Independent Group Risk Manager
Key responsibilities
Risk Governance Framework & Risk Appetite
Establish and maintain the Group Risk Register covering all business lines and entities, and establish a Group-wide Risk Taxonomy aligned with Compliance
Establish risk-rating standards and provide independent risk assessments for individual projects based on five dimensions: data sensitivity, exposure surface, impact radius, scale of change, and third-party dependency
Translate the CEO's defined risk appetite into a structured framework with clear and measurable requirements
Incident Management & Independent Review
Take ownership of the triage owner role within the Group Incident Reporting mechanism and conduct independent reviews of L2 / L3 incidents to validate root cause and assess preventive measures
Monitor implementation and effectiveness of preventive measures across four levels (L0 elimination, L1 clarification, L2 redesign, L3 automation) and provide quarterly trend reporting
RCSA & Key Risk Indicators (KRI)
Design and maintain RCSA templates and control checklists, and design KRIs covering areas such as client money segregation, reconciliation and settlement, private keys and custody, change management, and third-party dependencies
Third-Party & Concentration Risk
Conduct vendor risk assessments and risk tiering, identify concentration risks, and conduct ongoing monitoring and annual reassessments of critical third parties
Business Continuity & Resilience
Map critical business services, establish Recovery Time Objectives (RTOs), maintain BCP documentation, and organise, observe and report on semi-annual business continuity exercises
Risk Reporting
Produce monthly reports on Risk Register changes, accepted risks, incident trends, and overdue remediation items, and quarterly reports on Group-level risk landscape to the CEO and Board
Requirements
5+ years of risk management experience, including at least 2 years in an independent risk or internal audit role within a regulated financial institution
Experience building a risk framework from scratch
Familiarity with RCSA, KRI design and incident management methodologies
Experience in at least one of the following: CFD / brokerage risk management, Exchange or VASP risk, or Operational risk within a payment institution
Ability to independently conduct investigative work
Strong working proficiency in Chinese and English, with Chinese required for effective communication and collaboration with internal stakeholders