Head of Audit, Risk, and Compliance
Job description
Head of Audit, Risk, and Compliance at Navan.
About the role
This position involves establishing and overseeing Navan's entire governance system, bringing together Internal Audit, Enterprise Risk, and Regulatory Compliance. You will report to the CFO and be responsible for creating a flexible, technology-focused framework that supports business innovation while ensuring safety. The role requires delivering independent assurance to the Audit Committee and Executive Management, as well as collaborating with Finance, Legal, Security, and Product teams to manage risk effectively.
Key facts
What you'll do
- Develop and implement a comprehensive, multi-year plan for Navan's global Audit, Risk, and Compliance functions, balancing public company requirements with fast-paced business growth.
- Manage the complete SOX and ICFR readiness strategy, and create a risk-based internal audit plan that provides useful insights on control health to the Audit Committee.
- Oversee the global regulatory compliance strategy, including requirements specific to fintech and travel, sanctions (OFAC), KYC/KYB, and trade pre-clearance.
- Modernize compliance and audit operations by using automation and data analytics to improve third-party due diligence, banking/ABL reporting, and internal control monitoring.
- Work with Finance, Legal, Security, and Product to integrate compliance controls into business processes and ensure lasting solutions for identified issues.
- Recruit and develop a diverse team, advise the C-suite and Board on strategic risk and governance, and build a strong relationship with the Audit Committee Chair.
Requirements
- Over 12 years of increasing leadership experience in internal audit, SOX, enterprise risk, and compliance, preferably in high-growth technology, fintech, or complex public company settings.
- Strong understanding of SOX/ICFR, risk management frameworks (COSO/ISO), regulatory/sanctions compliance (OFAC, KYC), international travel compliance, and ITGCs.
- Experience auditing automated controls, cloud infrastructure, and data flows, with an understanding of technology's impact on financial data integrity and how to use automation for efficiency.
- Demonstrated ability to convert complex regulatory requirements into clear, automated software workflows and efficient operational processes.
- Proven capability to explain technical risk and governance concepts as strategic, actionable information for executive leadership, the Board, and external regulators.
- A pragmatic approach to building and designing processes, balancing strict compliance standards with operational speed to ensure compliance supports rather than hinders operations.
Nice to have
- Active professional certifications such as CPA, CIA, CISA, or CRCM.
- An advanced degree like an MBA or JD.
Skills & tools
- Internal Audit
- SOX (Sarbanes-Oxley Act)
- Enterprise Risk Management
- Regulatory Compliance
- ICFR (Internal Control Over Financial Reporting)
- COSO Framework
- ISO Framework
- OFAC (Office of Foreign Assets Control)
- KYC/KYB (Know Your Customer/Business)
- ITGCs (IT General Controls)
- Automation
- Data Analytics
- Cloud Infrastructure
Practical notes
Navan prioritizes in-person collaboration, with employees expected to work from the office four days a week. The company offers a comprehensive benefits program, including healthcare, insurance, wellness resources, retirement savings, equity plans, flexible time off, and paid parental leave. Navan is an equal opportunity employer and provides accommodations for disabilities.