Senior Internal Audit Manager - IT & Information Security

Ebury
Madrid
Workplace: HybridFull timeFunction: CybersecurityExperience: 5+ yearsSkills: ["Risk assessment","Stakeholder management","Communication","Mentoring","Collaboration"]

Lead risk-based internal audits for cloud infrastructure, cybersecurity controls, third-party platforms, and engineering controls across the SDLC. You’ll execute the annual IT Audit Plan, assessing SOC monitoring, incident response, SIEM/EDR coverage, and ITGC/ITACs within CI/CD pipelines. Partner with executives and the Audit Committee to deliver pragmatic, risk-ranked findings, ensuring alignment with regulatory requirements such as DORA, operational resilience, ISO 27001, and data privacy obligations.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Ebury
Ebury
1 day ago

Senior Internal Audit Manager - IT & Information Security

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 41 minutes agoStatus: Live

Job Summary

Lead risk-based internal audits for cloud infrastructure, cybersecurity controls, third-party platforms, and engineering controls across the SDLC. You’ll execute the annual IT Audit Plan, assessing SOC monitoring, incident response, SIEM/EDR coverage, and ITGC/ITACs within CI/CD pipelines. Partner with executives and the Audit Committee to deliver pragmatic, risk-ranked findings, ensuring alignment with regulatory requirements such as DORA, operational resilience, ISO 27001, and data privacy obligations.
Location: Madrid
Workplace: Hybrid
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Manager level

Key Responsibilities

  • •Lead risk-based audits across cloud infrastructure, network security, IAM, privileged access, and containerized deployment environments.
  • •Assess cyber defense controls including SOC monitoring, incident response, SIEM integration (Splunk), and EDR deployments (CrowdStrike).
  • •Audit IT General Controls (ITGCs) and automated application controls (ITACs) integrated into CI/CD deployment pipelines.
  • •Evaluate third-party vendor risk management and hosted assurance reviews for critical SaaS platforms, including operational resilience requirements (e.g., DORA, FCA PS21/3).
  • •Conduct regulatory alignment and readiness checks (e.g., ISO 27001, PCI DSS, operational resilience regimes) and deliver formal audit reports to executive and board audit committees.

Pay and Benefits

Perks:Health Insurance

Key Requirements

  • •5+ years in IT/Cyber Audit within cloud-native fintech platforms, financial institutions, or Big 4 tech practice.
  • •CISA, CISSP, CISM, or CRISC required; dual ACA/CIA qualification preferred.
  • •Experience auditing cloud-native digital architecture (microservices, containerization, API integrations) and delivering annual IT risk assessments/audit plans.
  • •Proven ability to evaluate end-to-end payment processing controls (authorisation, clearing, settlement, reconciliation).
  • •Ability to translate complex cybersecurity/technical risks into clear business insights for non-technical executives.
Experience:5+ yearsFintechCloud securityBig 4
Skills:Risk assessmentStakeholder managementCommunicationMentoringCollaboration
Certifications:CISACISSPCISMCRISCCIAACA
Tech Stack:AWSIdentity & Access ManagementSIEMSOCSplunkCrowdStrikeReliaQuestAuditBoardCI/CDMicroservicesContainerizationAPI integrations

Company Brief

Ebury
Provides international payments, FX, and treasury solutions for SMEs and mid-market companies, enabling cross-border transactions, multi-currency accounts, and financing services to support global trade and cash flow management.
Industry: Payments
Company Size: Enterprise (1,001+ employees)
Growth: Established Company
Funding: Private Equity Backed
Headquarters: London, United Kingdom
Founded: 2009
WebsiteLinkedIn