Senior IT Auditor
- Role
- Security
- Experience
- Senior
Open to CA, US only. Set where you work from to check your eligibility.
No BS summary
Senior IT auditor for Mercury’s internal audit function, focused on IT, cybersecurity, data security risks, controls, and compliance. Needs audit planning/testing experience, financial services background, IT control frameworks, cloud/security exposure, and must be in the US or Canada.
Core skills
Required skills
Mercury is building a complete finance stack for startups. We work hard to create the easiest and safest banking* experience possible to simplify entrepreneurs' and business owners’ financial lives. To accomplish this mission, not only do we have to build/maintain a magical banking platform but must also develop and uphold the trust and safety of our customers and the financial industry. To contribute to this effort, we’re looking to hire a Senior IT Auditor to support the efforts of our Internal Audit function at Mercury in the execution of our audit plan. You’ll help drive audits internally within Mercury as well as support audits being conducted externally by partners and third parties. In this role, you’ll perform hands-on IT and security audits, assess Mercury’s technology risks and controls, and work cross-functionally to improve Mercury’s control environment.
*Mercury is a fintech company, not an FDIC-insured bank. Banking services provided through Choice Financial Group and Column N.A., Members FDIC.
As part of the journey, we would expect you to:
- Assist in identifying, analyzing, and assessing risk, specifically IT, cybersecurity, and data security related, throughout Mercury
- Scope and plan multiple audits across Mercury products and operations
- Conduct process walkthroughs and execute audit testing to confirm the design and operational effectiveness of internal controls
- Assess compliance with Mercury’s compliance obligations
- Socialize, document, and report audit issues identified
- Collaborate with teams to develop appropriate action plans, track audit issue remediation, and conduct issue follow up testing
- Other duties as assigned
Some things that might make you successful in a role like this:
- Have experience scoping and planning new, complex audits
- Be comfortable conducting walkthroughs, creating audit test plans, and executing internal controls testing
- Be comfortable using AI tools (Claude, ChatGPT, etc.) to support your day to day workflows
- Have experience working with financial services companies, and have a working knowledge of laws, regulations and risk management standards for financial services
- Familiarity with IT control frameworks (e.g., NIST, ISO 27001, COBIT)
- Have exposure to cloud environments (e.g., AWS) and related security controls
- Experience with security and threat assessments
- Have the ability to quickly grasp and understand complex business processes
- Be able to build relationships/partnerships and work cross-functionally to drive time-sensitive deliverables, issues tracking, and reporting
- Have excellent written and verbal communication skills
- Be able to manage their own schedule to ensure deadlines are met
- Be a self-starter, someone who likes to innovate and think about how we can do things differently to be more efficient and effective
The total rewards package at Mercury includes base salary, equity (stock options/RSUs), and benefits.
Our salary and equity ranges are highly competitive within the SaaS and fintech industry and are updated regularly using the most reliable compensation survey data for our industry. New hire offers are made based on a candidate’s experience, expertise, geographic location, and internal pay equity relative to peers.
Our target new hire base salary ranges for this role are the following:
- US employees in New York City, Los Angeles, Seattle, or the San Francisco Bay Area: $132,400 - $165,500 USD
- US employees outside of New York City, Los Angeles, Seattle, or the San Francisco Bay Area: $119,200 - $149,000 USD
- Canadian employees (any location): CAD $125,100 - $156,400
Mercury values diversity & belonging and is proud to be an Equal Employment Opportunity employer. All individuals seeking employment at Mercury are considered without regard to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, sexual orientation, or any other legally protected characteristic. We are committed to providing reasonable accommodations throughout the recruitment process for applicants with disabilities or special needs. If you need assistance, or an accommodation, please let your recruiter know once you are contacted about a role.
#LI-AR1
What you'll do
- Assist in identifying, analyzing, and assessing IT, cybersecurity, and data security risk throughout Mercury
- Scope and plan multiple audits across Mercury products and operations
- Conduct process walkthroughs and execute audit testing to confirm the design and operational effectiveness of internal controls
- Assess compliance with Mercury’s compliance obligations
- Socialize, document, and report audit issues identified
- Collaborate with teams to develop appropriate action plans
- Track audit issue remediation
- Conduct issue follow-up testing
- Perform other duties as assigned
What they require
- Experience scoping and planning new, complex audits
- Comfortable conducting walkthroughs, creating audit test plans, and executing internal controls testing
- Comfortable using AI tools to support day-to-day workflows
- Experience working with financial services companies
- Working knowledge of laws, regulations, and risk management standards for financial services
- Familiarity with IT control frameworks
- Exposure to cloud environments and related security controls
- Experience with security and threat assessments
- Ability to quickly grasp and understand complex business processes
- Able to build relationships and partnerships
- Able to work cross-functionally to drive time-sensitive deliverables, issues tracking, and reporting
- Excellent written and verbal communication skills
- Able to manage own schedule to ensure deadlines are met
- Self-starter who likes to innovate and think about how to do things more efficiently and effectively
Benefits
- Base salary
- Equity (stock options/RSUs)
- Benefits
- Reasonable accommodations throughout the recruitment process for applicants with disabilities or special needs
Mercury is building a complete financial stack for ambitious businesses. Mercury is a fintech company, not an FDIC-insured bank; banking services are provided through Choice Financial Group and Column N.A., Members FDIC.
What people say about this company
3.6/ 5
- Employees enjoy the collaborative and innovative work culture.
- Many appreciate the flexibility and remote work options.
- Some reviews mention challenges with management and communication.