Internal Auditor

OnHires

United States

Remote

USD 110,000 - 170,000

Part time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

OnHires is seeking an Internal Auditor to run the third line of defence for its EU-licensed entity. This role audits Compliance controls, reports to the Management Board, and delivers board-ready findings with actionable remediations.

The environment emphasizes independence, evidence-based closure, and board/regulator-facing communication. The ideal candidate has 5+ years in internal audit within regulated financial services, hands-on fintech/a EMI/VASP auditing, and strong knowledge of

Qualifications

  • 5+ years of internal audit in a regulated financial services entity.
  • Hands-on audit experience with fintech/EMI/crypto/VASP.
  • Working knowledge of MiCA, PSD2, AMLD5/6 and DORA; translate obligations into tests.
  • Independence in practice; can defend findings to senior management/Board.
  • Fluent professional English; Board/regulator communications.
  • Right to work in the EU/EEA.

Responsibilities

  • Own and maintain the risk-based Internal Audit Plan across MiCA CASP and PSD2 PI obligations, AML/KYC/CTF controls, ICT and security (DORA), custody and client assets segregation, outsourcing and third-party risk, governance and financial controls.
  • Execute engagements end-to-end: design the programme, sample selection, test controls, rate severity and regulatory impact.
  • Prepare Board-ready audit reports with well-supported findings and actionable recommendations.
  • Obtain remediation plans with owners and deadlines; track closure against evidence.
  • Present findings and remediation status to the Management Board quarterly and in the annual IA report.
  • Deliver annual AML/CFT audit and DORA ICT framework audit and follow-up.
  • Scope, direct, and challenge external specialists when deeper testing is needed.
  • Maintain audit evidence for supervisory reviews and inspections.

Skills

Internal audit
Regulated finance
MiCA/PSD2 knowledge
AML/KYC/CTF
Independent judgement
English fluency
AI tools in audit

Education

CIA/CISA/ACCA or EU IA qualification

Tools

AI audit tools

Job description

Remote | EU/EEA | Regulated Crypto & Payments Company | Part-time B2B Consultancy

About the Client

Our client is a global fintech company operating at the intersection of crypto and traditional payments. It serves millions of users worldwide through two business lines: a B2C retail platform for buying, selling, and swapping crypto, and B2B infrastructure providing on/off-ramp APIs, payouts, and compliance infrastructure for fintechs, wallets, and platforms.

The company's EU operating entity holds a MiCA CASP authorisation and a Payment Institution licence under PSD2, serving EU customers and powering a regulated B2B platform that fintechs, neobanks, PSPs, and Web3 companies build on - under the company's licences. Its control environment is part of the product, not back-office overhead.

About the Role

The company is looking for an Internal Auditor to run the third line of defence for its EU-licensed entity.

This is not a compliance role and not a monitoring role with an audit title. You audit Compliance controls - you do not execute them. You report functionally to the Management Board, you set your own severity ratings, and you deliver findings to the people who run the company, including when the finding is about them.

The function already exists. The Charter, Audit Universe, Internal Audit Plan and findings register are in place and Board-approved. This is not a rebuild of the methodology - it is delivering the plan with rigour, keeping the register alive and closed out with evidence, and putting the Board and the supervisor in a position where the control environment can be answered from the file.

