Back to jobs

    About Kraken

    Payward, the parent company behind Kraken, NinjaTrader, Breakout, xStocks, Payward Services, and CF Benchmarks, has spent 15 years building a globally accessible financial infrastructure platform to advance an open, global financial system. Founded in 2011, Kraken is one of the world's longest-standing crypto platforms, trusted by over 10 million individuals and institutions, offering spot trading, margin, futures, staking, and OTC services.

    About the Position

    Introduction

    Kraken, a leading crypto platform, is seeking a Senior Analyst, Security Compliance. This role involves building and operating an information technology controls program, working with external auditors, and contributing to initiatives shaping emerging Web3 standards within a rapidly evolving environment.

    Responsibilities

    • Lead and manage SOC 1 and SOC 2 examinations under AICPA standards, partnering with external auditors and internal teams to design, implement, and continuously improve IT control processes.
    • Support end-to-end SOX planning and execution, including IT system scoping, audit readiness, and development and delivery of training for control owners.
    • Act as a trusted advisor to Security, IT, Infrastructure, Engineering, Data, and Finance teams, translating SOX and audit requirements into practical, scalable controls.
    • Lead security and IT control gap assessments, evaluate control design and operating effectiveness, and drive remediation efforts.
    • Facilitate the ongoing maturation of IT general controls (ITGCs) and IT application controls (ITACs), balancing regulatory expectations with innovation.
    • Oversee the quality and execution of audit initiatives, applying strong professional judgment to identify control gaps, assess risk, and guide teams.
    • Perform impact assessments for SOX control deficiencies and design risk-based, pragmatic remediation plans.
    • Implement and enhance controls monitoring and defense-in-depth across key IT risk areas.
    • Partner cross-functionally to identify systemic program challenges, recommend process improvements, and drive durable solutions.
    • Develop and maintain clear, auditor-ready documentation, including data flow diagrams and process flowcharts for high-risk security and financial processes.
    • Work closely with internal and external auditors to ensure efficient, high-quality audits.
    • Support audit evidence collection and continuous improvement initiatives, including leveraging automation.

    Requirements

    • 5+ years of experience in external IT audit and/or technology risk assurance or advisory, with demonstrated ownership of complex audit requirements.
    • Strong hands-on experience with Internal Controls over Financial Reporting (ICFR), including SOX 404 frameworks, control design, and operating effectiveness testing.
    • Prior experience at a Big 4 or other large public accounting firm, or equivalent experience working with external auditors in a highly regulated environment.
    • Proven ability to lead compliance and audit initiatives end to end, from planning and risk assessment through remediation and audit close.
    • Experience auditing or assessing hybrid and cloud-based environments (e.g., IaaS, PaaS, SaaS), including access management, change management, and logging/monitoring controls.
    • Ability to operate autonomously in ambiguous, fast-paced environments, driving outcomes across cross-functional teams with minimal supervision.
    • Strong oral and written communication skills, with the ability to clearly explain technical concepts to technical and non-technical stakeholders.
    • Demonstrated ability to manage multiple priorities, coordinate cross-functional work, and hold stakeholders accountable to agreed timelines.
    • Strong organizational and time management skills, with a high degree of self-motivation and effectiveness in a remote or distributed working environment.

    Nice to Have

    • Exposure to fintech, payments, crypto, or digital asset business models (crypto audit experience is a plus).
    • Familiarity with risk and control frameworks (e.g., NIST, ISO 27001, COBIT) beyond baseline audit requirements.
    • Professional security management certification such as CPA, CISA, or CRISC.

    Benefits

    • Accelerate your technical depth by working in a cutting-edge, modern infrastructure environment (cloud-native architectures, complex, real-time systems).
    • Broaden your impact and perspective by collaborating with highly integrated, globally distributed teams and world-class professionals.
    • Influence how controls are designed and scaled in a fast-growing, regulated technology business.
    • Gain meaningful ownership and visibility while helping shape a maturing audit and compliance program.

    About Company

    Payward, the parent company behind Kraken, NinjaTrader, Breakout, xStocks, Payward Services, and CF Benchmarks, has spent 15 years building a globally accessible financial infrastructure platform to advance an open, global financial system. Founded in 2011, Kraken is one of the world's longest-standing crypto platforms, trusted by over 10 million individuals and institutions, offering spot trading, margin, futures, staking, and OTC services.

    How to Apply

    Unless a specific application deadline is stated in the job posting, applications are accepted on an ongoing basis. Candidates are permitted to redact or remove information on their resume that identifies age, date of birth, or dates of attendance/graduation from an educational institution. Kraken considers qualified applicants with criminal histories for employment, consistent with the San Francisco Fair Chance Ordinance. Please visit the Kraken careers page for the official application link.

    Apply Now

    Your data is only shared with Kraken

    Location

    Worldwide

    Type

    Full-Time

    Keywords

    Security
    Compliance
    IT Audit
    SOX
    SOC 1
    SOC 2
    Risk Management
    Web3
    Blockchain
    Crypto
    Fintech
    Cloud Security
    NIST
    ISO 27001
    COBIT
    CPA
    CISA
    CRISC
    Verified Company

    Senior Analyst, Security Compliance

    Kraken