Head of Enterprise Risk – Payments

Global FinTech Talent

Randstad

Hybrid

EUR 120,000 - 170,000

Full time

11 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Global FinTech Talent is partnering with a high-growth European payments technology company to establish an Enterprise Risk function from the ground up. The role is a senior individual contributor, focused on designing and embedding practical risk governance, taxonomy, appetite and controls to support rapid product development within a regulated environment.

You will work closely with the CRO, senior leadership and regulatory stakeholders, shaping risk reporting, escalation and governance as the

Qualifications

  • 7+ years of risk experience in fintech or payments.
  • Built or materially transformed an Enterprise Risk framework.
  • Experience with risk appetite, taxonomy, RCSA, governance ownership.
  • Practical knowledge of PSD2, DORA and related EBA requirements.
  • Experience building or operating internal-control frameworks and managing third-party/outsourcing risk.

Responsibilities

  • Design and embed an enterprise risk framework from the ground up.
  • Define risk taxonomy, appetite, tolerances, KRIs and escalation mechanisms.
  • Design periodic enterprise-wide risk assessments and RCSA processes.
  • Develop scenario analysis and stress-testing for payments.
  • Create executive and Board-level risk reporting and oversight.
  • Establish annual Risk plan, monitoring programme and thematic reviews.
  • Embed risk into product launches and material business decisions.
  • Build the internal-control framework with robust controls across domains.

Skills

Enterprise Risk
Risk framework build
Payments/Fintech risk
RCSA & governance
PSD2/DORA knowledge
Internal-control frameworks
Third-party/outsourcing risk
Regulator engagement
Board/C-suite communication
Hands-on independence

Job description

We are partnering with a high-growth European technology company that is building out a regulated payments business as part of its next stage of expansion.

This is not a role where you inherit a mature Risk function, established processes and a large team. You will join at the point where the foundations are still being built.

The company has secured its regulated payments licence and is now developing the governance, enterprise risk and internal-control infrastructure required to support the next phase of its payments proposition.

The successful person will have genuine ownership of that journey: defining how Risk should operate, establishing the framework, challenging the business and helping ensure that new products can scale within a strong and pragmatic control environment.

It is a rare opportunity for someone who enjoys building rather than maintaining.

You will work closely with the Chief Risk & Compliance Officer, senior leadership, Management and Supervisory Boards and regulatory stakeholders, while partnering across Product, Engineering, Finance, Compliance, Operations and other group functions.

The role starts as a senior individual contributor. That is deliberate: the priority is finding someone capable of personally designing and embedding the function rather than simply managing an existing team. As the regulatory perimeter and business develop, you will also have significant influence over how the Risk function itself should evolve.

What you will build: Your first challenge will be to create and embed an enterprise risk framework that is practical enough for a fast-moving technology business while meeting the expectations of a regulated payments institution.

You will own the development of the risk taxonomy, risk appetite and tolerance framework, risk assessments, governance, escalation and Board-level reporting across financial and non-financial risk.

This will include:

  • Building and owning the Enterprise Risk Management framework from the ground up,
  • Establishing risk taxonomy, appetite, tolerances, KRIs and escalation mechanisms,
  • Designing periodic enterprise-wide risk assessments and RCSA processes,
  • Developing scenario analysis and stress-testing relevant to the payments business,
  • Creating clear executive and Board-level risk reporting,
  • Establishing the annual Risk plan, monitoring programme and thematic reviews,
  • Embedding Risk into strategic decisions, product launches and material business changes.

The mandate is deliberately broad. Enterprise Risk is the core, but you will need sufficient depth to oversee risks across payments, financial, operational, ICT, outsourcing, conduct and strategic domains.

Build the internal-control environment: An equally important part of the role is creating a robust internal-control framework. The organisation operates within a wider technology group, meaning that some activities affecting the regulated entity may be delivered by other group functions or shared services.

This creates an interesting Risk challenge: you will be accountable for ensuring the framework works without necessarily owning every team executing the controls.

You will therefore:

  • Design and implement the internal-control framework,
  • Define key controls across payments, safeguarding, ICT, outsourcing and incident management,
  • Establish clear first-line ownership and segregation of duties,
  • Challenge controls performed by group and shared-service teams,
  • Build a risk-based control testing and monitoring programme,
  • Track weaknesses, incidents and remediation,
  • Partner with Internal Audit,
  • Provide senior management and Boards with clear reporting on control effectiveness and emerging risks.

You need to be comfortable influencing rather than relying on hierarchy.

Payments and regulatory risk: You will operate within a regulated payments and e-money environment and oversee risks including:

  • Safeguarding of customer funds,
  • Settlement and liquidity risk,
  • Card scheme and acquiring risk,
  • Fraud and disputes,
  • Critical third-party and outsourcing risk,
  • ICT and operational resilience,
  • Product and change risk.

You will help translate PSD2, DORA, EBA guidance and other relevant regulatory requirements into practical systems, controls and business processes.

You will also be an important Risk contact for the Dutch Central Bank (DNB) and other regulatory stakeholders.

What makes this role different: There are several reasons this opportunity should appeal to an experienced Risk leader who still enjoys being close to the work.

Build something rather than inherit it.

There is real white space. You will have the autonomy to determine what good Enterprise Risk looks like rather than spending your first year undoing somebody else's framework.

High visibility without unnecessary hierarchy.

The regulated entity is deliberately lean, giving this role direct access to senior leadership and Boards and the ability to influence decisions at an early stage.

Join before the payments business is fully scaled.

Rather than joining after products, processes and controls have already been fixed, you will help shape the control environment while the proposition itself develops.

Technology rather than traditional financial services.

This is a product-led, fast-moving environment. The aim is not to reproduce a traditional bank Risk department inside a technology company, but to build a regulatory-grade framework that still allows the business to move quickly.

The company specifically wants somebody who can take accountability for the outcome and independently determine how the Risk framework should be built.

Who we are looking for: We are looking for someone who has already done this before.

You will likely have 7+ years of Risk experience, with substantial exposure to fintech, payments, e-money or another modern regulated financial-services environment.

More importantly, you should be able to demonstrate that you have personally built or materially transformed an Enterprise Risk framework, rather than simply operated one that was already established.

We would particularly like to speak with people who can demonstrate:

  • A genuine 0→1 Risk or ERM build
  • Experience within payments, EMI, fintech or digital banking
  • Risk appetite, taxonomy, RCSA, controls and governance ownership
  • Practical knowledge of PSD2, DORA and relevant EBA requirements
  • Experience building or operating internal-control frameworks
  • Third-party and outsourcing risk expertise
  • Exposure to safeguarding, liquidity, settlement or other payment-related financial risks
  • Experience engaging regulators, ideally including DNB
  • Board and C-suite communication
  • The confidence to challenge senior stakeholders constructively
  • The ability to operate independently and remain hands-on

Dutch is not required; fluent English is sufficient. The client explicitly confirmed this.

Technology and AI: The company is also looking for someone comfortable working in a modern, AI-enabled organisation. You do not need to be an AI specialist, but you should understand how modern AI tools can improve your own work, how to use and refine prompts effectively, where AI should and should not be used, and the new risks AI adoption creates for regulated organisations.

Location and flexibility

For candidates in the Netherlands, the team currently spends around one to two days per week together. This is particularly valuable while the business and regulatory framework are being built, but the expectation is that this becomes more flexible as the build phase matures.

Why consider it? This role will not appeal to someone whose next move is primarily about inheriting a large team. It should appeal strongly to someone who wants something harder to find:

the opportunity to put their own fingerprints on an Enterprise Risk function from the beginning, inside a successful technology company that is investing seriously in regulated payments.

You will have the mandate, senior access and autonomy to build the framework properly , while joining early enough that your decisions will genuinely shape how the business operates for years to come.

Location: Netherlands – flexible hybrid, typically 1–2 days per week with the team during the build phase.

Alternative location: Spain, employment available via Employer of Record.

Type: Senior Individual Contributor / Enterprise Risk Leadership.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Enterprise Risk Architect — Build the Function
Enterprise Risk Architect — Build the Function

Global FinTech Talent • Randstad

Hybrid
EUR 120,000 - 170,000
Risk Consultant - Strategy & Consulting
Risk Consultant - Strategy & Consulting

Accenture the Netherlands • Amsterdam

Hybrid
EUR 90,000 - 130,000
Mobility budget
Laptop
iPhone
+2
Risk Management Consultant
Risk Management Consultant

All About Expats • Amsterdam

Hybrid
EUR 70,000 - 100,000
Pension plan
Annual bonuses
Training budget
+4
Consumer Credit Risk Manager
Consumer Credit Risk Manager

PaymentGenes • Amsterdam

Hybrid
EUR 110,000 - 150,000
Regulatory Transformation Consultant
Regulatory Transformation Consultant

Levy Professionals • Noord-Holland

On-site
EUR 65,000 - 95,000
First Line Operational Risk Officer
First Line Operational Risk Officer

nngroup • Den Haag

On-site
EUR 60,000 - 79,000
Thirteenth month
Holiday allowance
Diversity Days
+5
Enterprise Risk & Reporting Lead — Global Reg & Growth
Enterprise Risk & Reporting Lead — Global Reg & Growth

Finom • Netherlands

Hybrid
EUR 110,000 - 150,000
Stock options
EU remote/hybrid work
Work & Swim Cyprus program
+1
Risk Officer
Risk Officer

Blockrise • Rotterdam

Hybrid
EUR 33,000 - 45,000
Tools allowance
Bitcoin pension
25 vacation days
+6
Non-Financial Risk Specialist
Non-Financial Risk Specialist

New10-B.v. • Amsterdam

Hybrid
EUR 57,000 - 77,000
Great pension
Annual development budget
NS Business Card
+4
Non-Financial Risk Specialist
Non-Financial Risk Specialist

New10 B.V • Amsterdam

Hybrid
EUR 57,000 - 77,000
Salary 5112–6938 EUR monthly
Pension plan
Annual Development Budget
+6