Hi! We're Mercuryo , and we’re on a mission to redefine finance by blending the best of traditional banking with the power of decentralized finance (DeFi). We believe everyone deserves seamless access to Web3 and traditional financial services, so we're building the platform that makes it real: one that simplifies crypto and integrates it into the broader financial ecosystem. Since launching in 2018, we've grown into a recognized force in the industry, named one of Europe's Fastest-Growing Startups 2025 by Sifted and awarded Best Crypto On-Ramp & Payments Solution 2025 by Cryptonomist. We've partnered with leading brands including Visa, Mastercard, MetaMask, Trust Wallet, Ledger, and Jupiter, powering over 200 products and collaborating directly with major ecosystems like Solana, Consensys, and BNB Chain. Why Mercuryo? Industry Impact Join us in helping world-class Web3 projects onboard millions of new users into the next generation of finance. Innovative Environment Collaborate with more than 300 talented professionals from diverse backgrounds - including banking, SaaS, and Web3 — all united in delivering outstanding user experiences. AI-First Culture We actively integrate AI across the company, from operations and analytics to marketing and product workflows. It helps teams move faster, improve productivity, and focus on high-impact work - while maintaining human oversight and accountability at every step. We see AI as a core part of how our teams innovate, collaborate, and scale. Growth and Learning Our expanding network of 200+ B2B partnerships and a user base of over 7 million means there’s always room to grow your skills, tackle new challenges, and push boundaries. Flexible Culture We're remote-first, celebrating diversity across 30 countries. In 2026, Mercuryo was recognized as a Great Place to Work across five countries based entirely on anonymous employee feedback. The recognition reflects a culture of trust and collaboration. About the Role: We are seeking a full-time Internal Auditor to establish and deliver the independent internal audit function of our regulated Spanish crypto-asset service provider. Reporting directly to the Board of Directors, you will provide independent and objective assurance over the effectiveness of the Spanish entity’s governance, regulatory compliance, operational processes and internal controls. You will be responsible for creating and managing the annual internal audit calendar, coordinating audit activity across the business and ensuring that planned audits, reports and follow-up reviews are completed throughout the year. This role requires someone proactive, highly organised and comfortable managing the audit programm independently, with limited day-to-day direction. The Spanish entity operates within a wider international group and uses local and group-level policies, systems, services and specialist functions. The Internal Auditor will assess how effectively these arrangements are implemented, evidenced and overseen by the Spanish entity and audit the control environment. The role will principally involve auditing policies, procedures and operational processes; gathering and evaluating supporting evidence; identifying evidence gaps and procedural failures; and recommending proportionate corrective actions. This is not a statutory financial statement audit or specialist technical cybersecurity position. Your Role: Annual Audit Planning and Delivery Create and maintain a risk-based annual internal audit calendar for Board approval. Plan and schedule audit activities (evidence requests, fieldwork, reporting, follow-up) across the year. Independently manage delivery of the audit programme within required timescales. Prioritise audits based on regulatory requirements, deadlines, emerging risks and prior findings. Define scope, objectives, methodology and timetable for each audit. Track audit status and report progress to the Board. Policy, Procedure and Process Audits Independently audit the Spanish entity's policies, procedures and internal controls for currency, approval and regulatory alignment. Assess whether policies are effectively implemented in practice, and whether responsibilities, controls and escalation routes operate as intended. Identify gaps between documented procedures and actual practice, and control weaknesses. Assess how group-level policies are adopted and overseen locally. Cover key areas: governance, onboarding, AML/CFT, Travel Rule, transaction monitoring, complaints, conflicts of interest, regulatory reporting, outsourcing, business continuity, customer protection, and information security/ISMS (ISO 27001 alignment). Evidence Gathering and Evaluation Collaborate with Operations, Product, Risk, Compliance (FinCrime & Regulatory) and InfoSec to obtain audit evidence. Prepare clear evidence requests; gather policies, records, MI, minutes and training data. Conduct interviews and process walkthroughs; perform sample testing. Maintain organised, traceable audit working papers. Identify and assess evidence gaps, distinguishing isolated errors from systemic control failures. Findings, Recommendations and Follow-up Produce clear, evidence-based audit reports covering scope, testing, findings, risk ratings and root causes. Report control weaknesses and policy gaps objectively; make practical recommendations. Agree action plans, owners and deadlines with management (without taking on implementation). Present findings directly to the Board. Maintain a findings/recommendations register and independently verify remediation before closure. Escalate material or overdue findings to the Board. Governance and Regulatory Support Maintain the Internal Audit Charter, methodology, templates and working-paper standards. Support regulatory inspections; provide evidence of audit programme effectiveness to CNMV and other authorities. Monitor regulatory developments and update the audit universe accordingly. Promote a culture of accountability and continuous improvement. What We’re Looking For: University degree or professional qualification in internal audit, law, compliance, risk, technology, financial regulation or related field. 4+ years' experience in internal audit, compliance assurance, control testing or regulatory risk within financial services, fintech, payments or crypto. Compliance/risk backgrounds considered with substantive experience in independent reviews, evidence testing and reporting. Strong experience reviewing policies and processes against legal/regulatory/control requirements. Strong knowledge of MiCA, AML/CFT and Travel Rule; practical understanding of DORA and outsourcing arrangements. Familiarity with ISMS and ISO 27001 principles; ISO 27001 audit experience a plus. Experience with regulatory inspections (CNMV, Banco de España, SEPBLAC or equivalent) a plus. Strong analytical skills — able to identify root cause and significance of control gaps. Excellent organisational/project-management skills across multiple audits and deadlines. Proactive, self-starting approach; able to work independently. Strong cross-functional collaboration skills with independence and professional scepticism. Clear written communication for reports to senior management, Board and regulators. Full professional fluency in Spanish and English. Certifications (CIA, CISA, CESCOM, CAMS, ISO 27001 Lead Auditor) advantageous, not essential. Knowledge of crypto-assets, blockchain analytics, custody or digital-asset transaction monitoring a plus. What We Offer: Competitive market rate salary and performance-based incentives. 22 days annual leave with an additional 6 company days, plus bank holidays. Comprehensive health insurance plans. Maternity & Paternity leave support. Extensive benefits program. Flexible work schedule and remote work options. Modern offices and co-working spaces across 6 countries. Working equipment. Professional development and training opportunities. Opportunity to shape the initiatives you’re working on. Diverse and friendly team. We are open-minded to new ideas. Join Us! If you're driven to be a part of the Web3 forefront and are keen to leave your mark on this rapidly evolving field, Mercuryo is an excellent choice. Discover our open positions and see how you can contribute to shaping the future! Mercuryo is an equal opportunity employer and prohibits discrimination and harassment of any kind. We are committed to providing employees with a work environment that is progressive and open-minded. Our employment philosophy is to hire the best people and empower them to do the best work of their lives. Employment decisions are based on business needs and individual merit, without regard to race, colour, religion, ethnicity, sexual orientation, nationality, marital status, gender, age, disability, veteran status, or any other characteristic protected by law. Mercuryo is also committed to providing reasonable accommodations during the application process for qualified individuals with disabilities. If you require assistance to complete your application, please contact our Talent Team.
Internal Auditor (m/f/d)
Allianz Technology
Senior Cyber Security Internal Auditor
Globalhub2 Sita
Internal Auditor (m/f/d)
Allianz
Internal Auditor
Pinnacle Fund Services
Business Intelligence Internal Auditor
Ats
Payroll Associate - SAP MPS
SD Worx Group