About the Role
SumUp's Global Internal Audit team, part of the G&A / GRC function, plays a critical role in protecting the company's integrity, supporting regulatory compliance, and strengthening trust. As an Internal Auditor - IT security specialist, you will bring essential technology and data analytics expertise to partner with senior leaders, acting as the go-to expert for technology-focused audits and helping shape how IT risks, controls, and governance are assessed in a fast-scaling global fintech.
Responsibilities
- Support the delivery of SumUp’s approved Internal Audit Plan, with a strong focus on technology, data, and systems risk.
- Plan and execute IT internal audits in line with the annual audit plan.
- Assess IT general controls, security, governance, and risk management frameworks.
- Prepare clear, insightful audit reports, presenting findings and recommendations to senior stakeholders.
- Use data analytics to improve audit efficiency, sample testing, and risk identification.
- Support ad-hoc audit projects and regulatory-related reviews.
- Contribute to the continuous improvement of internal audit methodologies, frameworks, and templates.
- Stay up to date with technology standards, regulatory developments, and industry best practices.
- Build strong relationships across the business and promote a proactive internal controls culture.
- Conduct targeted audits of AWS security standards and access controls across our cloud environment, ensuring credit card data stored in cloud services is adequately protected.
- Perform risk-based reviews of payment products and ensure security requirements are consistently embedded throughout the development lifecycle.
- Identifying anomalies or excessive privileges across different systems and payment platforms.
Requirements
- Minimum 4 years’ experience in IT / Internal Audit within a regulated financial services environment.
- Strong knowledge of audit standards, risk management, and internal controls.
- Experience auditing IT controls and frameworks such as COBIT, ISO 27001, PCI DSS, ITIL, NIST, GDPR.
- Practical exposure to areas like data security, cloud architecture, disaster recovery, security operations, or network infrastructure.
- Advanced data analytics skills.
- Professional-level English (written and spoken).
- Professional certifications such as CIA, CISA, CPA.
- Additional IT/security certifications (CISSP, CISM, CRISC, ISO 22301, or similar).
- Experience with audit-related data analytics tools.
- High ethical standards and integrity.
- Strong analytical and problem-solving mindset.
- Confidence influencing change and challenging the status quo constructively.
- Ability to work independently in a multinational environment.
Skills
- Technology
- Data Analytics
- IT Security
- Audit Standards
- Risk Management
- Internal Controls
- COBIT
- ISO 27001
- PCI DSS
- ITIL
- NIST
- GDPR
- Data Security
- Cloud Architecture
- Disaster Recovery
- Security Operations
- Network Infrastructure
- AWS Security Standards
- Payment Products Security
Location
- London, United Kingdom
Work Type
- Office-first setup
Experience Level
- Minimum 4 years’ experience
Benefits
- Enrolment onto our VSOP program
- 28 days of paid leave, plus bank holidays and special leaves
- Vitality health cover, including optical and dental
- Salary-sacrifice commuter benefits via Gogeta
- Retirement scheme (SumUp matches 7% when you contribute 5%)
- Life insurance from MetLife for 2x your salary
- 1-month sabbatical after 3 years of service
- Referral Bonus
About the Company
- We believe in the everyday hero. Those who have the courage to follow their passion and who have the strength and determination to realise their dreams.
- Small business owners are at the heart of all we do, so we're creating powerful, easy-to-use financial solutions to help them run their businesses.
- With a founder’s mentality and a team-first attitude, our diverse teams across Europe, South America and the United States work together to ensure that small business owners can be successful doing what they love.
Equal Opportunity
- Commitment to Diversity and Inclusion: be part of a workplace that values and promotes diversity, fostering an inclusive environment where everyone's perspectives are respected and embraced.
