Risk & Control Officer

Pleo · via Arbeitnow ·

TypeFull-time job
LocationLondon
Posted7 hours ago
About Pleo
Messy spend management is tricky business. And tedious processes are a lose-lose situation for all involved, not just finance. At Pleo, we're changing that. We build spend solutions that make managing money seamless, empowering, and surprisingly effective for finance teams and employees alike - with a vision to help all businesses ‘go beyond’.
The word ‘Pleo’ actually means ‘more than you’d expect’, and living by that mantra has been the secret to our success over the last 10 years.
Now, we’re at a pivotal moment in our journey; every move we make has a direct impact on our 40,000+ customers, our business, and our collective success. We need people who take pride in uncovering customer needs, who turn complex problems into simple solutions, challenge the way things are done (respectfully), and always aim high. With great ambitions driving us forward, we can’t say we’ve got this whole thing figured out. And frankly, that’s half the fun! What we can say is that we’re a driven, progressive, and, importantly, a kind bunch of 850+ people from over 100 nationalities, all committed to delivering the future of business spending, together.
About the role
We're looking for a Risk & Controls Officer to join our Risk & Control team at Pleo. In this role, you'll operate as a key part of our Second Line of Defence, helping to strengthen the risk management framework that underpins everything we do — from our product to our regulatory relationships. You'll work at the intersection of risk expertise and business partnership, offering thoughtful challenges and practical guidance to our First Line teams as we continue to scale. If you're excited by the prospect of shaping how a fast-growing FinTech approaches risk maturity, and are passionate about building robust, pragmatic control environments, then this is the opportunity for you!

Who you’ll be working with and reporting to
You’ll report to our Head of Risk and Control and work closely with First Line teams across the business. Our Risk & Control team is highly collaborative and dedicated to driving a culture of sound risk management across Pleo. You’ll also have the chance to partner with teams across Product, Operations, Finance, and Compliance to ensure cross-functional success.

What you’ll be doing
As a Risk & Controls Officer, you will:
Support Risk Framework Execution – Contribute to the implementation and maintenance of Pleo's 2LOD risk management framework, ensuring controls remain aligned with regulatory expectations and business strategy.

Execute Oversight Activities – Conduct RCSAs (Risk and Control Self Assessments) and control reviews across the business. Assess the quality of risk identification and control design, and challenge 1LOD findings where appropriate.

Identify & Assess Risks – Support scenario analysis and stress-testing exercises across operational, technology, product, and credit risk domains. Help surface emerging risk exposures to leadership.

Be a Reliable Risk Advisor – Support business teams with guidance on risk topics, control requirements, and regulatory change, providing practical recommendations on risk and control issues.

Support Risk Reporting & Regulatory Engagement – Contribute to the preparation of clear, data-informed risk reports for senior management and governance committees, and assist with regulator interactions on risk and control matters.

To put things into context, we currently have scaling our 2LOD oversight framework and enhancing cross-functional RCSA processes on our roadmap. You can expect to work with modern risk management platforms, GRC tools, and data analytics dashboards.

What you bring
You’ll thrive in this role if you have:
Financial Services Experience – 3+ years of experience in a regulated financial services environment (FinTech, banking, payments, or similar) with hands-on experience in risk or control management.

Essential Credit Risk Expertise – A solid, demonstrated understanding of the assessment and management of credit risk.

Core Risk Domain Knowledge – Proven experience with operational risk, technology risk, and product risk assessment.

Hands-On Risk & Control Execution – Background in ERM framework execution, control design, RCSAs, assurance activities, and remediation tracking.

Clear & Collaborative Communication – Ability to translate complex risk concepts into practical, accessible language for diverse audiences, from frontline teams to leadership.

Pragmatic, Solutions-Oriented Approach – A real-world problem-solving mindset that delivers workable answers to real risk challenges rather than defaulting to theoretical frameworks alone.

Why is this role a good fit for you
This role is a good fit for you if:
You want to actively shape 2LOD risk maturity in a high-growth FinTech scale-up.

You enjoy a pragmatic, hands-on role where risk oversight directly enables business growth and innovation.

You thrive in a collaborative environment partnering with cross-functional teams across Product, Operations, and Finance.

This role is not a good fit for you if:
Your background is primarily in traditional Internal Audit, Consulting, or pure Compliance without direct operational risk framework and RCSA experience.

