Company Mission
Payhawk is a leading global spend management solution for scaling businesses. Headquartered in London and combining company cards, reimbursable expenses and accounts payable into a single product; its future-facing technology enables finance teams to control and automate company spending at scale.
The Payhawk customer base includes fast-growing and mature multinational companies in 32 countries including LuxAir and Wagestream. With offices in New York, London, Berlin, Munich , Barcelona, Paris, Amsterdam, Vilnius and Sofia; Payhawk is backed by renowned investors such as Lightspeed Venture Partners, Greenoaks, QED Investors, Bek Ventures and Eleven Ventures.
Our values include supporting flat hierarchies, taking ownership and responsibility, seeking and providing feedback, managing constructive critique, and speaking our minds. We understand that the best ideas don’t all come from the same place, so we encourage diversity and inclusion in all areas of our work.
The future of fintech is about more than money, it is about continual learning and empowered teams. We’re also on a journey to measure and improve our environmental and social impact . From virtual cards to digital subscriptions, our software and automation help take paper out of the equation for our customers, too.
We’re changing the world of payments, and we’re looking for an exceptional team to help us.
About the Role
This is a senior second-line role with a wide mandate: independent control testing across two licensed entities and the full regulatory framework, reporting into the Risk Committee and both Boards, with the latitude to design the programme the way you think it should work.
Payhawk operates two electronic money institution licences, one in the UK supervised by the Financial Conduct Authority and one in Lithuania supervised by the Bank of Lithuania. You will cover both, reporting to the Director of Risk and Outsourcing, independent of the teams you review.
In plain terms: you test whether our controls work, and whether they would catch what they are designed to catch. That means testing systems rather than case files, and populations rather than hand-picked samples. The questions look different in every domain. Does a safeguarding reconciliation actually prove what it claims to prove. Would we know promptly if a critical outsourced provider stopped meeting its obligations. Is a regulatory return built on data that reconciles. Would a resilience control hold in the scenario it was designed for. Are the alerts a screening or monitoring tool should be raising being raised at all. It takes someone comfortable with data, confident forming their own view, and senior enough to be heard when the answer is unwelcome.
Your mandate is the whole control framework across both entities: regulatory compliance and conduct, regulatory reporting, financial crime and sanctions, operational resilience and ICT under the Digital Operational Resilience Act, safeguarding, capital adequacy, outsourcing and third-party management, and governance. You will agree risk-based priorities with the Risk Committee each cycle rather than testing everything at once.
You will own the programme end to end and shape how it develops: the plan, the testing, the findings, the credible challenge to control owners, the remediation through to closure, and the reporting into both Boards. Identifying a gap is the easy half, so this role is as much programme management as testing: convening the right stakeholders, setting clear expectations and dates, keeping the work moving, escalating where it stalls, securing the approvals it needs, and validating independently that the fix holds before anything is marked complete.
How we work with AI. Payhawk builds automation for a living, and we build our control functions the same way. Good assurance at our scale means testing whole populations rather than hand-picked samples, so we want someone fluent with AI as a working tool: pulling your own data from connected systems, prompting well enough to get reliable answers out of large document sets, and turning a test into something repeatable that produces its own evidence. We will give you the tooling, the data access and the mandate to build the programme around it, and any recurring manual check is yours to automate.
Responsibilities
- Build and own the Board-approved group control assurance and monitoring plan covering both licensed entities, with priorities set by the risk assessment and agreed with the Risk Committee
- Design and run risk-based control testing across the group risk register, assessing both design effectiveness and operating effectiveness
- Test operational resilience and ICT controls under the Digital Operational Resilience Act, and governance and conduct controls across both entities
- Test safeguarding and capital adequacy controls, including whether reconciliations and calculations evidence what they are relied on to evidence
- Test regulatory reporting controls, including the completeness and accuracy of the data behind regulatory returns
- Test outsourcing and third-party controls, including whether we would detect a critical provider falling below its obligations
- Independently test detection controls end to end, including sanctions and politically exposed person screening effectiveness and transaction monitoring coverage and calibration, including the population that never generated an alert
- Lead the remediation of the gaps you identify, acting as programme manager for closure: convene the relevant stakeholders, agree scope, owners and dates, track progress, escalate where it stalls, and secure the governance approvals required
- Independently validate that a remediated control works before the finding is closed, and reopen it where the fix does not hold
- Provide credible challenge to control owners, with written findings, severity ratings, agreed actions and owners
- Report testing results, remediation status, coverage against plan and thematic findings to the Risk Committee and to the Boards of both entities
- Own the relationship with external assurance providers, and progressively bring recurring testing in-house to reduce cost and dependency
- Build the testing as tooling: automated, repeatable, population-level tests that generate their own evidence rather than one-off manual exercises
- Support supervisory engagement and internal audit by producing evidence of control effectiveness on demand
- Provide independent assurance over significant change, so that new systems and processes are tested before they become business as usual
Requirements
- Genuine fluency with AI in your day-to-day work. You can pull your own data and reports from connected systems, prompt well enough to get reliable answers out of large document sets and datasets, and build a repeatable workflow from a few chained steps. You have built something yourself, whether a workflow, a set of prompts, a report or a small automation that saved you real time, and you can walk us through it
- Compliance monitoring, control testing or assurance experience across a regulated framework, in a second-line or third-line capacity, covering more than one risk domain rather than a single specialism
- Strong knowledge of Financial Conduct Authority expectations on the compliance function and its monitoring programme, and of equivalent EEA expectations
- Real depth in at least two of the risk domains above, and the appetite to build it in the others
- The ability to distinguish control design from control execution, and to test a system rather than a case file
- A track record of driving remediation to closure, not only reporting findings. You can run a programme without owning the resources: convene stakeholders across functions, hold them to dates, escalate proportionately, and get decisions made
- Comfortable working with data at population level rather than relying only on manual samples, and able to get to an answer in a dataset with the tooling available to you
- Independence and spine. You can tell a senior control owner that their control does not work, evidence it, and make the finding stick
- Written English to Board standard, and the judgement to rate findings proportionately rather than escalating everything
- Fluent written and spoken English, and the right to work in the United Kingdom
Nice to have
- A Big Four or specialist consultancy assurance, audit or regulatory advisory background
- Experience in a payments, e-money or banking institution, and familiarity with how these frameworks apply to an electronic money institution
- Testing exposure to operational resilience and ICT risk, safeguarding, capital adequacy or regulatory reporting
- Experience testing screening or transaction monitoring effectiveness, including matching behaviour, list coverage and scenario back-testing
- SQL, Python or similar, and practical use of data testing frameworks
- A relevant qualification such as IIA, ICA, ACAMS or equivalent
- Experience of a multi-entity or multi-jurisdiction group structure, and of intragroup outsourcing oversight
Company Benefits
- 30 days of paid time off + 12 work-from-anywhere days
- Exchange policy to another Payhawk office (Amsterdam, Paris, Barcelona, Berlin, Sofia)
- Health and fitness membership
- Two company on-sites per year
- Opportunity to use the Payhawk product, with a monthly commuting allowance of £150
Payhawk is an Equal Employment Opportunity Employer. Qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status.