SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
OnePay is a consumer fintech platform backed by Walmart and Ribbit Capital, offering an all-in-one financial services ecosystem including banking, high-yield savings, credit cards, point-of-sale lending, investing, and crypto. The company also delivers embedded financial services to millions of employees and frontline workers through partnerships with employers, HCM providers, and gig platforms.
The Compliance Controls & Monitoring (C&M) team serves as OnePay's second line of defense, responsible for establishing and overseeing the firm's compliance control environment. This role is distinct from independent compliance testing and requires partnering across Product, Operations, Engineering, Legal, Risk, Compliance, and other business units to ensure compliance risks are identified, assessed, and managed through effective controls, monitoring, and governance throughout the product lifecycle.
Key responsibilities include:
• Building trusted relationships across the organization to influence compliance outcomes through strong collaboration, credibility, and influence, translating technical compliance analysis into meaningful business results.
• Supporting maintenance and enhancement of the compliance control framework, including centralized control inventories, risk-to-control mapping, ownership documentation, and monitoring relationships within the firm's GRC platform.
• Supporting the enterprise Compliance Risk Assessment process by maintaining the compliance risk register, facilitating periodic risk assessments, calibrating inherent and residual risk ratings, and ensuring identified risks map to controls and monitoring activities.
• Developing, executing, and enhancing risk-based monitoring activities including exception reporting, threshold monitoring, trend analysis, and data quality reviews. Recommending and implementing automation, data analytics, and AI-enabled solutions to improve monitoring efficiency and coverage.
• Identifying opportunities to improve existing controls, monitoring activities, documentation, and operational processes to increase efficiency, consistency, and scalability.
• Partnering with Regulatory Change Management, Operational Change Management, and Third-Party Risk Management to translate regulatory changes, operational/system changes, and third-party relationships into control and monitoring impacts, and performing compliance risk and control impact assessments for material changes.
• Partnering with cross-functional teams during product development and implementation to ensure compliance risks, controls, and monitoring activities are identified and documented prior to launch, with ongoing post-launch oversight to identify emerging risks and control gaps.
• Supporting assigned regulatory or operational domains (such as Disputes, Fraud, FCRA reporting, AI governance, operations change management, and third-party/partner monitoring) as a compliance resource and trusted partner.
• Preparing clear, concise reporting for leadership, governance committees, and stakeholders highlighting monitoring results, emerging risks, control trends, key observations, and recommended actions.
• Providing credible second-line challenge on control design, issue remediation, and root cause analysis while maintaining appropriate separation from first-line control ownership and execution.
Requirements:
• 5–10 years of progressively responsible experience in Compliance, Risk Management, Controls, Compliance Monitoring, or a related second-line function within banking, fintech, or another regulated financial services environment.
• Strong analytical and organizational skills with high attention to detail and accuracy, and the ability to manage multiple priorities.
• Experience using GRC platforms and risk assessment methodologies, including risk registers, inherent and residual risk assessments, and control documentation.
• Experience partnering across regulatory change management, operational/project change management, and third-party or vendor risk to assess the control impact of change.
• Experience leveraging data analytics, automation, or AI-enabled tools to improve compliance monitoring, reporting, or operational efficiency, or a demonstrated ability to quickly adopt emerging technologies.
• A risk-based mindset demonstrating strong critical thinking and sound judgment with the ability to identify root causes, assess risk, and balance regulatory expectations with practical business solutions.
• Excellent written and verbal communication skills (English proficiency required), with a track record of producing clear, audit-ready documentation and high-impact reporting for management and risk committees. Ability to communicate effectively with technical teams, business leaders, and executive stakeholders.
• Proven track record of delivering high-quality work under competing priorities and deadlines.
• CRCM, CIA, or equivalent certification preferred.