We are looking for a highly motivated Risk & Compliance Program Manager to strengthen our risk management framework, ensure regulatory compliance, and support scalable growth across fintech, banking, and payments operations. This role will partner with cross-functional teams to operationalize risk processes, oversee compliance programs, support audits, and build governance infrastructure that aligns with business and regulatory requirements.
-
Maintain and manage the enterprise risk register.
-
Track risk acceptances, mitigation plans, and committee action items.
-
Drive issue management, corrective action plans, and control testing activities.
-
Ensure ongoing compliance with FinCEN, Nacha, PCI DSS, SOC 2, and other applicable regulations.
-
Lead Business Impact Analysis (BIA) and Business Continuity Planning (BCP) initiatives.
-
Conduct client onboarding risk assessments and due diligence reviews.
-
Manage client questionnaires, contractual risk reviews, and onboarding checkpoints.
-
Monitor ACH limits, onboarding conditions, and client-specific compliance obligations.
-
Standardize responses to client RFIs and due diligence requests.
-
Partner with Security teams to strengthen access control governance and conduct periodic access reviews.
-
Monitor and interpret regulatory changes related to BSA/AML, Nacha, OCC, FFIEC, GLBA, and other industry requirements.
-
Translate regulatory requirements into actionable internal processes and controls.
-
Ensure policies, procedures, and communications remain aligned with regulatory and client commitments.
-
Support continuous improvement of compliance and governance programs.
-
Embed risk assessments into product development and client onboarding workflows.
-
Establish and maintain approval thresholds, exception management, and escalation processes.
-
Track risk deviations, approvals, and acceptance records.
-
Collaborate with Legal, Product, and Operations teams to ensure consistent risk-based decision-making.
-
Lead audit preparation and readiness activities for SOC 2, PCI DSS, client audits, and compliance reviews.
-
Maintain centralized audit documentation and evidence repositories.
-
Coordinate compliance testing, remediation activities, and risk committee reporting.
-
Strengthen vendor risk management processes through control assessments and ongoing monitoring.
-
Develop and maintain Key Risk Indicators (KRIs), dashboards, and executive reporting.
-
Prepare risk and compliance reports for leadership and board-level stakeholders.
-
Partner with SalesOps and Legal teams to integrate risk controls into Salesforce and contract workflows.
-
Design scalable, repeatable governance processes that support organizational growth.
-
5 to 8 years of experience in Risk, Compliance, Operations, or Governance roles within FinTech, Banking, Payments, or BaaS organizations.
-
Strong understanding of regulatory compliance, risk management, vendor risk, audit readiness, and access control frameworks.
-
Experience building and scaling risk or compliance programs across multiple business functions.
-
Knowledge of:
- BSA/AML
-
FinCEN
-
Nacha
-
PCI DSS
-
SOC 2
-
OCC
-
FFIEC
-
GLBA
-
Experience with tools such as:
- Power BI
-
JIRA
-
ServiceNow
-
Salesforce
-
Strong analytical, organizational, and stakeholder management skills.