Head of Compliance
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Lead Astra’s enterprise compliance program, serving as BSA/AML Compliance Officer and overseeing financial crimes, payments, privacy, GRC, SOC 2, PCI DSS, audits, bank partnerships, and third-party risk. The role manages and scales the compliance team, advises executives and the Board, evaluates product and payment-flow risks, develops practical controls, and supports responsible growth across fintech and embedded-finance use cases. The summary above was generated by AI About Astra
Astra is building mission-critical infrastructure for moving money at scale. Our platform processes billions in annual transaction volume with 99.9%+ uptime, powering real-time transfers, bank debits, card disbursements, and complex financial compliance systems. We provide APIs and automation tools that enable businesses to move money programmatically while maintaining strict regulatory requirements.
The Role
Astra is on a mission to make payments radically better - faster, more secure, and worthy of the products built on top of them. We’re an instant-payments platform powering developers and product teams across banking, BaaS, payroll, lending, crypto, and other financial-services use cases.
As Astra grows, we’re looking for a Head of Compliance to lead and scale our enterprise compliance program across financial crimes, payments compliance, privacy, security assurance, and governance.
This leader will inherit an established program and team and will be responsible for strengthening its strategy, operating model, controls, and oversight as Astra’s products, payment flows, partnerships, and compliance obligations evolve. The Head of Compliance will serve as Astra’s designated BSA Compliance Officer and oversee the company’s BSA/AML, KYC/KYB, sanctions, payment-network, privacy, SOC 2, PCI DSS, and broader compliance-risk programs.
This is a hands-on leadership role requiring both strategic judgment and operational depth. You will work closely with Product, Engineering, Security, Legal, Operations, executive leadership, and Astra’s bank partners to translate complex requirements into practical, scalable controls that support responsible growth.
Reporting to the COO, the Head of Compliance will serve as Astra’s senior compliance leader and a key advisor to executive leadership and the Board.
What You’ll Do
Lead Astra’s Enterprise Compliance Program
- Set the strategy for Astra’s enterprise compliance program and continuously improve its policies, procedures, risk assessments, controls, testing, training, and reporting.
- Serve as Astra’s designated BSA/AML Compliance Officer, overseeing KYC/KYB, customer due diligence, sanctions screening, transaction monitoring, alert and case management, and financial-crimes risk.
- Provide clear reporting to executive leadership and the Board regarding material compliance risks, program performance, audits, and remediation.
- Lead, develop, and appropriately scale Astra’s existing Compliance and GRC team while remaining directly involved in complex reviews, escalations, and strategic initiatives.
Oversee Payments and Bank Partner Compliance
- Serve as the senior compliance point of contact for Astra’s sponsor-bank partners, supporting ongoing oversight, due diligence, audits, inquiries, and program governance.
- Oversee compliance with applicable ACH/NACHA, card-network, RTP, FedNow, and other payment-rail requirements.
- Evaluate new products, payment flows, customers, partnerships, and markets to identify compliance requirements and establish appropriate controls before launch.
- Partner with outside counsel to evaluate regulatory developments and potential licensing or registration requirements arising from changes to Astra’s products or operating model.
- Partner cross-functionally to build and enhance fraud controls across Astra’s payment flows, including monitoring rules, transaction limits, and escalation processes.
Lead GRC, Audit, and Privacy Programs
- Own the governance and continued maturity of Astra’s SOC 2 and PCI DSS programs, including scoping, control ownership, audit readiness, auditor coordination, findings management, and annual assessments.
- Oversee Astra’s readiness for BSA, NACHA, sponsor-bank, customer, SOC 2, PCI DSS, and other applicable audits and assessments.
- Maintain an enterprise risk and controls framework that connects compliance obligations, risks, controls, testing, evidence, and remediation.
- Lead Astra’s privacy compliance program, including applicable GDPR and U.S. privacy requirements, data-subject requests, retention, privacy notices, and reviews of new products, data uses, and vendors.
- Oversee third-party compliance risk, customer assurance activities, and compliance-related due-diligence responses.
Partner Across the Business
- Advise Product, Engineering, Sales, and Integrations on compliance requirements for new products, payment flows, and customer use cases, partnering with relevant teams to implement effective, scalable controls.
- Manage third-party compliance vendors, including KYC/KYB/sanctions screening providers., * Experience at a BaaS company or payments platform managing sponsor bank program obligations and audit readiness.
- Experience supporting complex or emerging payment use cases, such as cross-border payments, crypto, payroll, lending, or other embedded-finance products.
- Prior experience presenting compliance strategy to a founding team, board, or investors.
