Sobre este puesto de Compliance Analyst/Manager, Issue Management en Cardless
We're looking for a compliance professional to own issue management end to end: the inventory of known compliance issues across our card programs, the corrective action plans that resolve them, the consumer remediation that makes affected customers whole, and the reporting that tells our bank partners exactly where each issue stands.
This is the role that decides whether a problem is actually fixed. Not fixed on a ticket, not fixed in a status update, but fixed in the product, validated with evidence, and closed with a record that holds up when an examiner reads it two years later.
Cardless is a program manager that partners with FDIC- and OCC-regulated issuing banks to design and deliver co-branded credit and debit card programs. Our compliance team operates within this bank partnership model, which means every issue you work has to satisfy us, a brand partner, and an issuing bank with its own regulator, issue management guidance, numbering conventions, and reporting cadence. Understanding the program manager structure is key to succeeding in this role.
This is a hands-on, individual-contributor role, and we are open on level. Depending on what you bring, this is an analyst seat or a manager seat, and the title and the offer follow what you can actually do. We care much more about how you think than about how many years you have done it. Today this work is done by our Compliance Officer alongside everything else he owns, which means it competes with whatever is on fire that week. Our bank partner told us plainly that this function needs a dedicated person who does not get pulled away. That person is you.
You do not need a background in banking. Most postings like this one ask for years inside a bank. We are not going to. The regulations are learnable and we will teach them. What we cannot teach is the instinct to look at a number that does not add up and refuse to move on, so that is what we are screening for.
You will inherit a real inventory: a live issue log spanning multiple bank partners, issues at every stage from newly identified through remediating to pending validation, and remediation populations that run from a handful of accounts into the thousands. Some of it is well documented. Some of it needs to be rebuilt into something defensible. You will be the one who knows, at any moment, what is open, who owns it, when the harm stopped, and what is left to prove.
This is a high-ownership role for someone who is energized by messy, cross-functional problems and who is not satisfied with closing a ticket when the thing that caused it is still there.
Responsibilities
Own the issue inventory
Own the compliance issue log end to end: intake, classification, root cause, target dates, status, and closure, across every card program and bank partner.
Log newly identified issues with the facts that matter: what broke, which regulation or requirement it touches, when it started, when consumer harm stopped, and how many customers are affected.
Keep the log reconciled to each bank partner's own issue register, one for one, so the two records never tell different stories.
Maintain a dated chronology for each issue at a granular level. Examiners ask what happened, when, who knew, and when it reached a compliance committee. The answer needs to already exist.
Reassess aged issues honestly and negotiate achievable remediation timelines with the bank rather than letting dates quietly slip.
Drive corrective action to validated closure
Write corrective action plans that name the defect, the fix, the owner, the target date, and the evidence that will prove it worked.
Establish and document the date ongoing consumer harm stopped for every consumer-impacting issue, and push for an interim control when the permanent fix is months away.
Work with Engineering, Product, and Operations to get the underlying defect fixed, and distinguish a durable fix from a point patch that will resurface as a repeat finding.
Test the fix yourself, or make sure someone did, before you call an issue remediated.
Escalate early and in writing when a remediation date is going to be missed, or when a previously closed issue comes back.
Scope and run consumer remediation
Scope impacted populations by sub-issue, including the overlaps, so there is a full picture of who needs which kind of remediation.
Design the remediation: what each affected population is owed, how it gets delivered, and how customers who are closed, charged off, or otherwise hard to reach are handled rather than quietly dropped.
Verify after the fact that every customer received the amount they were supposed to receive, and build the audit trail that proves it.
Partner with Finance and Operations on payment execution, and own the reconciliation when the numbers do not match.
Report to bank partners and governance
Produce the monthly issue log for each bank partner on a fixed date, with accurate status on every open item.
Adopt and operate to each bank partner's issue management guidance, and adapt to differing expectations across partners.
Respond to bank partner and examination requests on open issues, including remediation status, populations, and evidence, on short turnarounds.
Prepare issue management reporting for the Compliance Committee and the Board.
Strengthen the program
Improve the tooling and workflow behind issue management, including automation, so the program scales faster than headcount.
Turn recurring issue patterns into preventive controls and monitoring, so the same defect class does not come back.
Keep issue records organized, complete, and examination ready at all times, not assembled in a scramble when a request arrives.
Provide coverage across other compliance functions, as needed.
Requirements
You think critically and you show your work. Given a problem with incomplete information, you can work out what actually happened, say what you are confident about and what you are not, and defend where you drew the line. This is the requirement. Everything else on this list is secondary to it.
You finish things. You have personally taken a problem from "something is wrong here" through to fixed and verified, in whatever domain you have worked in. You are the person who checks that the fix held rather than assuming it did.
You work with AI and you want to get better at it. You use AI tools in your actual work today, you have a sense of where they are reliable and where they are not, and you check their output instead of forwarding it. We will give you every tool we have; we expect you to outrun the job with them.
You are comfortable around data. You can read a number, work out whether it can possibly be right, and notice when a count contradicts itself. You do not need to be an engineer.
You write clearly. A large share of this job is writing: corrective action plans, issue narratives, remediation summaries, and reporting that our bank partners and their regulators read. Plain, precise, and defensible beats polished.
You are willing to learn the regulations. You do not need to arrive knowing Regulation Z, Regulation E, Regulation B, UDAAP or FCRA. You do need to be genuinely interested in learning them properly, because the work does not make sense without them.
