Director FCC Governance, Data and Risk Oversight
Description

Who We Are

Thread Bank is a digital-first financial technology community bank that aims to enhance customer engagement through innovative solutions. Thread Bank offers a modern website, a CRM system, and a mobile app to simplify banking for businesses and individuals. Our embedded banking solution helps business technology platforms provide secure banking experiences. We also partner with other banks, credit unions, and FinTechs to integrate compliant financial solutions. Thread Bank values innovation, collaboration, and flexibility, offering excellent benefits and a family-friendly culture.


What We Are Looking For

The Director, FCC Governance, Data, and Risk Oversight leads Thread Bank’s financial crimes compliance (FCC) program governance, data integrity, quality control, and risk oversight functions. Reporting to the Chief BSA Officer, this role ensures that financial crimes controls operate as designed, that data supporting those controls is accurate and auditable, and that the Bank maintains examination-ready documentation across all FCC verticals. The role carries particular significance within Thread Bank’s embedded banking model, where a substantial share of financial crimes risk sits inside partner programs and third-party platforms that require active governance and oversight.


What You’ll Do


Transaction Monitoring Oversight and Rule Governance  

  • Govern the transaction monitoring platform, including scenario inventory, rule logic, segmentation, thresholds, and coverage against the Bank’s assessed risks and product set
  • Demonstrate working-level command of rule construction, including how parameters and lookback windows behave, how segmentation and customer risk attributes drive selection, and how a rule change propagates through alerts, cases, and SAR outcomes
  • Own the tuning lifecycle end to end, covering coverage assessments, above-the-line and below-the-line testing, threshold analysis, sample design, results documentation, approval, and post-implementation validation
  • Confirm that data feeding the platform arrives complete, mapped correctly, and current, and ensure platform constraints such as rule caps, field limits, ingestion failures, and vendor defects are documented, escalated, and tracked to resolution
  • Analyze alert-to-case conversion, case-to-SAR conversion, productivity, false positive rates, and aging, and translate findings into rule, staffing, or process action
  • Support model risk management for monitoring, sanctions screening, fraud, and customer risk rating models, including documentation, validation support, and remediation of validator findings

Data Governance, Analytics, and Reporting Integrity

  • Serve as FCC business owner for data governance, data quality, and reporting integrity across all FCC systems of record
  • Query FCC data directly using SQL, Python, or the Bank’s analytics and BI tooling to validate populations, reconcile counts, test control assertions, and respond to examiner questions
  • Establish controls over FCC data sourcing, transformation, reconciliation, and reporting, including control totals, completeness checks, and exception handling
  • Document data lineage from source system through transformation to the reported metric, and substantiate that lineage on demand
  • Build KPIs, KRIs, dashboards, and executive metrics with defined calculation logic, thresholds, tolerances, and named owners
  • Partner with Technology, Data, and Analytics teams on FCC data architecture, field mapping, feed monitoring, and remediation of defects that degrade monitoring coverage
  • Detect and escalate data gaps that suppress alerts, misstate risk ratings, or understate exposure, and treat each as a control failure until analysis confirms otherwise

Quality Control Ownership and Program Build-Out

  • Work with the CRO, CDO and Compliance to own and deliver Thread’s quality control program for FCC end to end, including methodology, coverage standards, staffing models, reporting and independence of review.
  • Lead the build-out of an enhanced QC function that scales with partner growth, advancing the program from sampling for defects toward measuring control effectiveness
  • Define QC methodology: risk-based sample design, coverage targets by vertical and partner, defect taxonomy, severity ratings, scoring standards, and acceptance thresholds
  • Extend QC coverage across alert and case dispositions, SAR decisioning and filing quality, CIP and KYC, CDD and EDD, customer risk rating outcomes, fraud dispositions, high-risk and prohibited business reviews, and partner-delegated work
  • Run calibration across reviewers and verticals to ensure QC results measure the work rather than the reviewer, and document rationale where analysts and QC disagree
  • Build QC analytics and automation, including sample selection logic, exception queues, trend reporting, and targeted testing
  • Convert QC results into action: root cause analysis on recurring defects, feedback loops into training and procedures, retraining triggers, and issues raised when defect patterns reflect a control weakness
  • Report QC results to FCC leadership, governance committees, and examiners with defect rates, themes, remediation status, and a defensible view of program quality over time
  • Coordinate QC with internal audit, independent testing, and partner assurance to ensure coverage without duplication

Fraud, FIU, and CIU Oversight

  • Establish oversight reporting for Fraud, FIU, and CIU covering volume, SLA adherence, quality results, staffing capacity, and control effectiveness
  • Own the FCC control framework, including control inventories, testing standards, issue tracking, and reporting
  • Evaluate control effectiveness across onboarding, monitoring, investigations, fraud, and partner oversight activities
  • Drive continuous improvement across FCC verticals and retire controls that no longer address the underlying risk

