About PleoMessy spend management is tricky business. And tedious processes are a lose-lose situation for all involved, not just finance. We build spend solutions that make managing money seamless, empowering, and surprisingly effective for finance teams and employees alike - with a vision to help all businesses ‘go beyond’.every move we make has a direct impact on our 40,000+ customers, our business, and our collective success. With great ambitions driving us forward, we can’t say we’ve got this whole thing figured out. What we can say is that we’re a driven, progressive, and, importantly, a kind bunch of 850+ people from over 100 nationalities, all committed to delivering the future of business spending, together.About the roleWe're looking for a Risk & Controls Officer to join our Risk & Control team at Pleo. In this role, you'll operate as a key part of our Second Line of Defence, helping to strengthen the risk management framework that underpins everything we do — from our product to our regulatory relationships. You'll work at the intersection of risk expertise and business partnership, offering thoughtful challenges and practical guidance to our First Line teams as we continue to scale. If you're excited by the prospect of shaping how a fast-growing FinTech approaches risk maturity, and are passionate about building robust, pragmatic control environments, then this is the opportunity for you!Who you’ll be working with and reporting toYou’ll report to our Head of Risk and Control and work closely with First Line teams across the business. Our Risk & Control team is highly collaborative and dedicated to driving a culture of sound risk management across Pleo. You’ll also have the chance to partner with teams across Product, Operations, Finance, and Compliance to ensure cross-functional success.What you’ll be doingAs a Risk & Controls Officer, you will:Support Risk Framework Execution - Contribute to the implementation and maintenance of Pleo's 2LOD risk management framework, ensuring controls remain aligned with regulatory expectations and business strategy.Execute Oversight Activities - Conduct RCSAs (Risk and Control Self Assessments) and control reviews across the business. Assess the quality of risk identification and control design, and challenge 1LOD findings where appropriate.Identify & Assess Risks - Support scenario analysis and stress-testing exercises across operational, technology, product, and credit risk domains. Help surface emerging risk exposures to leadership.Be a Reliable Risk Advisor - Support business teams with guidance on risk topics, control requirements, and regulatory change, providing practical recommendations on risk and control issues.Support Risk Reporting & Regulatory Engagement - Contribute to the preparation of clear, data-informed risk reports for senior management and governance committees, and assist with regulator interactions on risk and control matters.You can expect to work with modern risk management platforms, GRC tools, and data analytics dashboards.Financial Services Experience - 3+ years of experience in a regulated financial services environment (FinTech, banking, payments, or similar) with hands-on experience in risk or control management.Essential Credit Risk Expertise - A solid, demonstrated understanding of the assessment and management of credit risk.Core Risk Domain Knowledge - Proven experience with operational risk, technology risk, and product risk assessment.Hands-On Risk & Control Execution - Background in ERM framework execution, control design, RCSAs, assurance activities, and remediation tracking.Clear & Collaborative Communication - Ability to translate complex risk concepts into practical, accessible language for diverse audiences, from frontline teams to leadership.Pragmatic, Solutions-Oriented Approach - A real-world problem-solving mindset that delivers workable answers to real risk challenges rather than defaulting to theoretical frameworks alone.Why is this role a good fit for youThis role is a good fit for you if:You want to actively shape 2LOD risk maturity in a high-growth FinTech scale-up.You enjoy a pragmatic, hands-on role where risk oversight directly enables business growth and innovation.This role is not a good fit for you if:Your background is primarily in traditional Internal Audit, Consulting, or pure Compliance without direct operational risk framework and RCSA experience.You prefer operating strictly within rigid, theoretical risk models without adapting to fast-paced commercial realities.You prefer purely administrative risk logging over proactive challenge, advisory, and stakeholder collaboration.How you’ll develop in this roleIn your first 12 months at Pleo, you’ll:Get under the skin of Pleo's risk landscape and take ownership of key 2LOD review, RCSA, and challenge activities across priority business areas.Play an active role in evolving our risk framework as the company continues to scale — contributing your expertise to initiatives that shape how we manage risk for years to come.Build strong cross-functional relationships, establishing yourself as a credible, trusted advisor on risk and control matters.We’re committed to helping you develop your career, whether that means deepening your technical subject matter expertise, expanding your regulatory exposure, or stepping into broader leadership responsibilities within the Risk team.We can hire on a hybrid or in-person set-up in any of the locations listed on the advert but you will need to be physically based in the country of your choice with a valid right to work. Lunch is on us for your work days - enjoy catered meals or receive a lunch allowance based on your local officeComprehensive private healthcare - depending on your location, coverage options include Vitality, Alan or MédisWe offer 25 days of holiday + your public holidaysWe use MyndUp to give our employees access to free mental health and well-being support with great success so farPaid parental leave - we want to make sure that we're supportive of families and help you feel that you don't have to compromise your family due to workThe interview processWe want to ensure you are set-up for success and understand what will be expected of you. A 30-minute chat with our Talent Partner to discuss the role and your background.A 45-minute chat with our Head of Risk & Control.A 60-minute chat with your peers and / or senior stakeholders.A 30-minute chat with our SVP Risk & Compliance.Last time we hired a Risk & Controls Officer, we received a high volume of applications, but only a selective group were invited to an intro call. CV writing and content: A top tip from us is to use the “Achieved X, as measured by Y, by doing Z” formula to give a really clear picture of what you’ve worked on. Including links to your previous companies' websites is also a huge help!Profile to role fit: For this role specifically, candidates whose backgrounds focus exclusively on professional consultancy, compliance reporting, or internal audit without hands-on 2LOD risk framework, credit risk, and RCSA execution experience often do not meet our core requirements.Since it's our company language, please submit your application in English. Our talent team reads every single application to ensure the process is fair. Diversity drives us. Your data is safe. When you apply, we process your personal data as a data processor. For more information on how Pleo processes personal data, read our Privacy Policy here.LocationLondonEmployment TypeFull timeLocation TypeHybridDepartmentRisk & Compliance
Risk and Control Management Officer in London employer: Pleo
Pleo is an exceptional employer that fosters a culture of innovation and collaboration, making it an ideal place for a Staff Engineer to thrive. With a strong emphasis on employee growth, you will have the opportunity to shape foundational data practices while working with cutting-edge technologies in a supportive environment. Located in a vibrant city, Pleo offers unique advantages such as a diverse team and a commitment to leveraging AI in meaningful ways, ensuring your contributions have a significant impact across the organisation.