You prefer operating strictly within rigid, theoretical risk models without adapting to fast-paced commercial realities.

You prefer purely administrative risk logging over proactive challenge, advisory, and stakeholder collaboration.

How you’ll develop in this role
In your first 12 months at Pleo, you’ll:
Get under the skin of Pleo's risk landscape and take ownership of key 2LOD review, RCSA, and challenge activities across priority business areas.

Play an active role in evolving our risk framework as the company continues to scale — contributing your expertise to initiatives that shape how we manage risk for years to come.

Build strong cross-functional relationships, establishing yourself as a credible, trusted advisor on risk and control matters.

We’re committed to helping you develop your career, whether that means deepening your technical subject matter expertise, expanding your regulatory exposure, or stepping into broader leadership responsibilities within the Risk team.

The location
Please note: We can hire on a hybrid or in-person set-up in any of the locations listed on the advert but you will need to be physically based in the country of your choice with a valid right to work. We are unable to offer visa sponsorship for this role in any of the listed locations.

Show me the benefits!
Your own Pleo card (no more out-of-pocket spending!)

Lunch is on us for your work days - enjoy catered meals or receive a lunch allowance based on your local office

Comprehensive private healthcare - depending on your location, coverage options include Vitality, Alan or Médis

We offer 25 days of holiday + your public holidays

We use MyndUp to give our employees access to free mental health and well-being support with great success so far

Paid parental leave - we want to make sure that we're supportive of families and help you feel that you don't have to compromise your family due to work

The interview process
We want to ensure you are set-up for success and understand what will be expected of you. If your application is successful, our interview process is as follows:
Intro call: A 30-minute chat with our Talent Partner to discuss the role and your background.

Hiring Manager: A 45-minute chat with our Head of Risk & Control.

Peer Interview: A 60-minute chat with your peers and / or senior stakeholders.

Final Interview: A 30-minute chat with our SVP Risk & Compliance.

Transparency is important to us so we also wanted to share some insights about what we’re looking for in applications to ensure you can set yourself up for success!
Last time we hired a Risk & Controls Officer, we received a high volume of applications, but only a selective group were invited to an intro call. Some of the key reasons why previous candidates didn’t make it past the application screening stage include:
CV writing and content: We receive a lot of CVs, and many of them are AI-generated. We love seeing people leverage AI—it’s a big focus for us internally too—but without human intervention, these CVs can sometimes become generic and fail to show a candidate in the best light. What we're really looking for is the specific details of real impact that only you know from your previous experience. A top tip from us is to use the “Achieved X, as measured by Y, by doing Z” formula to give a really clear picture of what you’ve worked on. Including links to your previous companies' websites is also a huge help!

Application care: Every single application we receive is reviewed by a human because we believe that candidates' efforts should be matched by an equal level of human care. Read and answer the application questions carefully, as they make a huge difference in our decision-making process.

Profile to role fit: For this role specifically, candidates whose backgrounds focus exclusively on professional consultancy, compliance reporting, or internal audit without hands-on 2LOD risk framework, credit risk, and RCSA execution experience often do not meet our core requirements.

About your application
English first. Since it's our company language, please submit your application in English. You’ll be using it a lot if you join us.

A fair look for everyone. Our talent team reads every single application to ensure the process is fair. To keep things running smoothly, we only accept applications through our system—our support team can’t pass on calls or emails.

Diversity drives us. We can only reach our goals if our team reflects the world around us. That starts with you hitting apply, even if you don't tick every single box. We encourage people from all backgrounds and experiences to join us.

Interview at your best. We want you to feel comfortable throughout the process. If you have any accessibility requirements or need a specific format, email ----- We’ll design a process that works for you.

Your data is safe. When you apply, we process your personal data as a data processor. For more information on how Pleo processes personal data, read our Privacy Policy here.

Applying for multiple roles? Nothing is stopping you, and we assess every role independently. However, we do look for alignment, so make sure you can explain why your interest and experience are right for each specific role.

Reapplying. If you’re applying for the same role again, please wait six months from your last decision before hitting submit.

Find Jobs in United Kingdom on Arbeitnow
risk & compliance
Apply on Arbeitnow →

Job sourced from Arbeitnow. Applications happen directly on the original platform — we never collect your data.