Risk Control Lead Engineer
Klarna, briefly
At Klarna, we're building an everyday finance network, helping over 120 million consumers across 26 countries save time and money, and worry less about their finances. Working here means taking on problems most companies never get to solve, and being hands-on enough that the interesting part of the work lands with you, not someone else — you'll build with AI, not watch it happen.
This is the stretch zone. Come find out what you're capable of.
About the role
Klarna operates as a regulated financial institution across 26 markets, under regulatory frameworks including DORA, SFSA, FCA, NYDFS, and SOX. Those regulators, and Klarna's board, need an independent, evidence-based view of whether Klarna's ICT and security risks are actually under control — not just documented as under control. That's what Engineering Assurance exists to provide, and the function has been rebuilding its methodology, governance framework, and assurance programme from the ground up under new CSRO leadership since June 2026.
As a Risk Control Manager in Engineering Assurance, you'll plan and deliver risk-based assurance reviews across engineering and technology: software delivery, cloud infrastructure, cybersecurity, identity and access management, change management, incident management, resilience, and third-party technology risk. You'll work directly with engineering teams to test whether controls actually hold up, and you'll answer to senior stakeholders and regulators for what you find.
We're open to two kinds of backgrounds for this position: a technology assurance professional with Big Four experience in DORA, ICT risk, IT audit, technology risk, or regulatory compliance, or a technically strong GRC engineer from a regulated technology or fintech organisation such as Adyen, PayPal, Revolut, or Klarna itself. Which of the two you are will shape where you start, not what you're ultimately accountable for.
What you'll do
You'll plan and deliver risk-based assurance reviews that assess the design and operating effectiveness of engineering controls.
You'll review software delivery, cloud infrastructure, cybersecurity, identity and access management, change management, incident management, resilience, and third-party technology risk.
You'll translate regulatory obligations under frameworks like DORA, SFSA, FCA, NYDFS, and SOX into clear, testable technical control expectations.
You'll evaluate evidence, identify control weaknesses or systemic engineering risks, and produce defensible findings and recommendations for senior stakeholders.
You'll work constructively with engineering teams while keeping your professional judgement independent of theirs.
You'll help build automated testing, continuous control monitoring, and reusable assurance methods as the function moves from point-in-time reviews toward continuous assurance.
Who you are
You've worked in technology assurance, IT audit, ICT risk, security assurance, or GRC engineering, and you can point to specific reviews or assessments you've delivered.
You can assess both whether a control is designed correctly and whether it actually operates the way it's supposed to in practice.
You have enough technical depth in cloud, software delivery, cybersecurity, infrastructure, or operational resilience to challenge engineering teams credibly, not just document what they tell you.
You know how to evaluate evidence, recognize when it's incomplete or misleading, and reach a defensible conclusion using your own professional judgement.
You can turn a regulatory requirement into a specific, testable technical control, rather than just restating the regulation.
You've worked in a regulated or otherwise high-control environment, so you know what evidence, documentation, and independence mean in practice there.
Bonus points for
Experience within a fintech, payments company, bank, or technology-led regulated business.
Knowledge of DORA, EBA requirements, NIS2, or comparable ICT regulations.
Knowledge of ISO 27001, NIST, COBIT, SOC reporting, or ISAE assurance standards.
Experience automating evidence collection or control testing using APIs, SQL, Python, or GRC tooling.
Things you should know before applying
Working together: we value co-located teams; most teams currently meet in the office 2–3 days per week, and this varies by team and can change over time.
Non-obvious backgrounds are welcome. Diversity of skills, perspectives and backgrounds is how we create, innovate, and disrupt like no other.
Final compensation will be based on the candidate's qualifications, skills, and experience.
Please include a CV in English. Concrete beats comprehensive — what you built, what it did, what it cost. Curious to learn more about Klarna and what it's like to work here? Explore our career site!
About the Company
More jobs at Klarna
-
Senior Data Scientist - Fraud Model Validation
London · · Sep 14, 2026
-
Senior Data Scientist - Fraud Model Validation
Milan · · Sep 14, 2026
-
Senior Machine Learning Engineer - Credit modelling
Milan · · Sep 8, 2026
-
Senior Machine Learning Engineer - Credit modelling
Warsaw · · Sep 8, 2026
-
Lead Engineer
London · · Sep 4, 2026