Ceffu is a leading institutional-grade digital asset custody platform, offering secure, compliant and scalable solutions for enterprises, hedge funds and financial institutions. Our mission is to provide cutting-edge security and infrastructure to support the seamless integration of blockchain technology into institutional finance.
Job Summary
We are hiring a dedicated Internal Control Officer to support and work with the Board in Turkey. This role will focus on monitoring internal processes, controls, and compliance and reporting identified issues to ensure regulatory adherence and operational integrity.
This is a critical position that supports the company’s risk management and audit functions in alignment with Turkish regulatory frameworks applicable to crypto asset service providers.
Key Responsibilities
- Prepare and execute risk-based annual and periodic internal control plans approved by the responsible non-executive board member or the Board, and report findings and recommendations to Senior Management and relevant governance bodies.
- Perform continuous control activities across custody operations, customer asset safeguarding, reconciliations, transaction flows, whitelisting, onboarding, access rights, incident management, recordkeeping and reporting.
- Test whether controls required under SPK, MASAK, information systems and internal governance rules are properly implemented and operating effectively, including authority matrices, approval workflows and segregation-of-duties requirements.
- Assess the adequacy and effectiveness of controls addressing operational, financial, compliance, technology, cybersecurity and AML/CFT risks, particularly in identified high-risk areas.
- Review information systems control evidence in coordination with the CISO and Information Systems Specialist while remaining independent from control implementation.
- Review MASAK-related process controls, including customer due diligence, sanctions and wallet-screening evidence, suspicious-transaction escalation and recordkeeping, without replacing the responsibilities of the MASAK Compliance Officer.
- Lead the design and implementation of control mechanisms for new products, digital assets, blockchain services, technology initiatives and material changes to business processes.
- Identify and classify control deficiencies, report findings to the appropriate governance bodies and action owners, and track corrective and remediation actions to completion.
- Coordinate internal and external control reviews and support regulatory inspections and independent assurance activities by providing control evidence, testing files and remediation records.
- Coordinate with Risk Management and immediately escape any matter that may threaten customer assets or the safe operation of custody services to the responsible board member and the Board.
- Maintain the internal control framework, control procedures, control matrices, RCSAs and related governance documentation; collaborate with relevant business and control functions; and ensure alignment with Turkish regulatory expectations and Ceffu’s global internal control framework.
Requirements
- Bachelor’s degree from a four-year university program in accounting, finance, business administration, information systems, computer engineering or a related field.
- Minimum 3–5 years of relevant experience in internal control, internal audit, compliance monitoring, operational risk or information systems control.
- Strong understanding of internal control principles and frameworks, including COSO, the Three Lines Model and risk-based control methodologies.
- Good knowledge of applicable SPK and MASAK requirements, AML/CFT legislation, FATF Recommendations, segregation-of-duties principles and governance requirements applicable to crypto-asset service providers.
- Experience in process mapping, risk assessment, control design, control testing, audit-evidence preparation, issue remediation and governance reporting.
- Familiarity with relevant information systems and control frameworks such as COBIT and ISO 27001.
- Ability to independently challenge process owners, document findings objectively and communicate effectively with senior stakeholders and governance bodies.
- Strong analytical, stakeholder-management, communication and report-writing skills.
- Highest standards of confidentiality, integrity, professionalism and discretion when handling sensitive information.
- Professional proficiency in Turkish and English.
- Candidates must be based in Istanbul and able to work under the company’s hybrid working model.
Preferred Qualifications
- Experience within a regulated financial institution, payment or custody provider, fintech company or crypto-asset service provider.
- Knowledge of blockchain technologies, digital-asset custody and crypto-asset operations.
- Professional certifications such as CIA, CISA, CCSA, CRISC, CAMS, ISO 27001 Lead Auditor or an equivalent qualification are considered an advantage.