Risk Control Analyst, Card & ATO Risk
Summary
Design and deploy risk controls for card fraud and account takeover at a global crypto exchange, using SQL, rules, and AI-driven detection pipelines.
Responsibilities:
- Serve as the primary risk point of contact for card issuer side risk matters, including BIN card fraud, transaction monitoring, and card lifecycle risk controls
- Collaborate with payment and card business teams to gather requirements, propose risk control measures, and drive end-to-end implementation
- Design and deploy risk rules and strategies for card-related scenarios, including card opening, credit limit adjustments, transaction authorization, and dispute/chargeback handling
- Monitor card risk metrics, conduct post-event analysis, and continuously optimize control effectiveness
- Evaluate third-party card risk vendors and solutions; drive integration where valuable
- Design and deploy ATO risk control strategies, including risk analysis, feature extraction, rule/strategy deployment, and control flow design
- Build and refine ATO detection and prevention pipelines across login, device, transaction, and account-change scenarios
- Leverage risk signals (device, IP, behavioral, biometric) to construct multi-layered defense chains
- Analyze attack patterns and emerging threats; translate insights into actionable detection rules and mitigation strategies
- Document risk control designs, decision logs, and post-incident reviews
- Work with data and engineering teams to implement and tune risk models and rules
- Participate in cross-functional projects spanning payment, compliance, and product teams
Requirements:
- 3+ years of experience in risk control, fraud prevention, or a related analytical role
- Hands-on experience designing and deploying risk rules/strategies in a real-time production environment
- Strong analytical skills: ability to extract risk features from data, build detection logic, and measure control effectiveness
- Solid understanding of risk control frameworks, including rule-based systems, scoring models, and layered defense design
- Proficiency in SQL and data analysis tools; comfortable working with large datasets
- Strong communication and stakeholder management skills — ability to translate business needs into risk control requirements and drive cross-team execution
- Experience using AI tools in day-to-day work, e.g., leveraging AI to analyze risk issues, automate and optimize rules, screen data, or accelerate investigation workflows
Preferred
- Experience in Card risk control on the issuer side (BIN management, authorization risk, 3DS, card fraud detection)
- Experience with ATO, account fraud, or identity risk domains
- Experience working with third-party risk vendors (e.g., face verification, device fingerprinting, fraud scoring)
- Knowledge of regulatory and compliance considerations in card and fintech risk
- Bilingual English/Mandarin is required to effectively coordinate with overseas partners and stakeholders.