Ready to get shit done?
Ready to Get Shit Done?
At bunq, we're building a bank that lives in the cloud, handles billions of transactions, and now integrates AI into our operations—all while keeping our user's data and trust intact. To operate at this scale and speed without compromising security, we need an Internal Auditor focused on Data Security & AI to audit our security controls, validate our AI governance, and ensure every system we build is resilient and trustworthy.
As an Internal Auditor – Data Security & AI, your mission is to strengthen bunq's security and AI governance posture by auditing data protection controls, assessing AI model risks, identifying vulnerabilities before attackers do, and ensuring our security practices evolve as fast as our technology.
Take Ownership
As an Internal Auditor - Data Security & AI, you'll own:
Audit security controls across infrastructure, applications, and operations, assessing access controls, encryption, monitoring, incident response, and third-party security effectiveness.
Build an AI governance audit program that evaluates model development, bias testing, monitoring, transparency, and regulatory alignment (AI Act, NIS2).
Identify and prioritize security and AI risks, conducting vulnerability assessments, pen test reviews, and model audits to surface gaps before they're exploitable.
What You'll Work on Right Away
Security Control Assessment: Audit bunq's critical security infrastructure (cloud environment, API security, data encryption, access management) and validate the effectiveness of controls; deliver a risk-prioritized remediation roadmap.
AI Model Governance Program: Design and execute bunq's first AI audit program, evaluating model development practices, data quality controls, bias testing, monitoring, and transparency, identifying governance gaps and building a scalable AI audit framework.
Data Protection & Privacy Audit: Conduct a comprehensive audit of bunq's data handling practices across all systems, assessing compliance with GDPR, data minimization principles, and data retention policies.
This challenge is perfect for you if
Do You Have What It Takes?
Security audit expertise: Hands-on experience auditing cloud infrastructure (AWS/Azure/GCP), application security, or operational security in fintech/high-security environments.
AI governance basics: Familiarity with AI risk frameworks (NIST AI RMF), model risk management, or ML/AI system audits (emerging expertise is fine if you're ready to grow).
Technical understanding: You grasp encryption, APIs, cloud architecture, and data flows well enough to ask smart audit questions.
Risk prioritization: You design efficient audits, gather evidence, and present findings with impact—not just checklists.
Fluency in English (ideally multilingual for our multi-market operations).
Curious to see how we make life easy? - try the bunq app, it only takes 5 minutes to sign up.
Your space to perform
We give you the space and the tools you need to succeed 💪
🤟 Great, international colleagues who share your mindset
👩💻 Hybrid setup: after 3 months in-office, work 2 days remote, 3 days in-office weekly.
🧳 Digital Nomad Program: After your first year, enjoy up to 20 days per year to work while traveling, combining flexibility with strong team collaboration
🚀 We reward tenure with a dedicated travel budget: €1.5k after 2 years and €3k after 4 years to visit another core office.
📚 We support growth with bunq Academy and €1500 annual learning budget
🚌 Travel expenses are covered whether you come walking or by bike, bus or car (though we prefer green choices 🌳)
💻 A MacBook so you can Get Shit Done with us
🥦 Delicious lunches from our fabulous in-house chefs with vegan and vegetarian options
💰 An optional pension plan with monthly contribution from bunq
🧘 €60 monthly allowance via Alleo by Epassi, rolling over monthly and resetting annually
🍻 Friday drinks and other celebrations - bunq style
All new hires are subject to Pre-employment Screening (PES), which includes checks conducted by our third-party partner, Zinc. This is part of our commitment to a secure and trustworthy workplace


