Internal Auditor (Non-Financial)

Posted 13 Days Ago
Be an Early Applicant
Valencia, Comunidad Valenciana, ESP
Hybrid
Mid level
Blockchain • Fintech • Financial Services • Cryptocurrency
The Role
Establish and run the Spanish entity's internal audit function: plan and execute a risk-based audit calendar, test policies/processes (governance, AML/CFT, Travel Rule, transaction monitoring, outsourcing, ISMS), gather evidence, report findings to the Board, track remediation, and support regulatory inspections and compliance oversight.
Summary Generated by Built In

Hi! We're Mercuryo, and we’re on a mission to redefine finance by blending the best of traditional banking with the power of decentralized finance (DeFi). We believe everyone deserves seamless access to Web3 and traditional financial services, so we're building the platform that makes it real: one that simplifies crypto and integrates it into the broader financial ecosystem.

Since launching in 2018, we've grown into a recognized force in the industry, named one of Europe's Fastest-Growing Startups 2025 by Sifted and awarded Best Crypto On-Ramp & Payments Solution 2025 by Cryptonomist. We've partnered with leading brands including Visa, Mastercard, MetaMask, Trust Wallet, Ledger, and Jupiter, powering over 200 products and collaborating directly with major ecosystems like Solana, Consensys, and BNB Chain.

Why Mercuryo?

Industry Impact
Join us in helping world-class Web3 projects onboard millions of new users into the next generation of finance.

Innovative Environment
Collaborate with more than 300 talented professionals from diverse backgrounds - including banking, SaaS, and Web3 — all united in delivering outstanding user experiences.

AI-First Culture

We actively integrate AI across the company, from operations and analytics to marketing and product workflows. It helps teams move faster, improve productivity, and focus on high-impact work - while maintaining human oversight and accountability at every step. We see AI as a core part of how our teams innovate, collaborate, and scale.

Growth and Learning
Our expanding network of 200+ B2B partnerships and a user base of over 7 million means there’s always room to grow your skills, tackle new challenges, and push boundaries.

Flexible Culture
We're remote-first, celebrating diversity across 30 countries. In 2026, Mercuryo was recognized as a Great Place to Work across five countries based entirely on anonymous employee feedback. The recognition reflects a culture of trust and collaboration.

About the Role:

We are seeking a full-time Internal Auditor to establish and deliver the independent internal audit function of our regulated Spanish crypto-asset service provider. 

Reporting directly to the Board of Directors, you will provide independent and objective assurance over the effectiveness of the Spanish entity’s governance, regulatory compliance, operational processes and internal controls. 

You will be responsible for creating and managing the annual internal audit calendar, coordinating audit activity across the business and ensuring that planned audits, reports and follow-up reviews are completed throughout the year. This role requires someone proactive, highly organised and comfortable managing the audit programm independently, with limited day-to-day direction. 

The Spanish entity operates within a wider international group and uses local and group-level policies, systems, services and specialist functions. The Internal Auditor will assess how effectively these arrangements are implemented, evidenced and overseen by the Spanish entity and audit the control environment. 

The role will principally involve auditing policies, procedures and operational processes; gathering and evaluating supporting evidence; identifying evidence gaps and procedural failures; and recommending proportionate corrective actions. 

This is not a statutory financial statement audit or specialist technical cybersecurity position. 

Your Role:

Annual Audit Planning and Delivery

  • Create and maintain a risk-based annual internal audit calendar for Board approval.
  • Plan and schedule audit activities (evidence requests, fieldwork, reporting, follow-up) across the year.
  • Independently manage delivery of the audit programme within required timescales.
  • Prioritise audits based on regulatory requirements, deadlines, emerging risks and prior findings.
  • Define scope, objectives, methodology and timetable for each audit.
  • Track audit status and report progress to the Board.

Policy, Procedure and Process Audits

  • Independently audit the Spanish entity's policies, procedures and internal controls for currency, approval and regulatory alignment.
  • Assess whether policies are effectively implemented in practice, and whether responsibilities, controls and escalation routes operate as intended.
  • Identify gaps between documented procedures and actual practice, and control weaknesses.
  • Assess how group-level policies are adopted and overseen locally.
  • Cover key areas: governance, onboarding, AML/CFT, Travel Rule, transaction monitoring, complaints, conflicts of interest, regulatory reporting, outsourcing, business continuity, customer protection, and information security/ISMS (ISO 27001 alignment).

Evidence Gathering and Evaluation

  • Collaborate with Operations, Product, Risk, Compliance (FinCrime & Regulatory) and InfoSec to obtain audit evidence.
  • Prepare clear evidence requests; gather policies, records, MI, minutes and training data.
  • Conduct interviews and process walkthroughs; perform sample testing.
  • Maintain organised, traceable audit working papers.
  • Identify and assess evidence gaps, distinguishing isolated errors from systemic control failures.

Findings, Recommendations and Follow-up

  • Produce clear, evidence-based audit reports covering scope, testing, findings, risk ratings and root causes.
  • Report control weaknesses and policy gaps objectively; make practical recommendations.
  • Agree action plans, owners and deadlines with management (without taking on implementation).
  • Present findings directly to the Board.
  • Maintain a findings/recommendations register and independently verify remediation before closure.
  • Escalate material or overdue findings to the Board.

Governance and Regulatory Support

  • Maintain the Internal Audit Charter, methodology, templates and working-paper standards.
  • Support regulatory inspections; provide evidence of audit programme effectiveness to CNMV and other authorities.
  • Monitor regulatory developments and update the audit universe accordingly.
  • Promote a culture of accountability and continuous improvement.

