
Senior Internal Audit Manager - IT & Information Security
Ebury · Madrid
Job description
Ebury helps ambitious businesses unlock global growth, and we take the same approach with our people. We encourage innovation and movement, collaboration and problem-solving, and foster an environment where everyone can feel they belong, are valued, supported and empowered to succeed. If you’re a collaborator who wants to help transform how businesses operate globally, get in touch - we’d love to discuss how Ebury can accelerate your career so you can shape the future. Senior Internal Audit Manager - IT & Information Security Ebury Madrid Office - Hybrid: 4 days in the office, 1 day working from home per week Role Overview The Senior Audit Manager - IT & Information Security is a technology risk expert responsible for evaluating and enhancing the internal control environment across cloud infrastructure, cyber security controls, third-party ecosystems, and engineering platforms used in the SDLC. This candidate combines deep technical expertise in cloud security and DevSecOps with financial technology regulations (e.g., DORA, FCA PS21/3, PRA Operational Resilience, ISO 27001). Qualification Area Ideal Candidate Specification Target Experience 5+ years in IT/Cyber Audit within cloud-native Fintech platforms, financial institutions, or Big 4 tech practice. Core Credentials CISA, CISSP, CISM, or CRISC required; dual ACA/CIA qualification preferred. Technical Stack Cloud Infrastructure (AWS), Identity & Access Management, SIEM/SOC (Splunk, CrowdStrike, ReliaQuest), GRC (AuditBoard). Regulatory Knowledge DORA, FCA PS21/3, PRA Operational Resilience, ISO 27001, COBIT, NIST framework, and related. Domain Focus Payments lifecycle, treasury automation platforms, API security, third-party/BPO risk management. Job Purpose The Senior Audit Manager - IT & Information Security leads the design, execution, and delivery of the annual IT Audit Plan. Reporting to the Group Head of Internal Audit, the role provides independent assurance to executive stakeholders (CIO, CISO, COO, CRO, DPO) and the Audit Committee regarding platform resilience, cybersecurity maturity, data protection, and adherence to evolving international regulatory standards. Key Responsibilities Technology & Cyber Security Assurance
Verified and listed by ActiveJobs. Applications are made directly on Ebury's own career page — we never sit in the middle.