Kraken Digital Asset Exchange Logo

Kraken Digital Asset Exchange

SOX Auditor - IT Controls Manager

Posted 2 Hours Ago
Be an Early Applicant
Remote
Hiring Remotely in United States
83K-167K Annually
Senior level
Remote
Hiring Remotely in United States
83K-167K Annually
Senior level
Lead IT SOX controls testing for ITGCs (access, change, operations) across blockchain-native and enterprise systems. Build testing programs, validate remediation, perform root-cause analysis, report to Audit Committee, and collaborate with Engineering, Security, and external auditors to ensure SOX compliance and scalable audit processes.
The summary above was generated by AI
Building the Future of Open Finance

Payward - the parent company behind Kraken, NinjaTrader, Breakout, xStocks, Payward Services and CF Benchmarks - has spent the last 15 years building one of the most modern and globally accessible financial infrastructure platforms in the industry, built to advance an open, global financial system.


Before you apply, we encourage you to explore our culture page to understand what drives us and how we work.

The team

Founded in 2011, Kraken is one of the world's longest-standing crypto platforms, trusted by over 10 million individuals and institutions across the globe. It offers spot trading, margin, futures, staking, and OTC services, with products built for both individual investors and institutional clients.

 

Payward's Risk & Audit function operates as an Integrated Assurance organization, bringing together Internal Audit and Enterprise Risk Management under a unified risk oversight strategy. The function spans SOX Compliance, Enterprise Risk Management, and Internal Audit across multiple regulated entities and jurisdictions. The Audit team partners with co-sourced providers, maintains direct reporting lines to the Global and Local Audit Committee Chairs, and is building a technology-forward assurance capability at the forefront of crypto and financial innovation.

 

This role sits within Internal Audit and will lead the independent testing of IT general controls and IT application controls across the SOX program. You will assess whether controls over access management, change management, system operations, and application-level processes are designed and operating effectively, providing the assurance that the Audit Committee, external auditors, and regulators rely on.

 
The opportunity

You will lead Internal Audit’s IT SOX controls testing program building the testing approach, workpapers, and institutional knowledge from the ground up. This is a hands-on role with real program ownership and you’ll be doing it at a crypto exchange — where the technology stack spans blockchain-native infrastructure, digital asset custody systems, on-chain and off-chain processing, and a pace of engineering change that most companies never encounter. The systems are complex, the deployments are frequent, and the controls are consequential. If you want an IT SOX role where the tech is genuinely interesting and the stakes are real, this is it.

 

Responsibilities span the following areas:

ITGC SOX controls testing

  • Lead the execution of independent testing of IT General Controls (ITGCs) across key control domains: access management, change management, and system operations.

  • Evaluate the design and operating effectiveness of IT controls across in-scope applications and infrastructure, including systems that support blockchain-native operations, digital asset custody, and crypto trading platforms. Document testing procedures and results to meet Internal Audit and external auditor quality standards.

  • Identify new systems, applications, or process changes that emerge during testing and assess their SOX implications in coordination with the SOX Compliance team.

  • Build and maintain testing programs, templates, and workpapers that create a repeatable, scalable foundation for IT SOX testing.

  • Identify opportunities to leverage AI-enabled workflows and data analytics to improve testing coverage and efficiency across IT control domains.

 

Remediation validation & issue management

  • Independently validate the remediation of open SOX findings, including material weaknesses and significant deficiencies, across ITGC control areas.

  • Evaluate control deficiencies by performing root cause analysis and assessing the severity and pervasiveness of exceptions to inform deficiency classification.

  • Assess whether management’s remediation actions are adequately designed and operating effectively before closing findings.

  • Track remediation progress, escalate delays or gaps, and report status to Internal Audit leadership and the Audit Committee as required.

  • Coordinate with the SOX Compliance team to ensure alignment on remediation expectations, timelines, and evidence requirements.

 

Stakeholder engagement & reporting

  • Serve as a trusted Internal Audit point of contact for IT control owners across Engineering, Infrastructure, Security, and IT Operations. Bridge the gap between audit methodology and engineering culture — these teams speak a different language than accountants, and you need to be fluent in both.

  • Contribute to Internal Audit reporting to the Audit Committee, external auditor, and senior leadership on IT SOX testing coverage, findings, and remediation status.

  • Partner with the business process SOX tester and co-sourced resources to ensure coordinated testing coverage across the full SOX program.

 
What you bring
  • 8+ years of experience in IT audit, internal audit, external audit, or SOX compliance, with significant exposure to IT general controls testing.

  • Experience in crypto, fintech, payments, or technology-intensive environments with complex, rapidly evolving infrastructure.

  • CISA and CPA certifications required. Candidates with one certification who are actively pursuing the other will be considered.

  • Strong knowledge of ITGC frameworks, SOX compliance requirements, COSO, COBIT, and PCAOB auditing standards as they apply to IT controls.

  • Hands-on experience testing ITGCs across access management, change management, and system operations.

  • Technical fluency with enterprise technology environments — you don’t need to be an engineer, but you need to understand how systems, databases, and deployment pipelines work to effectively test the controls around them.

  • Understanding of how IT controls underpin the reliability of financial reporting — you can connect an ITGC failure to its downstream impact on business process controls and the financial statements.

  • Experience working with or alongside external auditors (Big 4 preferred) on SOX engagements.

  • Experience operating across multi-entity structures or multiple jurisdictions.

  • Effective communicator who can translate technical IT audit findings for control owners, engineering teams, senior leadership, and external stakeholders.

 
Nice to haves
  • Familiarity with blockchain infrastructure, digital asset custody systems, on-chain transaction processing, or crypto-native technology environments.

  • Experience with CI/CD pipelines, GitLab or similar version control systems, cloud infrastructure (AWS, GCP), and modern deployment practices.

  • Prior experience building or scaling an IT SOX testing program in a growth-stage or first-year SOX company.

  • Familiarity with audit management platforms such as AuditBoard or Workiva.

  • Familiarity with AI-assisted audit tools and willingness to adopt emerging technologies.

Unless a specific application deadline is stated in the job posting, applications are accepted on an ongoing basis.

Please note, applicants are permitted to redact or remove information on their resume that identifies age, date of birth, or dates of attendance at or graduation from an educational institution.

We consider qualified applicants with criminal histories for employment on our team, assessing candidates in a manner consistent with the requirements of the San Francisco Fair Chance Ordinance.

Payward is powered by people from around the world and we celebrate the diverse talents, backgrounds, contributions, and unique perspectives that everyone brings to the table. We hire based on merit, seeking out people with the right abilities, knowledge, and skills for the job. We encourage you to apply for roles where you don't fully meet the listed requirements, especially if you're passionate or knowledgeable about crypto.

We may ask candidates to complete job-related skills or work-style assessments as part of our hiring process. These assessments evaluate competencies relevant to the role and are applied consistently across candidates for similar positions. Results are considered alongside experience and interviews, and are not the sole basis for any employment decision.

As an equal opportunity employer, we don't tolerate discrimination or harassment of any kind, whether based on race, ethnicity, age, gender identity, citizenship, religion, sexual orientation, disability, pregnancy, veteran status, or any other protected characteristic as outlined by federal, state, or local laws.

Stay in the know

Follow us on Twitter

Learn on the Kraken Blog

Connect on LinkedIn


Candidate Privacy Notice

Similar Jobs

15 Minutes Ago
Remote
USA
85K-85K Annually
Mid level
85K-85K Annually
Mid level
Computer Vision • Healthtech • Information Technology • Logistics • Machine Learning • Software • Manufacturing
Own the full sales cycle to acquire SMB customers in a new vertical, build the go-to-market playbook, track pipeline in Salesforce, partner with leadership, and feed learnings into product and marketing.
Top Skills: CRMSalesforce
18 Minutes Ago
Easy Apply
Remote
United States
Easy Apply
230K-300K Annually
Mid level
230K-300K Annually
Mid level
Artificial Intelligence • Fintech • Hardware • Information Technology • Sales • Software • Transportation
The Account Executive will develop and close business with large enterprise clients, managing relationships and driving revenue growth across several industries. Responsibilities include prospecting new clients, leveraging executive relationships, resolving issues, utilizing technical resources, and meeting sales targets while keeping informed on market trends.
19 Minutes Ago
Easy Apply
Remote
United States
Easy Apply
230K-300K Annually
Mid level
230K-300K Annually
Mid level
Artificial Intelligence • Fintech • Hardware • Information Technology • Sales • Software • Transportation
As an Enterprise Account Executive, you will develop and close business with large prospects, establishing relationships and leveraging insights to drive expansion and meet revenue goals.
Top Skills: AnalyticsSaaSSoftware

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account