What You'll Do
  • Own and maintain the risk-based Internal Audit Plan across MiCA CASP and PSD2 PI obligations, AML/KYC/CTF controls, ICT and security (DORA), custody and segregation of client assets, safeguarding of client funds, outsourcing and third-party risk, governance and financial controls.
  • Execute engagements end-to-end - design the programme, select samples, test controls, rate severity and regulatory impact.
  • Write Board-ready audit reports with findings that hold up under challenge and recommendations someone can actually act on.
  • Obtain remediation plans with named owners and deadlines; track and verify closure against evidence, not assertion.
  • Present findings and remediation status to the Management Board - quarterly updates and the annual Internal Audit Report.
  • Deliver the annual independent AML/CFT audit and the DORA ICT framework audit and follow-up.
  • Scope, direct, and challenge external specialists where an engagement needs deep technical testing.
  • Maintain the audit evidence that supports regulatory supervisory reviews and inspections.
What We're Looking For
Required
  • 5+ years of internal audit or internal control experience in a regulated financial services entity - bank, payment institution, EMI, investment firm, insurer, regulated fintech or crypto/VASP. Unregulated-only experience will not be considered.
  • Hands-on audit experience with at least one fintech, payment institution, EMI, crypto exchange or VASP - execution, not advisory theory.
  • Working knowledge of at least two of MiCA, PSD2, AMLD5/6 and DORA, with the ability to turn a regulatory obligation into a test programme.
  • Strong understanding of AML/KYC/CTF frameworks and how to audit their effectiveness.
  • Evidence of independence in practice - critical findings delivered to senior management or a Board and held under challenge.
  • Ability to run an engagement unsupervised and to make and defend a professional judgement on control severity.
  • Sufficient ICT and information security audit literacy to scope a DORA engagement and to direct and challenge an external technical specialist.
  • Fluent professional English - reports go to the Board and to the regulator as written.
  • Hands-on use of AI tools in audit work - planning, analysis, testing or reporting - with concrete examples.
  • Right to work and tax residence in the EU/EEA, with eligibility to be appointed to an internal control function of a licensed entity.
Nice to Have
  • MiCA CASP post-authorisation audit experience.
  • PSD2 / EMI safeguarding, own funds and scheme-compliance audit experience.
  • Deep ICT / information security audit capability, including DLT infrastructure, wallet security and key management.
  • DORA operational resilience, outsourcing and third-party risk audit experience.
  • Custody and segregation-of-client-assets audit experience.
  • Travel rule (FATF / EU TFR) audit experience.
  • Experience with a Baltic or other EU financial supervisor.
  • Board- or regulator-facing communication experience.
  • CIA, CISA, ACCA or an EU-recognised internal audit qualification.
  • Russian or Latvian.
What Makes This Role Different
  • This role is for auditors who want real independence, not a compliance review with an audit title.
  • You inherit a working function - Charter, plan, universe, and …
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Internal Audit - Regulatory Lead, EMEA
Internal Audit - Regulatory Lead, EMEA

Stripe • London (KY)

On-site
USD 146,000 - 212,000
Internal Audit Manager
Internal Audit Manager

LOOP • Greenville (SC), Spartanburg (SC), Anderson (SC)

On-site
USD 120,000 - 180,000
[EU] Head of Internal Audit EU
[EU] Head of Internal Audit EU

Bybit • Town of Vienna (WI)

On-site
USD 180,000 - 260,000
Senior Internal Auditor
Senior Internal Auditor

Selby Jennings • Dallas (TX)

On-site
USD 85,000 - 120,000
Senior Internal Auditor, Regulated Fintech, Remote EU
Senior Internal Auditor, Regulated Fintech, Remote EU

OnHires • United States

Remote
USD 110,000 - 170,000
[EU] EU Internal Audit Expert
[EU] EU Internal Audit Expert

Bybit • Town of Vienna (WI)

On-site
USD 104,000 - 151,000
Study Growth Fund
Internal Events
Global Collaboration
+2
Senior Manager, Internal Audit: Banking and Trade
Senior Manager, Internal Audit: Banking and Trade

Confidential • Jacksonville (FL)

On-site
USD 110,000 - 150,000
Internal Auditor
Internal Auditor

associacareers • Richardson (TX)

On-site
USD 65,000 - 90,000
Senior Internal Auditor
Senior Internal Auditor

Tier4 Group • Chicago (IL)

On-site
USD 90,000 - 140,000
Chief Audit Executive
Chief Audit Executive

Centralbancompany • Jefferson City (MO)

On-site
USD 150,000 - 210,000