Hi! We're Mercuryo and we’re on a mission to redefine finance by blending the best of traditional banking with the power of decentralized finance (DeFi). We believe everyone deserves seamless access to Web3 and traditional financial services so we're building the platform that makes it real one that simplifies crypto and integrates it into the broader financial ecosystem. Since launching in 2018 we've grown into a recognized force in the industry named one of Europe's Fastest-Growing Startups 2025 by Sifted and awarded Best Crypto On-Ramp & Payments Solution 2025 by Cryptonomist. We've partnered with leading brands including Visa Mastercard MetaMask Trust Wallet Ledger and Jupiter powering over 200 products and collaborating directly with major ecosystems like Solana Consensys and BNB Chain. Why Mercuryo? Industry Impact Join us in helping world-class Web3 projects onboard millions of new users into the next generation of finance. Innovative Environment Collaborate with more than 300 talented professionals from diverse backgrounds - including banking SaaS and Web3 — all united in delivering outstanding user experiences. AI-First Culture We actively integrate AI across the company from operations and analytics to marketing and product workflows. It helps teams move faster improve productivity and focus on high-impact work - while maintaining human oversight and accountability at every step. We see AI as a core part of how our teams innovate collaborate and scale. Growth and Learning Our expanding network of 200+ B2B partnerships and a user base of over 7 million means there’s always room to grow your skills tackle new challenges and push boundaries. Flexible Culture We're remote-first celebrating diversity across 30 countries. In 2026 Mercuryo was recognized as a Great Place to Work across five countries based entirely on anonymous employee feedback. The recognition reflects a culture of trust and collaboration.
We are seeking a full-time Internal Auditor to establish and deliver the independent internal audit function of our regulated Spanish crypto-asset service provider. Reporting directly to the Board of Directors you will provide independent and objective assurance over the effectiveness of the Spanish entity’s governance regulatory compliance operational processes and internal controls. You will be responsible for creating and managing the annual internal audit calendar coordinating audit activity across the business and ensuring that planned audits reports and follow-up reviews are completed throughout the year. This role requires someone proactive highly organised and comfortable managing the audit programm independently with limited day-to-day direction. The Spanish entity operates within a wider international group and uses local and group-level policies systems services and specialist functions. The Internal Auditor will assess how effectively these arrangements are implemented evidenced and overseen by the Spanish entity and audit the control environment. The role will principally involve auditing policies procedures and operational processes gathering and evaluating supporting evidence identifying evidence gaps and procedural failures and recommending proportionate corrective actions. This is not a statutory financial statement audit or specialist technical cybersecurity position. Your Role Annual Audit Planning and Delivery Create and maintain a risk-based annual internal audit calendar for Board approval. Plan and schedule audit activities (evidence requests fieldwork reporting follow-up) across the year. Independently manage delivery of the audit programme within required timescales. Prioritise audits based on regulatory requirements deadlines emerging risks and prior findings. Define scope objectives methodology and timetable for each audit. Track audit status and report progress to the Board. Policy Procedure and Process Audits Independently audit the Spanish entity's policies procedures and internal controls for currency approval and regulatory alignment. Assess whether policies are effectively implemented in practice and whether responsibilities controls and escalation routes operate as intended. Identify gaps between documented procedures and actual practice and control weaknesses. Assess how group-level policies are adopted and overseen locally. Cover key areas governance onboarding AML/CFT Travel Rule transaction monitoring complaints conflicts of interest regulatory reporting outsourcing business continuity customer protection and information security/ISMS (ISO 27001 alignment). Evidence Gathering and Evaluation Collaborate with Operations Product Risk Compliance (FinCrime & Regulatory) and InfoSec to obtain audit evidence. Prepare clear evidence requests gather policies records MI minutes and training data. Conduct interviews and process walkthroughs perform sample testing. Maintain organised traceable audit working papers. Identify and assess evidence gaps distinguishing isolated errors from systemic control failures. Findings Recommendations and Follow-up Produce clear evidence-based audit reports covering scope testing findings risk ratings and root causes. Report control weaknesses and policy gaps objectively make practical recommendations. Agree action plans owners and deadlines with management (without taking on implementation). Present findings directly to the Board. Maintain a findings/recommendations register and independently verify remediation before closure. Escalate material or overdue findings to the Board. Governance and Regulatory Support Maintain the Internal Audit Charter methodology templates and working-paper standards. Support regulatory inspections provide evidence of audit programme effectiveness to CNMV and other authorities. Monitor regulatory developments and update the audit universe accordingly. Promote a culture of accountability and continuous improvement.
University degree or professional qualification in internal audit law compliance risk technology financial regulation or related field. 4+ years' experience in internal audit compliance assurance control testing or regulatory risk within financial services fintech payments or crypto. Compliance/risk backgrounds considered with substantive experience in independent reviews evidence testing and reporting. Strong experience reviewing policies and processes against legal/regulatory/control requirements. Strong knowledge of MiCA AML/CFT and Travel Rule practical understanding of DORA and outsourcing arrangements. Familiarity with ISMS and ISO 27001 principles ISO 27001 audit experience a plus. Experience with regulatory inspections (CNMV Banco de España SEPBLAC or equivalent) a plus. Strong analytical skills — able to identify root cause and significance of control gaps. Excellent organisational/project-management skills across multiple audits and deadlines. Proactive self-starting approach able to work independently. Strong cross-functional collaboration skills with independence and professional scepticism. Clear written communication for reports to senior management Board and regulators. Full professional fluency in Spanish and English. Certifications (CIA CISA CESCOM CAMS ISO 27001 Lead Auditor) advantageous not essential. Knowledge of crypto-assets blockchain analytics custody or digital-asset transaction monitoring a plus.
Competitive market rate salary and performance-based incentives. 22 days annual leave with an additional 6 company days plus bank holidays. Comprehensive health insurance plans. Maternity & Paternity leave support. Extensive benefits program. Flexible work schedule and remote work options. Modern offices and co-working spaces across 6 countries. Working equipment. Professional development and training opportunities. Opportunity to shape the initiatives you’re working on. Diverse and friendly team. We are open-minded to new ideas. Join Us! If you're driven to be a part of the Web3 forefront and are keen to leave your mark on this rapidly evolving field Mercuryo is an excellent choice. Discover our open positions and see how you can contribute to shaping the future! Mercuryo is an equal opportunity employer and prohibits discrimination and harassment of any kind. We are committed to providing employees with a work environment that is progressive and open-minded. Our employment philosophy is to hire the best people and empower them to do the best work of their lives. Employment decisions are based on business needs and individual merit without regard to race colour religion ethnicity sexual orientation nationality marital status gender age disability veteran status or any other characteristic protected by law. Mercuryo is also committed to providing reasonable accommodations during the application process for qualified individuals with disabilities. If you require assistance to complete your application please contact our Talent Team.
Unlock: Sign Up for free / Sign In and use the searches from your home page or the links in the footer.