Payward - the parent company behind Kraken, NinjaTrader, Breakout, xStocks, Payward Services and CF Benchmarks - has spent the last 15 years building one of the most modern and globally accessible financial infrastructure platforms in the industry, built to advance an open, global financial system.
Before you apply, we encourage you to explore our culture page to understand what drives us and how we work.
Founded in 2011, Kraken is one of the world's longest-standing crypto platforms, trusted by over 10 million individuals and institutions across the globe. It offers spot trading, margin, futures, staking, and OTC services, with products built for both individual investors and institutional clients.
Payward's Audit & Risk function operates as an Integrated Assurance organization, bringing together Internal Audit and Enterprise Risk Management under a unified risk oversight strategy. The function spans Internal Audit, SOX Compliance, and Enterprise Risk Management across multiple regulated entities and jurisdictions. Internal Audit partners with co-sourced providers, maintains direct reporting lines to the Global and Local Audit Committees, and is building a technology-forward assurance capability at the forefront of crypto and financial innovation.
You'll partner with Internal Audit leadership to execute the technology audit program, evaluating the design and operating effectiveness of controls across a broad IT environment - cybersecurity, identity and access management, the software development lifecycle, data and privacy, operational resilience, and AI. This is a hands-on role with real ownership over scope, stakeholders, and outcomes - you'll shape how safely Payward manages some of the highest-risks it carries. You'll be doing it at a crypto exchange - where the infrastructure spans blockchain-native systems and digital asset custody, deployment cycles are fast, and client trust depends on getting the controls right. If you want technology audit work where the systems are genuinely complex and the stakes matter, this is it.
Responsibilities span the following areas:
Technology audit execution
Plan and execute technology audits across a broad IT environment - cybersecurity, cloud, identity and access management, the software development lifecycle (SDLC) and change management
Assess the security of core systems holding sensitive customer records and identity documentation - access controls, data protection, monitoring, and regulatory and policy compliance
Assess operational resilience (business continuity, disaster recovery, and resilience testing), incident management, technology risk management, and third-party technology oversight
Review data governance, privacy, and data-lake controls, and assess AI governance, security, and privacy across the organization's use of AI and machine-learning systems
Test the design and operating effectiveness of IT general controls and application controls against frameworks such as ISO 27001, NIST CSF, SOC 2, or COBIT; identify gaps, perform root cause analysis, and assess business and financial-reporting impact
Apply AI-enabled workflows - AI-assisted testing, anomaly detection, and analytics - to expand coverage and efficiency, with human ownership of conclusions
Engagement & issue management
Lead multiple audit engagements concurrently, managing planning, fieldwork, and reporting end-to-end
Document audit findings, including control gaps and root cause, and draft clear, well-supported workpapers and reports
Track and validate remediation of identified issues, escalating delays or gaps to Internal Audit leadership
Contribute to the continuous improvement of audit methodologies and frameworks, and ensure conformance with the IIA Global Internal Audit Standards and the function's quality assurance requirements
Lead engagement teams, including staffing and coordinating co-sourced specialists, to ensure quality and timely delivery across audits
Stakeholder engagement & reporting
Serve as a trusted point of contact for control owners across Engineering, Infrastructure, and Security teams to communicate audit results and advise on control improvements, while maintaining audit independence
Translate technical findings into clear, actionable conclusions for non-technical stakeholders and senior leadership
Partner with other Internal Audit team members and co-sourced resources to ensure coordinated coverage across the audit plan
5-8 years in IT audit, information security, or a related technology risk function, ideally within financial services, fintech, or crypto
Broad IT audit experience across several of: cybersecurity, identity and access management, ITGCs, cloud, SDLC and change management, data and privacy, operational resilience, and third-party technology risk
Strong grasp of control frameworks (ISO 27001, NIST CSF, SOC 2, or COBIT) and cloud environments (AWS, GCP, Azure)
Working knowledge of data governance and privacy (e.g., GDPR), with exposure to AI governance, security, and privacy
Technically fluent with enterprise technology (systems, databases, deployment pipelines) and able to translate findings clearly for engineers and senior leaders alike
Applies generative AI responsibly, with human oversight, to improve testing coverage and efficiency
Relevant certifications: CISA, CISSP, CRISC, CIA, or equivalent
Familiarity with blockchain infrastructure, digital asset custody, or crypto-native technology environments
Experience with CI/CD pipelines, version control, and modern deployment practices.
Exposure to operational resilience and ISO 27001 certification environments
Unless a specific application deadline is stated in the job posting, applications are accepted on an ongoing basis.
Please note, applicants are permitted to redact or remove information on their resume that identifies age, date of birth, or dates of attendance at or graduation from an educational institution.
We consider qualified applicants with criminal histories for employment on our team, assessing candidates in a manner consistent with the requirements of the San Francisco Fair Chance Ordinance.
