Ceffu logo

Internal Auditor - Digital Asset / Fintech / Crypto

CeffuApplies on LinkedInFinance
Hiring from
Turkey
Work type
Hybrid
Posted
Is this job info correct?
Show job description

About Ceffu

Ceffu is a leading institutional-grade digital asset custody platform, offering secure, compliant, and scalable solutions for enterprises, hedge funds, and financial institutions. Our mission is to provide cutting-edge security and infrastructure to support the seamless integration of blockchain technology into institutional finance.


Job Summary

We are seeking a highly motivated and detail-oriented Internal Auditor to join our growing team in Turkey. This role will be instrumental in evaluating and improving the effectiveness of governance, risk management, and internal controls in compliance with both local and global regulatory requirements for crypto asset service providers.


Key Responsibilities

  • Prepare and execute a risk-based annual internal audit plan covering the company’s units, activities, systems and material outsourced or group-supported processes.
  • Conduct independent audits across operational, financial and regulatory functions, including compliance with applicable SPK, MASAK, information systems, internal policy, custody, accounting, recordkeeping, outsourcing and conflict-of-interest requirements.
  • Evaluate the design and effectiveness of the company’s internal control, risk management and MASAK compliance frameworks without assuming ownership of, or operational responsibility for, those functions.
  • Audit custody operations and controls relating to customer asset safeguarding, reconciliations, transaction flows, wallet and key-management governance, access rights, incident handling and business continuity and recovery arrangements.
  • Perform audit testing of information systems governance, information security, access and change management, incident management, backup and recovery, outsourcing, logging, asset inventories and applicable TÜBİTAK controls.
  • Assess whether internal policies and procedures remain adequate, are implemented effectively and are reviewed at least annually or following material regulatory, operational or technological changes.
  • Prepare objective internal audit reports for the Board, including findings, risk ratings, root causes, recommendations, responsible action owners and remediation deadlines.
  • Monitor remediation of audit findings and risk-mitigation actions, and report overdue or material findings to the Board.
  • Perform regulatory inspections and provide complete audit evidence and documentation when requested by competent authorities.
  • Maintain and enhance internal audit methodologies, tools and documentation; remain informed of Turkish crypto-asset regulations and professional auditing standards; and coordinate with relevant functions solely for evidence collection and remediation monitoring while preserving Internal Audit’s independence.


Requirements

  • Bachelor’s degree from a four-year university program in accounting, finance, business administration, information systems, computer engineering or a related field.
  • Minimum five years of relevant experience in internal audit, information systems audit, control assurance, IT risk, information security controls, regulatory compliance or technology risk.
  • Experience within banking, financial services, payment or electronic-money institutions, fintech companies, custody providers or crypto-asset service providers.
  • Valid SPK Information Systems Independent Audit Licence, as required under the applicable regulatory framework.
  • Strong knowledge of internal audit practices, control-testing methodologies, risk management frameworks and compliance principles.
  • Good knowledge of applicable SPK internal-systems requirements, MASAK compliance-program obligations, AML/CFT regulations, FATF Recommendations, Travel Rule requirements, information systems governance and custody operational risks.
  • Experience auditing information security, IT governance, access and change management, cloud infrastructure, blockchain platforms, wallet and custody solutions or API security.
  • Ability to conduct audits independently, challenge process owners objectively and maintain appropriate professional independence while collaborating with relevant functions.
  • Strong analytical, report-writing, stakeholder-management and communication skills in both Turkish and English.
  • Highest standards of confidentiality, integrity, professional ethics and discretion when handling sensitive information.
  • Candidates must be based in Istanbul and able to work under the company’s hybrid working model.


Preferred Qualifications

  • Professional certification such as CIA, CISA, CRMA, ISO 27001 Lead Auditor, CPA or an equivalent qualification.
  • Direct internal audit experience within a crypto-asset service provider, digital-asset custodian, crypto exchange or regulated fintech company.
  • Experience auditing blockchain platforms, wallet and key-management solutions, digital-asset custody infrastructure, cloud environments or API security.
  • Practical understanding of KYC/AML processes, cybersecurity controls and applicable data-protection and privacy frameworks.
  • Experience performing audits, reviews or regulatory inspections involving SPK, MASAK, TÜBİTAK or other Turkish financial supervisory authorities.
  • Experience auditing material outsourced or group-supported technology and operational processes.




Similar jobs

Apply on LinkedIn