
Kraken, part of Payward, has spent 15 years building a globally accessible financial infrastructure platform to advance an open, global financial system. We encourage you to explore our culture page to understand what drives us and how we work.
The Team
Founded in 2011, Kraken is one of the world's longest-standing crypto platforms, trusted by over 10 million individuals and institutions. It offers spot trading, margin, futures, staking, and OTC services.
Payward's Risk & Audit function operates as an Integrated Assurance organization, unifying Internal Audit and Enterprise Risk Management. This function spans SOX Compliance, Enterprise Risk Management, and Internal Audit across multiple regulated entities and jurisdictions. The Audit team partners with co-sourced providers, reports directly to Audit Committee Chairs, and is building a technology-forward assurance capability at the forefront of crypto and financial innovation.
This role sits within Internal Audit and will lead the independent testing of IT general controls and IT application controls across the SOX program. You will assess the design and operating effectiveness of controls over access management, change management, system operations, and application-level processes, providing assurance to the Audit Committee, external auditors, and regulators.
The Opportunity
You will lead Internal Audit’s IT SOX controls testing program, building the testing approach, workpapers, and institutional knowledge from the ground up. This is a hands-on role with real program ownership at a crypto exchange, where the technology stack includes blockchain-native infrastructure, digital asset custody systems, on-chain and off-chain processing, and a rapid pace of engineering change. The systems are complex, deployments are frequent, and controls are consequential. If you seek an IT SOX role with genuinely interesting tech and real stakes, this is it.
Responsibilities
ITGC SOX Controls Testing
- Lead the execution of independent testing of IT General Controls (ITGCs) across key control domains: access management, change management, and system operations.
- Evaluate the design and operating effectiveness of IT controls across in-scope applications and infrastructure, including systems supporting blockchain-native operations, digital asset custody, and crypto trading platforms. Document testing procedures and results to meet Internal Audit and external auditor quality standards.
- Identify new systems, applications, or process changes that emerge during testing and assess their SOX implications in coordination with the SOX Compliance team.
- Build and maintain testing programs, templates, and workpapers to create a repeatable, scalable foundation for IT SOX testing.
- Identify opportunities to leverage AI-enabled workflows and data analytics to improve testing coverage and efficiency across IT control domains.
Remediation Validation & Issue Management
- Independently validate the remediation of open SOX findings, including material weaknesses and significant deficiencies, across ITGC control areas.
- Evaluate control deficiencies by performing root cause analysis and assessing the severity and pervasiveness of exceptions to inform deficiency classification.
- Assess whether management’s remediation actions are adequately designed and operating effectively before closing findings.
- Track remediation progress, escalate delays or gaps, and report status to Internal Audit leadership and the Audit Committee as required.
- Coordinate with the SOX Compliance team to ensure alignment on remediation expectations, timelines, and evidence requirements.
Stakeholder Engagement & Reporting
- Serve as a trusted Internal Audit point of contact for IT control owners across Engineering, Infrastructure, Security, and IT Operations. Bridge the gap between audit methodology and engineering culture, becoming fluent in both languages.
- Contribute to Internal Audit reporting to the Audit Committee, external auditor, and senior leadership on IT SOX testing coverage, findings, and remediation status.
- Partner with the business process SOX tester and co-sourced resources to ensure coordinated testing coverage across the full SOX program.
What You Bring
- 8+ years of experience in IT audit, internal audit, external audit, or SOX compliance, with significant exposure to IT general controls testing.
- Experience in crypto, fintech, payments, or technology-intensive environments with complex, rapidly evolving infrastructure.
- CISA and CPA certifications required. Candidates with one certification who are actively pursuing the other will be considered.
- Strong knowledge of ITGC frameworks, SOX compliance requirements, COSO, COBIT, and PCAOB auditing standards as they apply to IT controls.
- Hands-on experience testing ITGCs across access management, change management, and system operations.
- Technical fluency with enterprise technology environments – you don’t need to be an engineer, but you need to understand how systems, databases, and deployment pipelines work to effectively test the controls around them.
- Understanding of how IT controls underpin the reliability of financial reporting – you can connect an ITGC failure to its downstream impact on business process controls and the financial statements.
- Experience working with or alongside external auditors (Big 4 preferred) on SOX engagements.
- Experience operating across multi-entity structures or multiple jurisdictions.
- Effective communicator who can translate technical IT audit findings for control owners, engineering teams, senior leadership, and external stakeholders.
Nice to Haves
- Familiarity with blockchain infrastructure, digital asset custody systems, on-chain transaction processing, or crypto-native technology environments.
- Familiarity with CI/CD pipelines, GitLab or similar version control systems, cloud infrastructure (AWS, GCP), and modern deployment practices.
- Prior experience building or scaling an IT SOX testing program in a growth-stage or first-year SOX company.
- Familiarity with audit management platforms such as AuditBoard or Workiva.
- Familiarity with AI-assisted audit tools and willingness to adopt emerging technologies.
Timezone overlap
UTC-8–-5
Open to
US
Sign in to track applications and earn points.