Customer Risk and Due Diligence Program Governance

  • Provide governance over CDD, EDD, customer risk ratings, high-risk customer reviews, and prohibited business reviews
  • Validate methodology and configuration changes, including risk factors, weights, scoring logic, and override treatment, and confirm that documentation matches production configuration
  • Track population reviews, remediation campaigns, and backlog burn-down with counts the Bank can defend
  • Test operating effectiveness of onboarding and due diligence controls across direct and partner-originated channels, including delegated KYC arrangements

Problem Detection and Root Cause Analysis

  • Reconcile what systems show against what reporting states, and investigate discrepancies
  • Lead root cause analysis on control failures, data defects, missed or late filings, and vendor issues, distinguishing symptom from underlying cause
  • Convert findings into corrective action plans with named owners, testable exit criteria, and validation evidence
  • Track thematic issues across verticals and partners, and escalate patterns that no single queue owner can see

Governance, Issue Management, and Examination Readiness

  • Own the FCC governance framework and enhance it as the partner portfolio, product set, and regulatory expectations evolve
  • Run program-level risk tracking, issue management, corrective action planning, and escalation, and hold owners to committed dates
  • Coordinate FDIC and TDFI examinations, internal audit engagements, independent testing, and regulatory remediation from first request through closure validation
  • Maintain FCC policies, procedures, standards, and program documentation, including version control, approvals, and effective dates
  • Prepare governance committee, Executive Leadership Team, and Board materials that state risk plainly and support every conclusion with evidence
  • Maintain the FCC evidence repository so the Bank can substantiate any control assertion on request

Partner Oversight and Third-Party Risk

  • Maintain FCC partner oversight frameworks for fintech and embedded banking relationships
  • Coordinate FCC risk assessments, due diligence, and periodic reviews across the partner portfolio
  • Monitor partner remediation, assessment findings, control testing results, and ongoing oversight obligations
  • Support governance of emerging payment, embedded banking, and cross-border relationships, including delegated control arrangements and vendor platform dependencies

AI, Automation, and Model Governance

  • Support governance for AI, automation, and machine learning applied to FCC work, including scope definition, human review requirements, performance monitoring, and documentation
  • Establish validation and oversight frameworks for automation that maintain clear control ownership
  • Maintain inventories, approvals, and testing evidence sufficient to satisfy model risk and AI policy requirements

Qualifications

  • Eight or more years in BSA/AML, financial crimes compliance, fraud, or financial crimes risk management, with a substantial portion inside a regulated depository institution
  • Five or more years leading teams, including managing managers or senior individual contributors
  • Three or more years of direct experience in embedded banking, Banking as a Service, sponsor bank, or fintech partnership programs, including oversight of partner-originated customers and delegated controls
  • Demonstrated command of a transaction monitoring platform, covering rule construction, segmentation, thresholds, tuning, and testing
  • Direct ownership of a quality control or independent testing function, including methodology design, sample design, defect classification, calibration, and reporting to senior management
  • Proven record leading regulatory remediation, issue closure, and validation of corrective action
  • Deep knowledge of BSA/AML and OFAC requirements, CDD and EDD, customer risk rating methodology, transaction monitoring, SAR decisioning, and fraud typologies
  • Demonstrated root cause analysis skill, including identification of control failures that other reviewers missed
  • Strong executive communication skills, including the ability to present to Boards and examiners and defend conclusions with evidence
  • CAMS, CFCS, CFE, or comparable certification
  • Experience with Unit21, Alloy, Actimize, Verafin, Hawk, or comparable monitoring, screening, and onboarding platforms
  • Experience with a modern data stack such as Snowflake, Databricks, BigQuery, or dbt, and with a BI layer such as Tableau, Power BI, Looker, or Sigma
  • Scripting capability for analysis, sampling, and test automation using Python, R, or comparable tooling
  • Experience building governance frameworks in high-growth or de novo environments
  • Prior examination experience with the FDIC, TDFI, OCC, or Federal Reserve as the bank-side owner of the response
  • Nashville Based In-Office Position M-F


Employee must be able to perform essential functions of the position and, if requested, Thread Bank will make reasonable accommodations to enable employees with disabilities to perform the essential functions of their job, absent undue hardship, in accordance with the ADA. Thread Bank is an Equal Opportunity Employer. Thread Bank does not discriminate on the basis of race, religion, color, sex, gender identity, sexual orientation, age, non-disqualifying physical or mental disability, national origin, veteran status or any other basis covered by appropriate law. 

All employment is decided on the basis of qualifications, merit, and business need.

By submitting your application, you give Thread Bank permission to email, call, or text you using the contact details provided. We will only contact you with job-related information.