Why This Role Matters
Astra’s product promise-fast, secure transfers across multiple payment rails-is possible because of the trust we have built with our banking partners, payment networks, customers, and users. Compliance is not a secondary function within that model; it is part of Astra’s operating infrastructure.
As Astra scales, the complexity of our products, partnerships, data practices, and control environment will grow with us. The Head of Compliance will shape how Astra manages that complexity-strengthening our financial-crimes controls, maintaining strong bank partnerships, overseeing critical audit and assurance frameworks, advancing our privacy program, and helping the company launch new products responsibly.
This is an opportunity to lead an established program and talented team through their next stage of maturity while having a direct and visible impact on Astra’s growth.
What We Offer
- Competitive compensation with equity in a growing fintech company.
- Remote-first culture with flexible working arrangements
- Small team, big impact - your work directly supports Astra’s ability to scale responsibly
- Professional growth opportunities in compliance and risk management
- Mission-driven - build infrastructure that powers financial innovation while meeting the highest regulatory standards, Build and lead Chamber’s healthcare compliance function across regulatory, corporate, clinical, government programs, privacy, HIPAA, IT/security oversight, and internal audit. Responsibilities include developing compliance strategy, managing Medicare and Medicaid requirements, standardizing clinical compliance, overseeing audits and investigations, maintaining policies and training, and partnering cross-functionally on risk controls, AI-enabled workflows, payer relationships, and multi-state expansion. Top Skills: Ai-Enabled Clinical ToolsHipaaHitrustSoc 2 Gauntlet
Head of Compliance
14 Days Ago In-Office or Remote Senior level Senior level Blockchain * Fintech * Software * Cryptocurrency Lead and build Gauntlet’s compliance function: design policies, controls, monitoring, and reporting; support regulatory registrations and examinations; integrate compliance into Product, Engineering, Finance, and commercial workflows; use automation/AI to scale monitoring; advise across financial crime, securities, privacy, anti-corruption, employment, and marketing. Step
Head of Compliance
14 Days Ago Remote United States Expert/Leader Expert/Leader Fintech * Software * Financial Services Lead and scale Step’s compliance program across banking, lending, and payments regulations. Build policies, manage exams, audits, monitoring, and issue tracking. Partner cross-functionally and with sponsor banks to ensure compliant product development, translate regulatory change into action, and serve as primary regulator and auditor contact to support rapid growth.
What you need to know about the Colorado Tech Scene
With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.
Key Facts About Colorado Tech
- Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
- Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
- Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
- Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
- Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute
Requirements
- 8+ years of compliance experience in fintech, payments, banking, or financial services, with at least 3 years in a leadership role.
- Prior experience leading a BSA/AML compliance program at a financial institution, payments company, or fintech, ideally within a sponsor-bank or bank-fintech partnership model.
- Experience overseeing multiple compliance and assurance programs, including BSA/AML, fraud, privacy, SOC 2, PCI DSS, or payment-network compliance.
- Deep, practical expertise in BSA/AML, OFAC, KYC/KYB, customer due diligence, transaction monitoring, suspicious-activity escalation, and financial-crimes risk management.
- Familiarity with the intricacies of specific payment rails, specifically: ACH, RTP, and debit networks.
- Hands-on experience building or scaling compliance programs at a startup or high-growth company - you’ve done this before, and you know how to right-size controls for where a company actually is.
- Experience managing sponsor bank relationships and navigating bank program compliance requirements.
- Demonstrated experience leading and developing a compliance team while remaining closely involved in program execution.
- Ability and willingness to travel up to ~15% annually.
Education
- Bachelor’s degree required; JD, MBA, or advanced degree in a relevant field strongly preferred.
- Candidates without an advanced degree but with exceptional track records and relevant certifications will be fully considered - we care about what you’ve done, not just where you studied.
- CAMS, CRCM, CFE, or equivalent preferred.
Technical Skills
- Familiarity with modern compliance and financial crimes tooling - platforms like Alloy, Sardine, Unit21, Socure, or ComplyAdvantage - and the ability to evaluate and implement new tools as needs evolve.
- Comfortable working with data: able to analyze transaction patterns, interpret monitoring outputs, and engage credibly with Engineering on how technical controls are built and tuned.
- Working knowledge of API-driven payment architecture and how compliance requirements translate into product and engineering decisions.
- Understanding of instant payment rails including Visa Direct, card-to-card transfers, ACH/NACHA, RTP, and FedNow.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Highest Paying Tech Companies for Developers
Navigating the AI Shift
E-Commerce in the Agentic Age: When "Buy" Becomes a Function Call
Why Upskilling And Reskilling is Important For Developers