You are organized enough to hold a lot at once. Dozens of open items with hard dates, and you do not lose one.
You are self-directed. There is no playbook here and no daily check-in. You see what is broken or missing, you take it, and you follow through without being asked.
Any background is welcome. Financial services, operations, audit, consulting, analytics, engineering, science, law, the military, teaching, or something we have not thought of. What matters is the evidence that you think and finish.
Bonus Points
You can write a query. SQL against a warehouse, enough to pull and check a population yourself rather than waiting on someone. This is the single most useful extra thing you could bring.
You build your own tooling: scripts, automations, agents, dashboards, whatever removes the manual step.
Experience in consumer finance, credit cards, payments, lending, disputes, rewards, or servicing operations, which is where many of our issue root causes live.
Experience owning compliance issues, corrective action, remediation, internal audit, compliance testing, or a restitution or make-whole program.
Experience supporting a regulatory examination or an external audit: assembling evidence, answering follow-up requests on a clock, holding a consistent record across dozens of open items.
Experience building or maturing a program rather than inheriting a finished one.
CRCM or another consumer compliance certification.
Before You Apply
A few things worth knowing:
We work in the office 5 days a week. We know that is a dealbreaker for some people, and that is okay.
This is an early-stage company. We are a small team servicing hundreds of thousands of customers. You will be building processes that do not exist yet, not optimizing ones that do. If you want structure handed to you, this is not the right fit.
You will need to be highly self-directed. There is not a playbook for this role, and you will not get daily check-ins. We are looking for someone who sees what is broken or missing, takes ownership, and follows through without being asked.
The pace is intense, and this role is hands-on. We have aggressive goals and a lot to build. This is not a 9-to-5, quiet, maintenance-mode compliance job, and you will be in the middle of everything.
You are inheriting a real backlog, not a clean slate. Some of these issues are older than we would like and some are harder than they look. If that sounds like a problem to run from rather than a problem to solve, this is not the role.
Issues are real customers who did not get what they were owed. We take that seriously, and we expect you to as well.
If that scared you off, no hard feelings. If it got you excited, keep reading.
Why This Role is Cool
You get the whole loop. Most issue management roles stop at the tracker. This one runs through root cause, corrective action, consumer remediation, and validation, so you actually get to fix things rather than report on them.
Our bank partner asked for this role by name. You are arriving with a mandate, which is a rare thing in compliance.
Build the program, do not inherit it. The issue log exists and it works, but you will turn it into an operating program with real controls, real validation, and reporting nobody has to rebuild by hand.
Your work goes straight to our bank partners, the Compliance Committee, and the Board, and it is read by regulators.
You will sit at the intersection of Compliance, Engineering, Product, Operations, and Finance, which is the best seat in the company for understanding how everything actually works.
We are AI-forward, and we mean it. If you want to automate the boring parts of this job, nobody will stop you (in fact, we give you all the resources to do it).
Compensation
This role has an annual starting salary range of $120,000 to $160,000 plus equity and benefits. Because we are open on level, where an offer lands in that range depends on whether the role is scoped at analyst or manager level for you. Actual compensation is influenced by a wide array of factors including but not limited to skills, experience, and specific work location.
Benefits
We're proud to offer our team excellent benefits:
💵 Meaningful Start-up equity
🏥 100% health, vision & dental primary coverage
➕ 75% health, vision & dental dependent coverage
🍱 Catered lunches
🚺 $250/month Commuter benefit
👶 Parental leave
✈️ Team building events & happy hours
🌴 Flexible PTO with a minimum of 15 days off per year
🖥️ Apple equipment
💵 401k plan
Location
We're headquartered in San Francisco, CA, with a beautiful office in Jackson Square, near the Transamerica building. Very convenient between the Montgomery and Embarcadero BART stations. This role is in-office 5 days a week.
Who Thrives in This Role, and What Success Looks Like
Who thrives here
You are the person who reads "fixed, deployed" and asks to see the list. Wherever you have worked, you have been the one who checked, found the thing nobody had noticed, and said so. You are precise about numbers because you have been burned by an imprecise one, and you would rather be told your analysis missed a segment than be agreed with.
You write clearly and you write fast, because this job is mostly writing under a deadline, and what you write gets read by people whose job is to find the gap in it. You are organized enough to hold dozens of open items with hard dates and not lose one.
You are already working with AI, not curious about it in the abstract. You know where it is strong, you check it where it is weak, and you would rather build the thing that does the task twice than do the task twice.
You are comfortable with a blank page and you see it as something to build. You do not need to have done compliance before, but you want to learn why a rule exists rather than just what it says. And you are energized, not unsettled, by a program manager model where the same issue has to satisfy us, a brand partner, and an issuing bank with its own regulator.
What success looks like
In your first 90 days, you own the issue log. You know every open issue, its status, its owner, and its target date without looking it up. You have learned our programs, products, and partners well enough to scope a population without a chaperone. The log reconciles to each bank partner's register, the monthly reporting goes out on its committed date, and every consumer-impacting issue has a documented date that harm stopped.
By six months, you own a functioning issue management program: consistent intake and classification, corrective action plans with real evidence standards, remediation that is scoped by sub-issue and verified after payment, and reporting that bank partners recognize as an improvement. You have taken a meaningful share of the open inventory to validated closure, and the issues you closed have stayed closed. Recurring defect classes now have monitoring in front of them, so the next one gets caught by a control instead of by a customer. Issue management has gone from the thing we scramble on before a bank call into the program the rest of compliance is measured by.