Apply Edge Start your job search

Fintech Business Analyst – AML & GRC

Solidrange · Riyadh, Riyadh, Saudi Arabia

Apply & track with Apply Edge

Company DescriptionSolidrange is a cybersecurity company based in Riyadh, specializing in developing modern platforms to address cybersecurity and enterprise Governance, Risk, and Compliance (GRC) challenges. Our vision is to transform the GRC technology landscape, helping organizations modernize their practices and reduce operational overhead. Our mission centers on reducing human-driven cybersecurity risks, simplifying compliance and risk management, and facilitating seamless business continuity.Job SummaryWe are seeking a fintech-oriented Business Analyst with demonstrable knowledge of Anti-Money Laundering (AML) and Saudi Arabia’s Capital Market Authority (CMA) and Saudi Central Bank (SAMA) regulatory environments, together with practical GRC exposure in the AML domain. This is a product-development role rather than an operational customer-onboarding position. The role will support the design and enhancement of fintech products by translating AML/CFT obligations, user needs, and market requirements into product requirements, platform workflows, controls, user stories, data rules, and test scenarios. The selected candidate will partner with Compliance, the MLRO, Risk, Product, Technology, and Operations teams to develop AML and GRC product capabilities such as KYC/CDD configuration, sanctions and PEP screening, transaction monitoring, case management, regulatory reporting, control assurance, and audit evidence.Key Responsibilities· Elicit, analyze, document, and prioritize business and regulatory requirements for fintech AML and GRC capabilities.· Translate applicable Saudi CMA and SAMA AML/CFT rules, implementing regulations, circulars, and supervisory expectations into business rules, controls, workflows, acceptance criteria, and traceability matrices.· Analyze AML-related product journeys and capabilities—including configurable KYC/CDD, enhanced due diligence, beneficial ownership, sanctions and PEP screening, transaction monitoring, alert investigation, case management, escalation, and regulatory reporting—to define functional requirements and product improvements. The role supports these capabilities but does not perform customer onboarding or operational AML processing.· Facilitate workshops with Compliance, MLRO, Risk, Operations, Product, Engineering, Information Security, Internal Audit, and other stakeholders.· Develop business requirement documents, process maps, user stories, use cases, data requirements, decision tables, functional specifications, and test scenarios.· Support AML risk assessments, control mapping, issue management, remediation tracking, regulatory change assessments, and maintenance of evidence within the GRC platform.· Define and validate data fields, risk-rating logic, customer segmentation, alert scenarios, thresholds, workflow rules, dashboards, and management information requirements.· Coordinate user acceptance testing, defect triage, requirements traceability, release readiness, and post-implementation validation for AML and compliance features.· Identify product, control, data, integration, and user-experience gaps; assess their impact and recommend practical fintech product enhancements that balance regulatory compliance, usability, scalability, and operational efficiency.· Maintain clear documentation and support audit, assurance, and regulatory examinations by ensuring requirements, approvals, evidence, and remediation actions are traceable.Required Qualifications· Bachelor’s degree in Business Administration, Finance, Information Systems, Computer Science, Cybersecurity, or a related field.· Demonstrable experience as a Business Analyst or Product Analyst in a fintech, capital-markets, investment, payments, RegTech, or other regulated financial-services environment.· Strong AML/CFT domain experience sufficient to shape fintech product capabilities across configurable KYC/CDD, enhanced due diligence, beneficial ownership, sanctions and PEP screening, transaction monitoring, alert investigation, case management, and suspicious activity escalation; operational customer-onboarding responsibility is not required.· Mandatory experience working with Saudi CMA and SAMA requirements in a regulated institution, fintech, capital-markets business, banking or payments environment, or implementation serving CMA- or SAMA-regulated clients.· Proven ability to interpret Saudi AML/CFT obligations and applicable CMA and SAMA requirements and translate them into business rules, controls, workflows, data requirements, functional specifications, user stories, acceptance criteria, and traceability matrices.· Practical GRC exposure within the AML domain, including risk and control mapping, regulatory change assessment, issue management, remediation tracking, control testing, audit evidence, and management reporting.· Experience supporting UAT, defect management, workflow validation, and cross-functional delivery with compliance, product, engineering, operations, and data teams.· Strong analytical, documentation, communication, and stakeholder-management skills; professional proficiency in English, with Arabic an advantage.· Ability to work on-site in Riyadh and collaborate closely with Compliance, the MLRO, Risk, Product, Technology, and Operations teams.Preferred Qualifications· Experience supporting product development in a CMA- or SAMA-regulated fintech, investment platform, bank, payments business, or RegTech/AML solution provider.· Exposure to Saudi AML/CFT regulatory examinations, compliance monitoring, risk assessments, suspicious transaction reporting processes, or remediation programs.· Familiarity with AML transaction-monitoring, screening, KYC, case-management, data-analytics, ticketing, or GRC platforms.· Knowledge of API-driven fintech ecosystems, digital identity and verification services, data lineage, rules engines, configurable workflows, and system integrations.· Relevant certifications such as ACAMS, ICA, CBAP, ECBA, or a recognized GRC, risk, or compliance qualification are advantageous. Key Skills and Competencies· Fintech business analysis and requirements management· AML/CFT, KYC, CDD/EDD, sanctions, PEP, transaction monitoring, and case management· Saudi CMA and SAMA regulatory interpretation and regulatory change analysis· GRC controls, risk assessments, issues, evidence, and remediation tracking· Process mapping, user stories, acceptance criteria, and requirements traceability· Data analysis, risk-rating logic, rules validation, and management reporting· UAT planning, defect triage, and release validation· Cross-functional stakeholder facilitation and clear documentationRole Focus · The primary focus is business analysis and product development for fintech AML and GRC capabilities in CMA- and SAMA-regulated contexts.· The role connects regulatory obligations and user needs with product discovery, requirements, data, controls, integrations, workflows, testing, release readiness, and continuous product improvement.· The position is product- and technology-oriented. It supports the design of customer-onboarding and AML features but does not execute customer onboarding, alert investigations, case handling, or other operational AML activities.Notes for Recruitment Use · Prioritize candidates who can demonstrate direct AML process knowledge and explain how a CMA or SAMA requirement was converted into a business, control, data, or system requirement.· Assessment questions should test practical fintech product scenarios involving configurable KYC/CDD, sanctions or PEP screening, transaction-monitoring rules, case-management workflows, regulatory change, integrations, and GRC evidence—not the execution of customer onboarding.· During interviews, ask the candidate to produce or critique a user story, process map, acceptance criteria, and traceability approach for an AML control or workflow.