1 день назад
Internal Auditor (Non-Financial) (Web3)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Internal Auditor (Non-Financial) (Web3): Establishing and managing an independent internal audit function for a regulated Spanish crypto-asset service provider with an accent on governance, regulatory compliance, operational processes, and internal controls. Focus on risk-based audit planning, evidence testing, control-gap analysis, remediation follow-up, and reporting findings directly to the Board.
Location: Valencia, Spain (Hybrid)
Company
is a Web3 and fintech company building infrastructure that connects crypto-assets with traditional financial services.
What you will do
- Establish and manage the independent internal audit function for the regulated Spanish crypto-asset service provider.
- Create a risk-based annual audit calendar, define audit scopes and methodologies, and coordinate evidence requests, fieldwork, reporting, and follow-up reviews.
- Audit governance, onboarding, AML/CFT, Travel Rule, transaction monitoring, complaints, conflicts of interest, regulatory reporting, outsourcing, business continuity, customer protection, and information security controls.
- Gather and evaluate policies, records, management information, minutes, training data, interviews, process walkthroughs, and sample-testing evidence.
- Produce evidence-based reports, identify root causes and control weaknesses, agree action plans, and independently verify remediation.
- Present findings and audit-programme progress to the Board and support regulatory inspections by CNMV and other authorities.
Requirements
- University degree or professional qualification in internal audit, law, compliance, risk, technology, financial regulation, or a related field.
- At least 4 years of experience in internal audit, compliance assurance, control testing, or regulatory risk within financial services, fintech, payments, or crypto.
- Strong experience reviewing policies and processes against legal, regulatory, and control requirements.
- Strong knowledge of MiCA, AML/CFT, and the Travel Rule, with practical understanding of DORA and outsourcing arrangements.
- Analytical, organisational, reporting, and cross-functional collaboration skills, with the ability to work independently and maintain professional scepticism.
- Full professional fluency in Spanish and English required.
Nice to have
- Familiarity with ISMS and ISO 27001 principles or ISO 27001 audit experience.
- Experience with regulatory inspections involving CNMV, Banco de España, SEPBLAC, or equivalent authorities.
- CIA, CISA, CESCOM, CAMS, or ISO 27001 Lead Auditor certification.
- Knowledge of crypto-assets, blockchain analytics, custody, or digital-asset transaction monitoring.
Culture & Benefits
- Flexible work schedule with remote work options and a hybrid setup.
- 22 days of annual leave plus 6 company days and bank holidays.
- Comprehensive health insurance, maternity and paternity leave support, and an extensive benefits programme.
- Working equipment, professional development, and training opportunities.
- Access to modern offices and coworking spaces across six countries.
- Diverse, collaborative, and open-minded working environment.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →