HitPay

Payments infrastructure for businesses scaling in APAC

Hiring — 3 openYC-S21Fintech -> PaymentsGrowth

What HitPay does

HitPay is a full stack payments infrastructure platform designed for growing businesses in APAC. Founded in 2016 and headquartered in Singapore, HitPay unifies e-commerce, point of sale, and B2B payments into a single platform. The company is regulated in 6 APAC jurisdictions and backed by leading global investors, including Tiger Global, Y Combinator, Global Founders Capital, and HOF Capital.

3 open roles

AML Operations Analyst
PH / MY / Remote (PH; MY)Full-time3+ years$1K - $3K / monthlyVisa: US citizen/visa only
What the role involves

ABOUT THE ROLE -------------- You're on the frontline of HitPay's defence against financial crime. As an AML Operations Analyst you execute the controls that keep bad actors off the platform: verifying who our merchants are, investigating alerts, and escalating genuine suspicion to the MLRO. This is hands-on, high-volume, detail-intensive work that directly protects HitPay and its merchants across all five markets. This is a first-line execution role: you run the controls and escalate suspicion - the final STR decision sits with the MLRO, keeping our lines of defence cleanly separated. WHAT YOU'LL DO -------------- Onboarding (KYC/KYB): verify merchant identity, ownership and business legitimacy; collect and assess CDD documentation; apply Enhanced Due Diligence where risk warrants. Screening: review and disposition sanctions, PEP and adverse-media screening hits; clear false positives and escalate true matches. Transaction monitoring: triage alerts from the monitoring system, investigate flagged activity, and document your analysis and disposition. Case investigation: gather evidence, follow the money flow, and build a clear written rationale for each decision. Escalation: raise well-documented suspicious activity to the relevant market MLRO promptly - you identify and escalate; the MLRO decides on filing. Ongoing diligence: support periodic reviews, trigger-based re-screening, and record-keeping to standard. Work to defined SLAs and contribute to keeping queues clean and turnaround fast. WHAT YOU'LL BRING (MUST-HAVE) ----------------------------- 1-3 years in AML/KYC/KYB operations, compliance ops, fraud, or merchant onboarding - ideally in payments, fintech, or banking. Strong, consistent attention to detail and sound judgment on incomplete information. Clear written English - your case notes and escalations must stand on their own for a reviewer or auditor. Comfort working at volume against SLAs without dropping quality. Integrity and discretion handling sensitive customer data. NICE TO HAVE ------------ Exposure to screening tools and transaction-monitoring / case-management systems. Familiarity with SEA regulatory environments (MAS, BSP, BNM, AUSTRAC). Working knowledge of an additional regional language. Progress toward an AML certification (CAMS, ICA) is a plus.

Compliance Manager & MLRO, Malaysia
MY / Remote (MY)Full-time3+ years$1K - $5K / monthlyVisa: US citizen/visa only
What the role involves

ABOUT THE ROLE -------------- HitPay is licensed across five markets and is building out a per-jurisdiction compliance structure. This role owns regulatory compliance and the MLRO function for our Malaysia entity end-to-end - you are HitPay's accountable compliance owner in-market and the BNM-designated Compliance Officer. You'll set local policy, own the regulator relationship with Bank Negara Malaysia (BNM), and be the single escalation point and decision-maker for suspicious transaction reporting. This is a second-line control role: you design and test the controls and own the STR decision - you are deliberately separate from the first-line AML Operations team that runs day-to-day onboarding and alert triage. WHAT YOU'LL OWN --------------- Regulatory Compliance Own HitPay Malaysia's AML/CFT/CPF and TFS compliance with BNM requirements, and keep policies and procedures current as regulations and ML/TF/PF typologies evolve. Act as the reference point for all AML/CFT/CPF matters in the Malaysia entity. Manage the BNM relationship: regulatory reporting, submissions, examinations, and correspondence. Run independent control testing and periodic assessments of the AML/CFT/CPF framework's effectiveness - sample reviews, exception-report review, and remediation tracking. Advise the business on new products, corridors, technology and operational changes, and assess the ML/TF/PF risks they introduce. Deliver AML/CFT/CPF training across the Malaysia organisation and ensure reporting channels are understood and secure. MLRO Serve as the single point to whom all staff escalate suspicion; evaluate internal escalations from the AML Ops team. Make the final determination on, and file, Suspicious Transaction Reports to BNM's Financial Intelligence and Enforcement Department, with proper documentation of every decision - including reasoned decisions NOT to file. Maintain the independence and authority to escalate directly to senior management and the Board where needed. WHAT YOU'LL BRING (MUST-HAVE) ----------------------------- Demonstrable AML/CFT/CPF compliance experience in a BNM-regulated environment (payments, money services, e-money, banking, or fintech). The stature, authority and seniority to influence decisions and stand firm on compliance positions. "Fit and proper" standing - probity, personal integrity and reputation; competency and capability; financial integrity. Working knowledge of the AMLA 2001, BNM AML/CFT/CPF & TFS Policy Documents, and current ML/TF/PF typologies. Sound judgment under ambiguity and a documentation-first habit - your STR rationale must withstand regulator review. Fluency in English and Bahasa Malaysia. NICE TO HAVE ------------ Recognised AML/CFT certification or professional qualification - e.g. CAMS, ICA, or the AICB AML certification. Experience standing up or maturing a compliance function in a scaling fintech. Familiarity with screening and transaction-monitoring tooling.