What We’re Looking For:

  • University degree or professional qualification in internal audit, law, compliance, risk, technology, financial regulation or related field.
  • 4+ years' experience in internal audit, compliance assurance, control testing or regulatory risk within financial services, fintech, payments or crypto.
  • Compliance/risk backgrounds considered with substantive experience in independent reviews, evidence testing and reporting.
  • Strong experience reviewing policies and processes against legal/regulatory/control requirements.
  • Strong knowledge of MiCA, AML/CFT and Travel Rule; practical understanding of DORA and outsourcing arrangements.
  • Familiarity with ISMS and ISO 27001 principles; ISO 27001 audit experience a plus.
  • Experience with regulatory inspections (CNMV, Banco de España, SEPBLAC or equivalent) a plus.
  • Strong analytical skills — able to identify root cause and significance of control gaps.
  • Excellent organisational/project-management skills across multiple audits and deadlines.
  • Proactive, self-starting approach; able to work independently.
  • Strong cross-functional collaboration skills with independence and professional scepticism.
  • Clear written communication for reports to senior management, Board and regulators.
  • Full professional fluency in Spanish and English.
  • Certifications (CIA, CISA, CESCOM, CAMS, ISO 27001 Lead Auditor) advantageous, not essential.
  • Knowledge of crypto-assets, blockchain analytics, custody or digital-asset transaction monitoring a plus.

What We Offer:

  • Competitive market rate salary and performance-based incentives.
  • 22 days annual leave with an additional 6 company days, plus bank holidays.
  • Comprehensive health insurance plans.
  • Maternity & Paternity leave support.
  • Extensive benefits program.
  • Flexible work schedule and remote work options.
  • Modern offices and co-working spaces across 6 countries.
  • Working equipment.
  • Professional development and training opportunities.
  • Opportunity to shape the initiatives you’re working on.
  • Diverse and friendly team.
  • We are open-minded to new ideas.

Join Us!

If you're driven to be a part of the Web3 forefront and are keen to leave your mark on this rapidly evolving field, Mercuryo is an excellent choice. Discover our open positions and see how you can contribute to shaping the future!

Mercuryo is an equal opportunity employer and prohibits discrimination and harassment of any kind. We are committed to providing employees with a work environment that is progressive and open-minded. Our employment philosophy is to hire the best people and empower them to do the best work of their lives. Employment decisions are based on business needs and individual merit, without regard to race, colour, religion, ethnicity, sexual orientation, nationality, marital status, gender, age, disability, veteran status, or any other characteristic protected by law. Mercuryo is also committed to providing reasonable accommodations during the application process for qualified individuals with disabilities. If you require assistance to complete your application, please contact our Talent Team.

Skills Required

  • University degree or professional qualification in internal audit, law, compliance, risk, technology, financial regulation or related field
  • Minimum 4 years' experience in internal audit, compliance assurance, control testing or regulatory risk within financial services, fintech, payments or crypto
  • Experience conducting independent reviews, evidence testing, sample testing and producing audit reports
  • Experience reviewing policies and processes against legal, regulatory and control requirements
  • Strong knowledge of MiCA, AML/CFT and Travel Rule
  • Practical understanding of DORA and outsourcing arrangements
  • Familiarity with ISMS and ISO 27001 principles
  • ISO 27001 audit experience
  • Experience with regulatory inspections (CNMV, Banco de España, SEPBLAC or equivalent)
  • Strong analytical skills and ability to identify root causes
  • Excellent organisational and project-management skills across multiple audits and deadlines
  • Proactive, self-starting approach with ability to work independently and exercise professional scepticism
  • Clear written communication for reports to senior management, Board and regulators
  • Full professional fluency in Spanish and English
  • Certifications (CIA, CISA, CESCOM, CAMS, ISO 27001 Lead Auditor)
  • Knowledge of crypto-assets, blockchain analytics, custody or digital-asset transaction monitoring
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Chipping Norton
215 Employees
Year Founded: 2018

What We Do

At Mercuryo, we’re committed to creating novel, cryptopowered payments solutions that increase accessibility to seamless transacting in the digital age. In a world growing more globalised by the day, the need for affordable, cutting-edge fintech is more urgent than ever. We’re actively building financial technology to embrace the new paradigm - and help your business do the same. Mercuryo’s powerful feature set has been bundled into easily integrated, customisable products to help your business grow by providing a host of services including diverse payment methods, compliance and licence handling, and round-the-clock support. Our On- and off-ramps provide rapid, low cost payment rails for global transacting, amplifying your business’s reach and audience. Further, our Pay in & Pay out technology broadens the scope of payments methods, allowing businesses to accept both crypto and fiat payments. Our BaaS integration provides yet another resource-saving feature, allowing businesses to handle fiat processing via a single API integration, leveraging Mercuryo’s comprehensive global licencing. Since launching in 2018, we’ve partnered with over 200 major companies across the worlds of fiat and blockchain to aid their scaling journeys. Will yours be next?

Similar Jobs

Flywire Logo Flywire

Manager II, Software Engineering

Fintech • Payments • Software
Hybrid
Valencia, Comunidad Valenciana, ESP
1200 Employees

Carbon Robotics Logo Carbon Robotics

Performance Quality Technician

Artificial Intelligence • Computer Vision • Hardware • Machine Learning • Robotics • Software • Agriculture
Easy Apply
Remote or Hybrid
26 Locations
350 Employees
75K-85K Annually

Flywire Logo Flywire

Application Support II

Fintech • Payments • Software
Hybrid
Valencia, Comunidad Valenciana, ESP
1200 Employees

Flywire Logo Flywire

Payment Experience Associate I

Fintech • Payments • Software
Hybrid
Valencia, Comunidad Valenciana, ESP
1200 Employees

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account