logo
AI Resume Tailoring Sign in to use this AI Cover Letter Sign in to use this

Job Description

At Deriv, you’ll deliver independent, evidence-led IT audit work that helps strengthen the security, reliability, and governance of the technology supporting our international business. This is a hands-on individual contributor role focused on technology and cybersecurity assurance. You’ll examine technical controls, analyse system evidence, investigate weaknesses, and develop clear findings that explain their business impact. Working with IT audit managers and colleagues, you’ll take ownership of assigned audit work across infrastructure, cloud environments, applications, engineering processes, and operational resilience. You’ll also support integrated reviews with regulatory and operational auditors. Why This Matters Deriv's mission is Trading for Anyone, Anywhere, Anytime. Millions of traders, around the clock, across regulatory regimes. Real money, real regulations, real consequences. The technology behind that has to be secure, resilient, and provably well controlled. Auditing it means going to the evidence, not the policy document. We are building audit that is proactive, not annual. Why Deriv We're in production, not planning. 65%+ of customer enquiries resolved by AI, with genuine judgment, not decision trees Automated security review on every pull request 400+ users on our internal workflow orchestration platform You'll audit a technology estate that is already running AI in production, and you'll help shape how it gets assured. We share what we learn at Deriv<ed> (derivai.substack.com). What You’ll Do Plan IT audit work. Support technology risk assessments, system and process walkthroughs, and the development of audit scope, objectives, and testing programmes. Test technology and cybersecurity controls. Assess identity and privileged access management, infrastructure and network security, vulnerability management, security monitoring, incident response, and third-party technology controls. Review cloud and engineering practices. Perform assigned testing of cloud configurations, secure development, CI/CD pipelines, change management, application security, and secrets management. Assess application and data controls. Test automated business controls, interfaces, data integrity and protection, and relevant governance and controls for AI-enabled systems. Evaluate technology resilience. Review backup and recovery, disaster recovery testing, service availability, and technology dependencies supporting business continuity. Analyse technical evidence. Examine configurations, access records, logs, change histories, and test results; investigate exceptions and assess their risk, root cause, and any compensating controls. Document and communicate findings. Maintain clear, reproducible working papers and draft findings that explain the evidence, business impact, and practical recommendations. Validate remediation. Review closure evidence and retest controls where appropriate, escalating inadequate fixes, delays, or unresolved issues to the audit manager. Work constructively with stakeholders. Discuss systems and observations with engineering, security, and technology teams while maintaining independence, confidentiality, and professional scepticism. Improve audit delivery and build expertise. Use analytics, scripts, automation, and responsibly governed AI tools to improve testing. Stay current with technology risks and audit standards. Senior specialists will lead defined workstreams and support less-experienced auditors. Who You Are Relevant IT audit or technology assurance experience, ideally in regulated financial services, fintech, or another technology-intensive environment. Practical experience testing IT controls, assessing technical evidence, and documenting audit conclusions. Experience in cybersecurity, cloud, or engineering assurance is an advantage. A working understanding of cloud environments, infrastructure, cybersecurity, identity and access management, software development, application controls, and technology resilience, with deeper capability in one or more areas. The ability to examine system evidence directly and distinguish an effectively operating control from a documented policy or an unsupported explanation. Knowledge of risk-based auditing, the IIA Global Internal Audit Standards, and ISACA IT audit guidance, with familiarity with relevant frameworks such as COBIT, NIST, and ISO/IEC 27001. The ability to translate technology risks and applicable regulatory requirements into practical audit tests and explain technical weaknesses in business terms. Strong analytical skills, attention to detail, and the curiosity to investigate inconsistencies and understand root causes. The ability to manage assigned work and meet deadlines. Senior specialists should be able to deliver defined IT audits or complex workstreams with limited supervision, subject to managerial review. Excellent written and spoken English, including the ability to produce clear working papers and discuss findings with technical and non-technical stakeholders. A relevant degree in information systems, computer science, cybersecurity, or a related discipline. CISA, CIA, or an equivalent relevant audit qualification is preferred. Demonstrable interest in and practical use of data analysis, scripting, automation, or AI to improve work, supported by confidentiality safeguards and validation of outputs. What Success Looks Like Thorough technical testing delivered on time, reliable evidence supporting every conclusion, clear findings that identify meaningful technology risks, and remediation validated through evidence rather than assurances alone. The Honest Reality This is demanding work. You'll deliver findings that engineering and security teams won't always welcome, and you'll defend them with evidence. You'll balance thoroughness with relationships, and make calls on risk with incomplete data. But you'll audit real systems handling real transactions, and your conclusions will carry weight. If you want to check policies against checklists, this isn't it. If you want to test what actually runs, it might be.

Do you match this job?

Here is what this employer asked for. Sign in and we will fill in your half.

  • Role IT Audit Specialist
  • Experience 3-4 years
  • Education Bachelor Degree
  • Work type On-site
  • Location United Arab Emirates
Check my match (free)
Deriv
Financial Services & Fintech · 500+ Members

Deriv is an online trading broker with an office in Dubai.

Deriv offers retail traders platforms for trading contracts for difference and options on currencies, stocks, commodities and its own indices.

Job Overview
Eligibility
United Arab Emirates Right to work in the United Arab Emirates required.
Workplace
On-site
Job Posted:
2 months ago
Job Type
Full Time
Education
Bachelor Degree
Experience
3-4 years

Share This Job: