Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
Enstack Technologies, Inc. seeks a seasoned Risk and Compliance Officer to own AML/CFT programs in a BSP-regulated startup environment in Metro Manila. You will lead regulatory compliance, onboarding KYB/KYC, sanctions screening, and Travel Rule data across payment flows.
Ideal candidates have 5+ years’ AML/CFT compliance and risk management experience, familiarity with BSP MORPS, and strong liaison skills with BSP agencies. You will help shape policies, governance, and data privacy practices.
Enstack is changing the way businesses are built by empowering everyone to become entrepreneurs. Enstack is an all-in-one AI-powered store builder for entrepreneurs to manage sales, payments, and shipping across web, chat, and physical locations. By integrating Artificial Intelligence into the core of business building, it is a transformative force in entrepreneurship, providing tools and a supportive ecosystem to help its users dream bigger, build smarter businesses, and live richer lives. Powering 100,000+ entrepreneurs in the Philippines and expanding regionally, it is backed by Mangrove Capital Partners, first institutional investors of Skype & Wix, and payments leader Xendit.
More than any time in recent history, you can build and grow a business (or three) while having full control of your time and leading a balanced life. Success as an entrepreneur today is limitless, fueled by the power of your ideas and the courage to take risks. With Enstack, anyone can become their own boss, embrace every opportunity, and make time for what matters most. We foster a culture of collaboration, innovation, and personal growth, and we value humble, intelligent, compassionate, and creative individuals who possess grit and a drive to pursue bold ideas. Come shape the future of entrepreneurs and create a more digitally inclusive world while advancing your own career with us.
Risk and Compliance officer Key Responsibilities Regulatory Compliance (AML/CFT/BSP)
Own Enstack's AML program as a covered person under AMLA, including maintenance of the tiered negative list, suspicious transaction monitoring, and STR filing with AMLC.
Administer the KYC/KYB onboarding framework across Enstack's payment flows, including the screening-first/deferred-document design already built into the onboarding form.
Run sanctions screening on every party in every payment instruction, with no exceptions, per Enstack's compliance minimums.
Capture and transmit Travel Rule data with every payment message across all flows.
Serve as day-to-day liaison to BSP PSOD (current contact: Director Aldrin Q. Javier) and AMLC on open items
Manage the 30-business-day BSP notification cycle for any operational change under OPS COR
Track and prepare for any transition to OPS-MAL status under Circular 1198 Section 503.4,
Maintain data privacy compliance and NPC registration.
Partner and Outsourcing Risk Oversight
Conduct and document institutional KYB on institutional partners before go-live on any flow, and lead the mandatory annual operational review of both partners as outsourced service providers under MORPS Section 903.1.
Monitor financial partners independent reporting obligations under Circular 1108 as part of partner due diligence where applicable
Ensure BCP/DR provisions exist in partner agreements and are periodically tested.
Maintain records showing outsourcing arrangements were properly reviewed and diligenced, available for BSP inspection on request.
Operational and IT Risk Management
Build and maintain an IT Risk Management (ITRM) framework consistent with MORPS Section 903.2 — governance structure, periodic risk identification/monitoring, cybersecurity and fraud prevention/detection, incident reporting and other reportings for critical functions.
Own Enstack's risk appetite statement and risk governance framework, and ensure risk limits are defined for settlement, liquidity, and operational risk categories relevant to Enstack
Coordinate independent assessment of the risk management process and controls (internal or external).
Flag any proposed flow, product, or partner change that could shift Enstack's risk and compliance metrics
Governance and Reporting
Prepare board- and management-level compliance and risk reporting, including status of open BSP confirmations and go-live readiness against the checklist.
Support preparation of governance documentation for any future MAL or ODPS-level filings (bio-data, board resolutions, fit-and-proper certifications)
Maintain the negative list, onboarding forms, and compliance documents, updating them as BSP guidance or Enstack's flow structures evolve.
5+ years in AML/CFT compliance and/or risk management within a BSP-regulated entity (bank, EMI, VASP, remittance/RTC, or OPS).
Working knowledge of AMLA, BSP MORPS (particularly Sections 401, 503, 903), Circulars 1049/1108/1198/1140/982, and FATF/Wolfsberg/OFAC/UN/EU sanctions frameworks.
Direct experience with BSP supervisory engagement (PSLD/PSOD) is a strong plus, given the volume of open confirmations this role will manage.
Familiarity with VASP/crypto-adjacent payment rails and cross-border payment structures
Certification such as CAMS (Certified Anti-Money Laundering Specialist) preferred; CRCM or equivalent risk certification a plus.
Comfortable operating without a fully built-out compliance department as Enstack is a start up.