills
What We Do
Deriv is a regulated online brokerage group that connects millions of customers in more than 150 countries to global financial markets. It offers contracts for difference (CFDs) and other derivatives covering forex, stocks and indices, cryptocurrencies, commodities, and Derived Indices. The company also provides online trading platforms and tools, including mobile trading, TradingView, Deriv MT5, cTrader, Deriv Trader, and Deriv Bot.
.jpg)






