Independent Group Risk Manager

Key responsibilities

Risk Governance Framework & Risk Appetite

  • Establish and maintain the Group Risk Register covering all business lines and entities, and establish a Group-wide Risk Taxonomy aligned with Compliance

  • Establish risk-rating standards and provide independent risk assessments for individual projects based on five dimensions: data sensitivity, exposure surface, impact radius, scale of change, and third-party dependency

  • Translate the CEO's defined risk appetite into a structured framework with clear and measurable requirements

Incident Management & Independent Review

  • Take ownership of the triage owner role within the Group Incident Reporting mechanism and conduct independent reviews of L2 / L3 incidents to validate root cause and assess preventive measures

  • Monitor implementation and effectiveness of preventive measures across four levels (L0 elimination, L1 clarification, L2 redesign, L3 automation) and provide quarterly trend reporting

RCSA & Key Risk Indicators (KRI)

  • Design and maintain RCSA templates and control checklists, and design KRIs covering areas such as client money segregation, reconciliation and settlement, private keys and custody, change management, and third-party dependencies

Third-Party & Concentration Risk

  • Conduct vendor risk assessments and risk tiering, identify concentration risks, and conduct ongoing monitoring and annual reassessments of critical third parties

Business Continuity & Resilience

  • Map critical business services, establish Recovery Time Objectives (RTOs), maintain BCP documentation, and organise, observe and report on semi-annual business continuity exercises

Risk Reporting

  • Produce monthly reports on Risk Register changes, accepted risks, incident trends, and overdue remediation items, and quarterly reports on Group-level risk landscape to the CEO and Board

Requirements

  • 5+ years of risk management experience, including at least 2 years in an independent risk or internal audit role within a regulated financial institution

  • Experience building a risk framework from scratch

  • Familiarity with RCSA, KRI design and incident management methodologies

  • Experience in at least one of the following: CFD / brokerage risk management, Exchange or VASP risk, or Operational risk within a payment institution

  • Ability to independently conduct investigative work

  • Strong working proficiency in Chinese and English, with Chinese required for effective communication and collaboration with internal stakeholders

See also

Management jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available