
What the role involves
================================================================
WHY THIS ROLE EXISTS
================================================================
HitPay's risk surface spans card chargebacks across multiple acquirers, non-card rails (PayNow, FPX, QRPH, GCash, TouchnGo, etc.), partner onboarding fraud, the post-transaction tail that pre-tx vendors don't catch, and the full AML lifecycle — typology detection, transaction monitoring, STR/SAR filings, and regulator-facing obligations across SG/MY/PH/HK/AU/US.
We've built an automated detection stack that does the sweeping. What we need is a human in the loop who can investigate every exception, decide what's real, file what needs filing, and extend the toolset when a new typology shows up.
This is not a queue-clearing role. The automation produces the queue. You bring the judgment, the partner conversations, the regulatory filings, and the next piece of automation.
================================================================
WHAT YOU'LL OWN
================================================================
Daily investigation of every exception surfaced by the automated stack:
- Post-tx fraud signals across all acquirers and rails
- Bust-out, mule-ring, scam-proceeds, payout-redirect, and ATO patterns
- ATV outliers, chargeback spikes, reserve adequacy, partner abandonment
- Onboarding red flags surfaced before payments are enabled
AML lifecycle ownership
- Transaction monitoring across all rails — review alerts, escalate, close with reasoning
- STR/SAR drafting and filing across SG (STRO), PH (AMLC), MY (BNM), and any other jurisdiction we operate in
- Ongoing CDD reviews — periodic refresh, EDD for higher-risk partners, source-of-funds and source-of-wealth investigations
- Sanctions and PEP screening — adjudicate matches, document false positives, action true hits
- Typology calibration — when a new laundering pattern shows up, you're the one who recognises it and writes it up
Decision and action on every flag
- Payment/payout status decisions (suspend, hold, offboard, retain with monitoring)
- Reserve adjustments
- Partner outreach for SoF, SoW, business model clarification
- Coordination with regulators, scheme risk teams, and partner banks
- Closing every exception with a documented rationale
Tooling (this is the multiplier)
- When you see a typology the current stack misses, extend it or build a new detector for it
- Backtest every rule change against labeled good/bad cohorts before it goes live
- Every piece of automation you write is one fewer human-hour the team burns per week — that's the job
- ================================================================
- WHO YOU ARE
- ================================================================
Compliance, AML, and risk background, non-negotiable
- 4+ years in payments/fintech risk + AML, scheme-side fraud ops, or regulated FI transaction monitoring
- You've personally drafted and filed STRs/SARs — not just reviewed them
- Working knowledge of at least two of: MAS PSA, BSP MAL, BNM Merchant Acquirer, AUSTRAC, FinCEN MSB, FATF recommendations
- You can read a chargeback dispute, an unusual transaction pattern, or a partner's website and tell us in 60 seconds whether the partner is a target, a launderer, or a real business having an outlier month
- CAMS, ICA, or equivalent certification is a plus, not a requirement — we care more about the calls you've made
Technical, non-negotiable. You must be technical enough to
- Query the data warehouse directly — write your own SQL against Snowflake, no analyst middleman. You'll be doing this every day.
- Think in rules and thresholds — translate a typology you've spotted into a concrete, testable detection rule (signals, thresholds, edge cases, expected false-positive rate).
- Backtest before shipping — every rule change runs against labeled good and bad cohorts before it goes live. No exceptions. If you don't know how to set up a backtest, you're not ready for this role.
- Run and e
About HitPay
HitPay is a full stack payments infrastructure platform designed for growing businesses in APAC. Founded in 2016 and headquartered in Singapore, HitPay unifies e-commerce, point of sale, and B2B payments into a single platform. The company is regulated in 6 APAC jurisdictions and backed by leading global investors, including Tiger Global, Y Combinator, Global Founders Capital, and HOF Capital.
Full HitPay profile