Risk, Fraud & AML Analyst — HitPay
SG / Kuala Lumpur, Federal Territory of Kuala Lumpur, MY / Remote (SG; Kuala Lumpur, Federal Territory of Kuala Lumpur, MY)Full-time3+ years$3K - $8K / monthlyVisa: US citizen/visa only
What the role involves

================================================================ WHY THIS ROLE EXISTS ================================================================ HitPay's risk surface spans card chargebacks across multiple acquirers, non-card rails (PayNow, FPX, QRPH, GCash, TouchnGo, etc.), partner onboarding fraud, the post-transaction tail that pre-tx vendors don't catch, and the full AML lifecycle — typology detection, transaction monitoring, STR/SAR filings, and regulator-facing obligations across SG/MY/PH/HK/AU/US. We've built an automated detection stack that does the sweeping. What we need is a human in the loop who can investigate every exception, decide what's real, file what needs filing, and extend the toolset when a new typology shows up. This is not a queue-clearing role. The automation produces the queue. You bring the judgment, the partner conversations, the regulatory filings, and the next piece of automation. ================================================================ WHAT YOU'LL OWN ================================================================ Daily investigation of every exception surfaced by the automated stack: - Post-tx fraud signals across all acquirers and rails - Bust-out, mule-ring, scam-proceeds, payout-redirect, and ATO patterns - ATV outliers, chargeback spikes, reserve adequacy, partner abandonment - Onboarding red flags surfaced before payments are enabled AML lifecycle ownership: - Transaction monitoring across all rails — review alerts, escalate, close with reasoning - STR/SAR drafting and filing across SG (STRO), PH (AMLC), MY (BNM), and any other jurisdiction we operate in - Ongoing CDD reviews — periodic refresh, EDD for higher-risk partners, source-of-funds and source-of-wealth investigations - Sanctions and PEP screening — adjudicate matches, document false positives, action true hits - Typology calibration — when a new laundering pattern shows up, you're the one who recognises it and writes it up Decision and action on every flag: - Payment/payout status decisions (suspend, hold, offboard, retain with monitoring) - Reserve adjustments - Partner outreach for SoF, SoW, business model clarification - Coordination with regulators, scheme risk teams, and partner banks - Closing every exception with a documented rationale Tooling (this is the multiplier): - When you see a typology the current stack misses, extend it or build a new detector for it - Backtest every rule change against labeled good/bad cohorts before it goes live - Every piece of automation you write is one fewer human-hour the team burns per week — that's the job ================================================================ WHO YOU ARE ================================================================ Compliance, AML, and risk background, non-negotiable: - 4+ years in payments/fintech risk + AML, scheme-side fraud ops, or regulated FI transaction monitoring - You've personally drafted and filed STRs/SARs — not just reviewed them - Working knowledge of at least two of: MAS PSA, BSP MAL, BNM Merchant Acquirer, AUSTRAC, FinCEN MSB, FATF recommendations - You can read a chargeback dispute, an unusual transaction pattern, or a partner's website and tell us in 60 seconds whether the partner is a target, a launderer, or a real business having an outlier month - CAMS, ICA, or equivalent certification is a plus, not a requirement — we care more about the calls you've made Technical, non-negotiable. You must be technical enough to: - Query the data warehouse directly — write your own SQL against Snowflake, no analyst middleman. You'll be doing this every day. - Think in rules and thresholds — translate a typology you've spotted into a concrete, testable detection rule (signals, thresholds, edge cases, expected false-positive rate). - Backtest before shipping — every rule change runs against labeled good and bad cohorts before it goes live. No exceptions. If you don't know how to set up a backtest, you're not ready for this role. - Run and e

Roles are as last read from the company’s own listings. Openings close without notice — check the date on the listing before you spend an evening on the application.

Check the company’s own careers page — linked at the top — before a job board. A role appears there first, sometimes weeks before it is syndicated anywhere else.

Questions and experiences

Nobody has asked anything about HitPay yet. If you have interviewed here, what you know is worth more to the next person than anything on the rest of this page.

Reviewed before it appears. Do not include anything that identifies you or anyone else.

Company facts compiled from public sources and last refreshed 9 September 2026. Details change; treat the company’s own site as the authority.

jobo is a browser extension. Open this on a computer to install it.