Internal Auditor - SIA Paybis Europe

  • In-house
  • Compliance
  • Latvia

About Paybis

Paybis launched in 2014 with one goal: make crypto accessible using payment methods people already trust.

We are not a startup figuring out product-market fit. We are a regulated, profitable, bootstrapped business. SIA Paybis Europe, our Latvian operating entity, holds a MiCA CASP authorisation and a Payment Institution licence from Latvijas Banka. It serves our EU customers and powers the regulated B2B platform that fintechs, neobanks, PSPs and Web3 companies build on — under our licences. That makes our control environment part of the product, not back-office overhead.



About the Role

We are hiring an Internal Auditor to run the third line of defence for SIA Paybis Europe.

This is not a compliance role and not a monitoring role with an audit title. You audit Compliance controls — you do not execute them. You report functionally to the Management Board, you set your own severity ratings, and you deliver findings to the people who run the company, including when the finding is about them.

The function already exists. The Charter, Audit Universe, Internal Audit Plan 2026–2027 and findings register are in place and Board-approved. Your job is not to rebuild the methodology — it is to deliver the plan with rigour, keep the register alive and closed out with evidence, and put the Board and the supervisor in a position where the control environment can be answered from the file.



What You'll Be Doing

  • Own and maintain the risk-based Internal Audit Plan across MiCA CASP and PSD2 PI obligations, AML/KYC/CTF controls, ICT and security (DORA), custody and segregation of client assets, safeguarding of client funds, outsourcing and third-party risk, governance and financial controls
  • Execute engagements end-to-end — design the programme, select samples, test controls, rate severity and regulatory impact
  • Write Board-ready audit reports with findings that hold up under challenge and recommendations someone can actually act on
  • Obtain remediation plans with named owners and deadlines; track and verify closure against evidence, not assertion
  • Present findings and remediation status to the Management Board — quarterly updates and the annual Internal Audit Report
  • Deliver the annual independent AML/CFT audit and the DORA ICT framework audit and follow-up
  • Scope, direct and challenge external specialists where an engagement needs deep technical testing
  • Maintain the audit evidence that supports Latvijas Banka supervisory reviews and inspections


What We Expect

Must-have

  • 5+ years of internal audit or internal control experience in a regulated financial services entity — bank, payment institution, EMI, investment firm, insurer, regulated fintech or crypto/VASP. Unregulated-only experience will not be considered
  • Hands-on audit experience with at least one fintech, payment institution, EMI, crypto exchange or VASP
  • Working knowledge of at least two of MiCA, PSD2, AMLD5/6 and DORA, and the ability to turn an obligation into a test programme
  • Strong understanding of AML/KYC/CTF frameworks and how to audit their effectiveness
  • Evidence of independence in practice — critical findings delivered to senior management or a Board and held under challenge
  • Ability to run an engagement unsupervised and to make and defend a professional judgement on control severity
  • Enough ICT and information security audit literacy to scope a DORA engagement and direct and challenge an external technical specialist
  • Fluent professional English — your reports go to the Board and to the regulator as written
  • Hands-on use of AI tools in audit work — planning, analysis, testing or reporting — with concrete examples
  • Right to work and tax residence in the EU/EEA, and eligibility to be appointed to an internal control function of a Latvijas Banka-licensed entity

Nice-to-have

  • MiCA CASP post-authorisation audit experience
  • PSD2 / EMI safeguarding, own funds and scheme-compliance audit experience
  • Deep ICT / information security audit capability, including DLT infrastructure, wallet security and key management
  • DORA operational resilience, outsourcing and third-party risk audit experience
  • Custody and segregation-of-client-assets audit experience
  • Travel rule (FATF / EU TFR) audit experience
  • Experience with Latvijas Banka or another Baltic supervisor
  • Board- or regulator-facing communication experience
  • CIA, CISA, ACCA or an EU-recognised internal audit qualification
  • Russian or Latvian

Prior Head of Internal Audit title is not required. Demonstrated regulated-entity audit expertise outranks the credential.



What Success Looks Like

30 days — handover and ownership

  • Charter, plan, universe, working papers and findings register formally taken over and held by the function
  • Independence, access rights and the audit/compliance boundary confirmed with the Board
  • Control owners met across Compliance, Legal, Finance, Risk, Operations and IT
  • Status of every open engagement established and reported

90 days — first engagement delivered

  • Open engagement from the previous cycle closed out with an agreed remediation plan
  • Next engagement in the plan delivered end-to-end — scope memo, fieldwork, report, management response
  • Findings and remediation status presented to the Management Board
  • Findings register live, with evidence-based closure criteria

6 months — function running

  • Plan on schedule, including the annual independent AML/CFT audit
  • Remediation actively tracked with documented closure evidence
  • Plan re-prioritised where the risk picture changed, with Board approval
  • Recognised as independent and credible — a control enhancer, not a blocker


Interview Process

  1. HR screen (30 min) — experience, eligibility, independence, motivation
  2. Technical interview with Global Chief of Compliance (45–60 min) — methodology, regulatory depth, findings delivered upward
  3. Interview with CEO (45–60 min, discussion)
  4. References and eligibility check


Why Join Paybis?

  • Real independence, in writing — you report functionally to the Board, you own the Charter and the file, and your pay is tied to delivering the audit plan, not to keeping anyone comfortable
  • A dual MiCA CASP + PSD2 control environment — one of the more interesting perimeters in Europe to audit, and very few people have tested one
  • A working function to run, not a blank page — the structure exists; you deliver and improve it
  • Direct access to the CEO and the Management Board — your findings are read by the people who can act on them
  • Bootstrapped and profitable — no investor pressure on governance decisions
  • Part-time and remote across the EU/EEA, with periodic days in Riga, plus budget for external specialists and for professional development

Paybis is an equal opportunity employer.