Internal IT Auditor (Regulated Fintech)

Deriv

Cyberjaya

On-site

MYR 150,000 - 230,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Deriv is seeking an experienced IT auditor to improve controls across our regulated fintech entities, including banking, VASP wallets, and crypto tech. You will assess IT governance, security, and data protection, and embed robust controls into daily operations.

Bring 5+ years of audit experience, deep regulatory knowledge (DORA, banking guidelines), and hands-on work with AWS/GCP, Kubernetes/Docker, IAM and encryption standards. English communication is essential.

Qualifications

  • 5+ years in IT audit or technology compliance within fintech or regulated environments.
  • Deep knowledge of IT regulatory frameworks (DORA, banking guidelines).
  • Proven experience auditing cloud environments, containerized systems, and security controls.

Responsibilities

  • Evaluate IT governance, system security and data protection controls.
  • Audit banking, VASP, and investment service entities for regulatory alignment.
  • Identify vulnerabilities and drive remediation with engineering teams.
  • Track ISO 27001, SOC 2, and DORA compliance across platforms.
  • Report findings to senior management and audit committees.

Skills

IT auditing
Cloud security (AWS/GCP)
Kubernetes/Docker
IAM & encryption standards
Blockchain/crypto tech

Education

Bachelor's degree in CS/Cybersecurity/IT
CISA certification (CRISC/CISM/CISSP a plus)

Tools

AWS
GCP
Kubernetes
Docker
cryptography tools

Job description

You’ll focus on technology, information security, and IT governance audits across our regulated business entities—spanning banking, virtual assets (VASPs), and investment services. You’ll conduct technology risk‑based regulatory audits, identify infrastructure vulnerabilities, and embed robust technical controls directly into the DNA of our operations.

This isn’t standard checklist IT auditing. It’s executing high‑stakes technology risk operations where your security and regulatory expertise safeguards our entire fintech infrastructure.

Why this matters

Your IT audit work across our regulated entities ensures our infrastructure, DevOps pipelines, and core platforms stand up to intense regulatory scrutiny and cybersecurity threats.

Your foresight and strategic insights directly determine whether our high‑growth products stay online, secure, and compliant in a heavily regulated global market.

Why Deriv
  • Audit cutting‑edge tech. You won't just be looking at spreadsheets. You’ll actively audit cloud environments (AWS/GCP), containerized applications (Kubernetes/Docker), algorithmic trading systems, VASP wallets, and cryptographic key management.
  • Partner closely with Engineering and InfoSec. Forget working in a silo. You will collaborate directly with software engineers and security architects to foster a culture of risk awareness and ensure robust IT controls are built into daily operations.
  • Master complex global regulations. Build deep, future‑proof expertise in highly demanding frameworks like DORA, local banking IT guidelines, and virtual asset technology requirements across multiple jurisdictions.
What You’ll Do
  • Evaluate internal technology controls across IT governance, system security, and data protection to ensure we consistently meet regulatory expectations.
  • Conduct rigorous IT audits across regulated banking, VASP, and investment service entities, keeping our infrastructure and DevOps pipelines aligned with the fintech compliance landscape.
  • Audit specialized core systems, including banking platforms, VASP wallets, cryptographic key management, and algorithmic trading systems to mitigate operational risks.
  • Identify security and compliance vulnerabilities, proactively highlighting areas for improvement to prevent cybersecurity breaches, regulatory penalties, and system downtime.
  • Track global tech‑regulation standards (such as ISO 27001, SOC 2, and DORA) to keep Deriv ahead of international technology risk developments.
  • Collaborate with internal engineering and InfoSec teams to ensure technical controls are seamlessly integrated into daily workflows.
  • Report tech risk audit findings and cyber posture insights directly to senior management and audit committees.
  • Drive IT remediation plans to completion, ensuring the risk of technological failure or non‑compliance is kept to an absolute minimum.
Who You Are
  • 5+ years in IT audit or technology compliance. Ideally with experience gained inside a regulated fintech, banking, investment services, or VASP environment.
  • Deep understanding of IT regulatory frameworks. You know your way around technology risk guidelines, cybersecurity mandates, and frameworks like DORA.
  • Strong technical auditing skills. You have proven experience auditing cloud environments (AWS/GCP), containerized systems (Kubernetes/Docker), IAM, encryption standards, or blockchain tech.
  • Certified professional. You hold a degree in CS, Cybersecurity, or IT, backed by a CISA certification (CRISC, CISM, or CISSP are big pluses).
  • Analytical and highly collaborative. You can dissect complex technical architectures, present actionable insights, and speak the language of both software engineers and senior leadership.
  • Clear communicator. Excellent spoken and written English, with the integrity and discretion required to handle sensitive compliance matters.
The Honest Reality

You will be auditing complex, fast‑evolving systems across multiple regulated environments where the compliance landscape is constantly shifting. You'll need to keep pace with everything from traditional banking regulations to cutting‑edge blockchain tech, and you must have the confidence to challenge engineering setups when necessary.

The work demands absolute rigor and high technical depth. In return, you’ll gain unparalleled, future‑proof IT audit expertise across the absolute cutting edge of fintech, crypto, and global banking.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

FinTech IT Risk & Compliance Auditor
FinTech IT Risk & Compliance Auditor

Deriv • Cyberjaya

On-site
MYR 150,000 - 230,000
Head of Internal Audit
Head of Internal Audit

Deriv • Cyberjaya

On-site
MYR 300,000 - 420,000
Global Tax Manager (Advisory)
Global Tax Manager (Advisory)

Deriv • Cyberjaya

On-site
MYR 120,000 - 150,000
Senior Compliance Analyst
Senior Compliance Analyst

Deriv • Cyberjaya

On-site
MYR 180,000 - 240,000
Internal Auditor
Internal Auditor

Ant International • Kuala Lumpur

On-site
MYR 120,000 - 180,000
VP of Legal & Compliance
VP of Legal & Compliance

Deriv • Cyberjaya

On-site
MYR 150,000 - 250,000
Senior In-house Legal Counsel (Regulatory)
Senior In-house Legal Counsel (Regulatory)

Deriv • Cyberjaya

On-site
MYR 240,000 - 420,000
Senior Specialist - Risk Management
Senior Specialist - Risk Management

Deriv • Cyberjaya

On-site
MYR 180,000 - 300,000
Senior Offensive Security Engineer
Senior Offensive Security Engineer

Deriv • Cyberjaya

Hybrid
MYR 180,000 - 280,000
Senior Associate Internal Audit
Senior Associate Internal Audit

FINEXUS Group • Kuala Lumpur

On-site
MYR 90,000 - 150,000