You will have the following responsibilities
Audit Management & Certification:
- Own and coordinate our custody audit program, including ISAE 3402 (Type 1 and Type 2) engagements and interactions with independent auditors such as PwC
- Prepare and maintain control frameworks, including key management, cold-storage signing, key generation ceremonies, segregation of signing keys, and multiparty authorization controls
- Manage and respond to external and internal audit requests, supporting audit fieldwork, evidence collection, and the documentation of control objectives, addressed risks, and key controls
- Champion compliance with ISAE 3402, SOC2, DORA, ISO 27001 and related regulatory standards across the custody organization
- Ensure completeness and currency of business documentation and audit evidence to support certifications and regulatory examinations
Risk Management, Controls & Compliance:
- Design, implement, and continuously monitor operational and system controls related to Custody, from withdrawal-address whitelisting and 48-hour time-locks to 6-eye key ceremonies and M-of-N approval frameworks
- Participate in regular risk call updates and coordinate follow-up actions; drive risk initiatives and related improvement programs
- Report operational or system incidents to the Risk function and support incident response and remediation with our infrastructure and software development teams
- Maintain control evidence to ensure compliance with internal policies, regulatory requirements, and audits
- Support decision-making by providing insights in the form of operational or management reports and performing ad-hoc analysis of custody-related data
What you bring along
- Strong experience with external and internal audits and related standards such as ISAE 3402, SOC2, DORA, ISO 27001 and similar, ideally in a financial services environment
- Deep understanding of controls-based assurance, control objectives, control testing, and the design and operation of effective control frameworks
- Solid knowledge about cryptocurrencies, blockchain technologies, cryptography, cybersecurity, risk management, and adversarial thinking
- Experience with digital asset custody, including seeds, private keys, wallets, key management, and cold-storage solutions; being a crypto OG is a plus
- A degree in Finance, Economics, Business Information Technology, Computer Science, or another related subject
- Certifications in audit, risk, security, or governance areas are a strong plus
- Profound stakeholder management skills with a proven ability to partner effectively with auditors, regulators, and internal teams in challenging circumstances
- Excellent analytical skills, meticulous attention to detail, and a self-driven, open-minded personality
- Excellent language skills in English and optionally German
