{"id":1464424,"url":"https://alion.io/job/onhires-internal-auditor","title":"Internal Auditor","company":{"id":4265,"name":"OnHires","domain":"onhires.com","url":"https://alion.io/company/onhires","size_band":"51-200","is_staffing_agency":true,"employer_type":"agency","is_intermediary":false,"listed_via":null,"ats_vendor":"Ashby","truth_index":null},"role":"Finance","role_family":"Finance","seniority":null,"employment_type":"full_time","work_mode":"remote","remote_scope":"stated_regions","remote_scope_basis":"posting_text","remote_working_hours":null,"hiring_geo_confidence":"inferred","locations":["Limassol, Cyprus"],"countries":["CY"],"hiring_countries":["DE","FR","GB","AT","BE","BG","HR","CY","CZ","DK","FI","HU","IE","IT","NL","NO","PL","RO","ES","SE","CH","UA","EE","GR","IS","LV","LI","LT","LU","MT","PT","SK","SI"],"hiring_countries_total":33,"salary":null,"salary_estimate":null,"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[],"status":"live","first_seen_at":"2026-09-29T11:29:11Z","employer_posted_date":"2026-09-29","last_verified_at":"2026-09-30T23:25:27Z","board_verified":true,"closed_at":null,"days_open":2,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":2},"description":"Remote | EU/EEA | Regulated Crypto & Payments Company | Part-time B2B Consultancy\nAbout the Client\nOur client is a global fintech company operating at the intersection of crypto and traditional payments. It serves millions of users worldwide through two business lines: a B2C retail platform for buying, selling, and swapping crypto, and B2B infrastructure providing on/off-ramp APIs, payouts, and compliance infrastructure for fintechs, wallets, and platforms.\nThe company's EU operating entity holds a MiCA CASP authorisation and a Payment Institution licence under PSD2, serving EU customers and powering a regulated B2B platform that fintechs, neobanks, PSPs, and Web3 companies build on - under the company's licences. Its control environment is part of the product, not back-office overhead.\nAbout the Role\nThe company is looking for an Internal Auditor to run the third line of defence for its EU-licensed entity.\nThis is not a compliance role and not a monitoring role with an audit title. You audit Compliance controls - you do not execute them. You report functionally to the Management Board, you set your own severity ratings, and you deliver findings to the people who run the company, including when the finding is about them.\nThe function already exists. The Charter, Audit Universe, Internal Audit Plan and findings register are in place and Board-approved. This is not a rebuild of the methodology - it is delivering the plan with rigour, keeping the register alive and closed out with evidence, and putting the Board and the supervisor in a position where the control environment can be answered from the file.\nWhat You'll Do Own and maintain the risk-based Internal Audit Plan across MiCA CASP and PSD2 PI obligations, AML/KYC/CTF controls, ICT and security (DORA), custody and segregation of client assets, safeguarding of client funds, outsourcing and third-party risk, governance and financial controls.\n\nExecute engagements end-to-end - design the programme, select samples, test controls, rate severity and regulatory impact.\n\nWrite Board-ready audit reports with findings that hold up under challenge and recommendations someone can actually act on.\n\nObtain remediation plans with named owners and deadlines; track and verify closure against evidence, not assertion.\n\nPresent findings and remediation status to the Management Board - quarterly updates and the annual Internal Audit Report.\n\nDeliver the annual independent AML/CFT audit and the DORA ICT framework audit and follow-up.\n\nScope, direct, and challenge external specialists where an engagement needs deep technical testing.\n\nMaintain the audit evidence that supports regulatory supervisory reviews and inspections.\n\nWhat We're Looking For\nRequired\n5+ years of internal audit or internal control experience in a regulated financial services entity - bank, payment institution, EMI, investment firm, insurer, regulated fintech or crypto/VASP. Unregulated-only experience will not be considered.\n\nHands-on audit experience with at least one fintech, payment institution, EMI, crypto exchange or VASP - execution, not advisory theory.\n\nWorking knowledge of at least two of MiCA, PSD2, AMLD5/6 and DORA, with the ability to turn a regulatory obligation into a test programme.\n\nStrong understanding of AML/KYC/CTF frameworks and how to audit their effectiveness.\n\nEvidence of independence in practice - critical findings delivered to senior management or a Board and held under challenge.\n\nAbility to run an engagement unsupervised and to make and defend a professional judgement on control severity.\n\nSufficient ICT and information security audit literacy to scope a DORA engagement and to direct and challenge an external technical specialist.\n\nFluent professional English - reports go to the Board and to the regulator as written.\n\nHands-on use of AI tools in audit work - planning, analysis, testing or reporting - with concrete examples.\n\nRight to work and tax residence in the EU/EEA, with eligibility to be appointed to an internal control function of a licensed entity.\n\nNice to Have\nMiCA CASP post-authorisation audit experience.\n\nPSD2 / EMI safeguarding, own funds and scheme-compliance audit experience.\n\nDeep ICT / information security audit capability, including DLT infrastructure, wallet security and key management.\n\nDORA operational resilience, outsourcing and third-party risk audit experience.\n\nCustody and segregation-of-client-assets audit experience.\n\nTravel rule (FATF / EU TFR) audit experience.\n\nExperience with a Baltic or other EU financial supervisor.\n\nBoard- or regulator-facing communication experience.\n\nCIA, CISA, ACCA or an EU-recognised internal audit qualification.\n\nRussian or Latvian.\n\nWhat Makes This Role Different\nThis role is for auditors who want real independence, not a compliance review with an audit title.\n\nYou inherit a working function - Charter, plan, universe, and findings register already exist and are Board-approved - and you run it, not rebuild it from scratch.\n\nYou report functionally to the Board, set your own severity ratings, and deliver findings directly to the people who can act on them, including senior leadership.\n\nYou'll work across one of the more complex dual-licensed perimeters in Europe (MiCA CASP + PSD2 PI), with direct Board access and budget for external technical specialists where needed.\n\nWorking Environment\nRemote across the EU/EEA, with periodic in-person days at the company's EU office (roughly quarterly, or around Board meetings).\n\nPart-time engagement (~0.5 FTE), B2B consultancy contract.\n\nFunctional reporting to the Management Board; no team, no review layer - full ownership of the function.\n\nScheduled checkpoints at scope memo, draft report and Board reporting stages; no involvement from management in fieldwork, findings or ratings.","description_format":"text","description_chars":5809,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[{"language":"English","level":"All levels","optional":false}]},"benefits":[],"hiring_locations":[{"name":"Germany","iso":"DE","kind":"region"},{"name":"France","iso":"FR","kind":"region"},{"name":"United Kingdom","iso":"GB","kind":"region"},{"name":"Austria","iso":"AT","kind":"region"},{"name":"Belgium","iso":"BE","kind":"region"},{"name":"Bulgaria","iso":"BG","kind":"region"},{"name":"Croatia","iso":"HR","kind":"region"},{"name":"Cyprus","iso":"CY","kind":"country"},{"name":"Czech Republic","iso":"CZ","kind":"region"},{"name":"Denmark","iso":"DK","kind":"region"},{"name":"Finland","iso":"FI","kind":"region"},{"name":"Hungary","iso":"HU","kind":"region"},{"name":"Ireland","iso":"IE","kind":"region"},{"name":"Italy","iso":"IT","kind":"region"},{"name":"Netherlands","iso":"NL","kind":"region"},{"name":"Norway","iso":"NO","kind":"region"},{"name":"Poland","iso":"PL","kind":"country"},{"name":"Romania","iso":"RO","kind":"country"},{"name":"Spain","iso":"ES","kind":"region"},{"name":"Sweden","iso":"SE","kind":"region"},{"name":"Switzerland","iso":"CH","kind":"region"},{"name":"Ukraine","iso":"UA","kind":"country"},{"name":"Estonia","iso":"EE","kind":"country"},{"name":"Greece","iso":"GR","kind":"region"},{"name":"Iceland","iso":"IS","kind":"region"},{"name":"Latvia","iso":"LV","kind":"country"},{"name":"Liechtenstein","iso":"LI","kind":"region"},{"name":"Lithuania","iso":"LT","kind":"country"},{"name":"Luxembourg","iso":"LU","kind":"region"},{"name":"Malta","iso":"MT","kind":"region"},{"name":"Portugal","iso":"PT","kind":"region"},{"name":"Slovakia","iso":"SK","kind":"country"},{"name":"Slovenia","iso":"SI","kind":"country"},{"name":"Limassol","iso":null,"kind":"city"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Blockchain & Crypto"],"lifecycle":[{"event":"open","at":"2026-09-29T14:11:08Z"}],"liveness":{"score":54,"band":"ok","label":"Likely open","p_open":1,"p_active":0.542,"p_room":1,"age_days":1,"expected_fill_days":37,"reasons":["conf:6","agency","velocity","win:early"],"computed_at":"2026-10-01T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/onhires-internal-auditor","json_url":"https://alion.io/job/onhires-internal-auditor.json","meta":{"generated_at":"2026-10-01T12:49:48Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4333,"day_limit":5000,"remaining_today":667,"minute_limit":60,"resets_at":"2026-10-02T00:00:00Z"}}}