You’ll join SumUp’s Global Internal Audit team, part of our wider G&A / GRC function, reporting directly to the Global Head of Internal Audit. This team plays a critical role in protecting SumUp’s integrity, supporting regulatory compliance, and strengthening trust with our Board, Audit Committee, and regulators.
As our Internal Auditor – IT security specialist, you’ll bring essential technology and data analytics expertise into a team that partners closely with senior leaders across the business. You’ll be the go‑to expert for technology‑focused audits, helping shape how we assess IT risks, controls, and governance across a fast‑scaling global fintech.
In this role, you will support the delivery of SumUp’s approved Internal Audit Plan, with a strong focus on technology, data, and systems risk.
You’re a hands‑on IT auditor who enjoys combining technical depth with clear communication and stakeholder collaboration.
What You’ll Do
- Plan and execute IT internal audits in line with the annual audit plan
- Assess IT general controls, security, governance, and risk management frameworks
- Prepare clear, insightful audit reports, presenting findings and recommendations to senior stakeholders
- Use data analytics to improve audit efficiency, sample testing, and risk identification
- Support ad-hoc audit projects and regulatory‑related reviews
- Contribute to the continuous improvement of internal audit methodologies, frameworks, and templates
- Stay up to date with technology standards, regulatory developments, and industry best practices
- Build strong relationships across the business and promote a proactive internal controls culture
- Conduct targeted audits of AWS security standards and access controls across our cloud environment, ensuring credit card data stored in cloud services is adequately protected
- Perform risk‑based reviews of payment products and ensure security requirements are consistently embedded throughout the development lifecycle
- Identify anomalies or excessive privileges across different systems and payment platforms
Must‑have experience
- Minimum 4years’ experience in IT / Internal Audit within a regulated financial services environment
- Strong knowledge of audit standards, risk management, and internal controls
- Experience auditing IT controls and frameworks such as COBIT, ISO27001, PCIDSS, ITIL, NIST, GDPR
- Practical exposure to areas like data security, cloud architecture, disaster recovery, security operations, or network infrastructure
- Advanced data analytics skills
- Professional‑level English (written and spoken)
Nice to have
- Professional certifications such as CIA, CISA, CPA
- Additional IT/security certifications (CISSP, CISM, CRISC, ISO22301, or similar)
- Experience with audit‑related data analytics tools
What sets you apart
- High ethical standards and integrity
- Strong analytical and problem‑solving mindset
- Confidence influencing change and challenging the status quo constructively
- Ability to work independently in a multinational environment
#J-18808-Ljbffr…
