Internal Auditor
Quick Summary
About the Role
~1 min read5+ years of internal audit or internal control experience in a regulated financial services entity - bank, payment institution, EMI, investment firm, insurer, regulated fintech or crypto/VASP. Unregulated-only experience will not be considered.
Hands-on audit experience with at least one fintech, payment institution, EMI, crypto exchange or VASP - execution, not advisory theory.
Working knowledge of at least two of MiCA, PSD2, AMLD5/6 and DORA, with the ability to turn a regulatory obligation into a test programme.
Strong understanding of AML/KYC/CTF frameworks and how to audit their effectiveness.
Evidence of independence in practice - critical findings delivered to senior management or a Board and held under challenge.
Ability to run an engagement unsupervised and to make and defend a professional judgement on control severity.
Sufficient ICT and information security audit literacy to scope a DORA engagement and to direct and challenge an external technical specialist.
Fluent professional English - reports go to the Board and to the regulator as written.
Hands-on use of AI tools in audit work - planning, analysis, testing or reporting - with concrete examples.
Right to work and tax residence in the EU/EEA, with eligibility to be appointed to an internal control function of a licensed entity.
Nice to Have
~1 min readMiCA CASP post-authorisation audit experience.
PSD2 / EMI safeguarding, own funds and scheme-compliance audit experience.
Deep ICT / information security audit capability, including DLT infrastructure, wallet security and key management.
DORA operational resilience, outsourcing and third-party risk audit experience.
Custody and segregation-of-client-assets audit experience.
Travel rule (FATF / EU TFR) audit experience.
Experience with a Baltic or other EU financial supervisor.
Board- or regulator-facing communication experience.
CIA, CISA, ACCA or an EU-recognised internal audit qualification.
Russian or Latvian.
This role is for auditors who want real independence, not a compliance review with an audit title.
You inherit a working function - Charter, plan, universe, and findings register already exist and are Board-approved - and you run it, not rebuild it from scratch.
You report functionally to the Board, set your own severity ratings, and deliver findings directly to the people who can act on them, including senior leadership.
You'll work across one of the more complex dual-licensed perimeters in Europe (MiCA CASP + PSD2 PI), with direct Board access and budget for external technical specialists where needed.
Remote across the EU/EEA, with periodic in-person days at the company's EU office (roughly quarterly, or around Board meetings).
Part-time engagement (~0.5 FTE), B2B consultancy contract.
Functional reporting to the Management Board; no team, no review layer - full ownership of the function.
Scheduled checkpoints at scope memo, draft report and Board reporting stages; no involvement from management in fieldwork, findings or ratings.
Location & Eligibility
Listing Details
- Posted
- September 29, 2026
- First seen
- September 29, 2026
- Last seen
- September 29, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 66%
- Scored at
- September 29, 2026
Signal breakdown
Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.