Our commitmentPayward is powered by people from around the world and we celebrate the diverse talents, backgrounds, contributions, and unique perspectives that everyone brings to the table. We hire based on merit, seeking out people with the right abilities, knowledge, and skills for the job. We encourage you to apply for roles where you don't fully meet the listed requirements, especially if you're passionate or knowledgeable about crypto.
We may ask candidates to complete job-related skills or work-style assessments as part of our hiring process. These assessments evaluate competencies relevant to the role and are applied consistently across candidates for similar positions. Results are considered alongside experience and interviews, and are not the sole basis for any employment decision.
As an equal opportunity employer, we don't tolerate discrimination or harassment of any kind, whether based on race, ethnicity, age, gender identity, citizenship, religion, sexual orientation, disability, pregnancy, veteran status, or any other protected characteristic as outlined by federal, state, or local laws.
Stay connected
Follow us on Twitter
Learn on the Kraken Blog
Connect on LinkedIn
Candidate Privacy Notice
Skills Required
- 5-8 years in IT audit, information security, or related technology risk function
- Experience auditing cybersecurity, identity and access management, ITGCs, cloud, SDLC/change management, data/privacy, operational resilience, and third-party tech risk
- Strong grasp of control frameworks (ISO 27001, NIST CSF, SOC 2, COBIT)
- Experience with cloud environments (AWS, GCP, Azure)
- Working knowledge of data governance and privacy (e.g., GDPR) and exposure to AI governance, security, and privacy
- Technical fluency with enterprise systems, databases, and deployment pipelines; ability to translate findings for engineers and leaders
- Apply generative AI responsibly with human oversight to improve testing coverage and efficiency
- Relevant certifications such as CISA, CISSP, CRISC, CIA
- Familiarity with blockchain infrastructure, digital asset custody, or crypto-native environments
- Experience with CI/CD pipelines, version control, and modern deployment practices
- Exposure to operational resilience programs and ISO 27001 certification environments
Kraken Digital Asset Exchange Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Kraken Digital Asset Exchange and has not been reviewed or approved by Kraken Digital Asset Exchange.
-
Fair & Transparent Compensation — Pay is considered competitive for many roles, with strong total compensation reported for in‑demand technical and senior positions. Market‑aligned packages are highlighted across key functions, indicating the ability to reach top‑of‑market for certain hires.
-
Equity Value & Accessibility — Equity grants are available for most roles, complemented by bonus programs and the option to receive a portion of pay in crypto. This ownership‑oriented design is positioned as part of the standard total compensation approach.
-
Flexible Benefits — A remote‑first operating model, flexible time off, and a remote‑workstation setup bonus emphasize autonomy and location flexibility. Core benefits are framed to support distributed work across multiple regions.
Kraken Digital Asset Exchange Insights
What We Do
Kraken is one of the world’s longest-standing and most secure crypto platforms. Our mission is to accelerate the global adoption of crypto, so that everyone can achieve financial freedom and inclusion. Globally, Kraken clients trade more than 200 digital assets and 6 different national currencies, including GBP, EUR, USD, CAD, CHF, and AUD. Kraken was founded in 2011 and was one of the first platforms to offer spot trading with margin,, staking, regulated derivatives and index services. Trusted by over 10 million individuals, traders and institutions around the world, Kraken offers professional 24/7/365 client support along with one of the fastest, most performant trading platforms available. Kraken has set the industry standard for transparency and client trust, and was the first crypto platform to conduct Proof of Reserves. In 2024, Kraken ranked 12th in Newsweek's Global Top 100 list of Most Loved Workplaces. This recognition reflects our ongoing commitment to providing a flexible workplace that prioritizes wellbeing and career development. Kraken prioritizes client-centricity, security, and superior products, valuing merit and encouraging bold ideas within a transparent communication framework. Kraken offers a flexible, asynchronous, and globally remote work culture, allowing its employees (aka Krakenites) to balance team and personal needs. Kraken provides diverse learning and development programs, enabling Krakenites to chart their own professional paths in the crypto industry. Benefits include globally competitive compensation (with crypto payment options), flexible time off, wellness perks, and annual team retreats. Kraken's collaborative culture promotes authenticity, humility, and respect, encouraging candid interactions and valuing diverse perspectives from its global team. Crypto conviction is central to Kraken's ethos, driving product and service development. The company views challenges as opportunities for creative problem-solving, remaining adaptable in the fast-paced crypto industry. Kraken seeks individuals with an entrepreneurial spirit and a curious, self-starting approach to complex problems. The company fosters a culture of accountability and clear communication, valuing critical feedback for continuous improvement. Overall, Kraken's EVP reflects its commitment to building a bridge from traditional finance to crypto, both in its broader mission and in supporting employees transitioning to crypto careers.
Why Work With Us
Work at Kraken to be part of a mission-driven crypto revolution. Enjoy a flexible, remote-first culture that values bold ideas. Grow your career with competitive benefits and diverse learning opportunities. Join a collaborative team that embraces innovation, accountability, and globally inclusive perspectives.
Gallery








