Skip to content

Open nowPosted 7 days agoWe saw it 10 min after it went up

Internal Auditor

OnHires47 open roles

Where
Europe
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowInternal AuditorOnHires · Europe
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on OnHires's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.0% of postings close within 7 days. Measured by our own scanner across the market. OnHires postings stay open a median of 5 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 8.0%7 days
  4. 15.0%14 days
  5. 34.2%30 days
This job: posted 7 days ago

OnHires median: 5 days open

The posting

Remote | EU/EEA | Regulated Crypto & Payments Company | Part-time B2B Consultancy

About the Client Our client is a global fintech company operating at the intersection of crypto and traditional payments. It serves millions of users worldwide through two business lines: a B2C retail platform for buying, selling, and swapping crypto, and B2B infrastructure providing on/off-ramp APIs, payouts, and compliance infrastructure for fintechs, wallets, and platforms.

The company's EU operating entity holds a MiCA CASP authorisation and a Payment Institution licence under PSD2, serving EU customers and powering a regulated B2B platform that fintechs, neobanks, PSPs, and Web3 companies build on - under the company's licences. Its control environment is part of the product, not back-office overhead.

About the Role The company is looking for an Internal Auditor to run the third line of defence for its EU-licensed entity.

This is not a compliance role and not a monitoring role with an audit title. You audit Compliance controls - you do not execute them. You report functionally to the Management Board, you set your own severity ratings, and you deliver findings to the people who run the company, including when the finding is about them.

The function already exists. The Charter, Audit Universe, Internal Audit Plan and findings register are in place and Board-approved. This is not a rebuild of the methodology - it is delivering the plan with rigour, keeping the register alive and closed out with evidence, and putting the Board and the supervisor in a position where the control environment can be answered from the file.

- What You'll Do Own and maintain the risk-based Internal Audit Plan across MiCA CASP and PSD2 PI obligations, AML/KYC/CTF controls, ICT and security (DORA), custody and segregation of client assets, safeguarding of client funds, outsourcing and third-party risk, governance and financial controls.

- Execute engagements end-to-end - design the programme, select samples, test controls, rate severity and regulatory impact.

- Write Board-ready audit reports with findings that hold up under challenge and recommendations someone can actually act on.

- Obtain remediation plans with named owners and deadlines; track and verify closure against evidence, not assertion.

- Present findings and remediation status to the Management Board - quarterly updates and the annual Internal Audit Report.

- Deliver the annual independent AML/CFT audit and the DORA ICT framework audit and follow-up.

- Scope, direct, and challenge external specialists where an engagement needs deep technical testing.

- Maintain the audit evidence that supports regulatory supervisory reviews and inspections.

What We're Looking For Required

- 5+ years of internal audit or internal control experience in a regulated financial services entity - bank, payment institution, EMI, investment firm, insurer, regulated fintech or crypto/VASP. Unregulated-only experience will not be considered.

- Hands-on audit experience with at least one fintech, payment institution, EMI, crypto exchange or VASP - execution, not advisory theory.

- Working knowledge of at least two of MiCA, PSD2, AMLD5/6 and DORA, with the ability to turn a regulatory obligation into a test programme.

- Strong understanding of AML/KYC/CTF frameworks and how to audit their effectiveness.

- Evidence of independence in practice - critical findings delivered to senior management or a Board and held under challenge.

- Ability to run an engagement unsupervised and to make and defend a professional judgement on control severity.

- Sufficient ICT and information security audit literacy to scope a DORA engagement and to direct and challenge an external technical specialist.

- Fluent professional English - reports go to the Board and to the regulator as written.

- Hands-on use of AI tools in audit work - planning, analysis, testing or reporting - with concrete examples.

- Right to work and tax residence in the EU/EEA, with eligibility to be appointed to an internal control function of a licensed entity.

Nice to Have

- MiCA CASP post-authorisation audit experience.

- PSD2 / EMI safeguarding, own funds and scheme-compliance audit experience.

- Deep ICT / information security audit capability, including DLT infrastructure, wallet security and key management.

- DORA operational resilience, outsourcing and third-party risk audit experience.

- Custody and segregation-of-client-assets audit experience.

- Travel rule (FATF / EU TFR) audit experience.

- Experience with a Baltic or other EU financial supervisor.

- Board- or regulator-facing communication experience.

- CIA, CISA, ACCA or an EU-recognised internal audit qualification.

- Russian or Latvian.

What Makes This Role Different

- This role is for auditors who want real independence, not a compliance review with an audit title.

- You inherit a working function - Charter, plan, universe, and findings register already exist and are Board-approved - and you run it, not rebuild it from scratch.

- You report functionally to the Board, set your own severity ratings, and deliver findings directly to the people who can act on them, including senior leadership.

- You'll work across one of the more complex dual-licensed perimeters in Europe (MiCA CASP + PSD2 PI), with direct Board access and budget for external technical specialists where needed.

Working Environment

- Remote across the EU/EEA, with periodic in-person days at the company's EU office (roughly quarterly, or around Board meetings).

- Part-time engagement (~0.5 FTE), B2B consultancy contract.

- Functional reporting to the Management Board; no team, no review layer - full ownership of the function.

- Scheduled checkpoints at scope memo, draft report and Board reporting stages; no involvement from management in fieldwork, findings or ratings.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against OnHires's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on OnHires's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    OnHires's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.