Responsibilities:
Product Risk Management ("PRM"):
- Support in product risk assessment, work closely with Risk Owner to conduct risk and control assessment on risk exposure across different Crypto products
- Perform validation of controls identified via product risk assessment, and ensure remedial actions implemented in time
- Perform risk assessment on new products/services
- Support the maintenance of the FSRA Outsourcing Register, ensuring all material outsourcing arrangements are accurately recorded, updated, and reported in line with regulatory expectations
- Assist in conducting vendor due diligence and ongoing third-party risk assessments, including assessment of concentration risk, BCP/DR readiness, and SLA adequacy
- Coordinate with the Outsourcing Workgroup to track remediation actions arising from vendor reviews and ensure timely closure
- Maintain oversight of critical third-party dependencies (e.g., NCCL custody chain) and support periodic review of sub-custodian arrangements, concentration thresholds, and contingency arrangements
Regulatory Engagement & Remediation ("REM"):
- Support the preparation and submission of regulatory reports to FSRA, including periodic risk-related disclosures, ad-hoc RFI responses, and remediation progress updates
- Assist in maintaining the FSRA RFI response log, tracking turnaround times, response quality, and outstanding items to ensure timely and accurate regulator interactions
- Coordinate remediation of regulatory findings and action items, including root cause analysis, corrective action planning, and evidence compilation for regulator follow-up
- Support the preparation for FSRA on-site inspections, including agenda preparation, evidence gathering, walkthrough materials, and pre-inspection readiness checks
- Assist in tracking and reporting on regulatory remediation progress to the Board Risk & Compliance Committee and ADGM Risk & Compliance Committee
- Maintain the regulatory engagement calendar and ensure upcoming deadlines, reporting obligations, and inspection milestones are communicated to relevant stakeholders
Requirements:
- Minimum of 7 years of experience in the financial services industry.
- Strong background in compliance, risk management, project management, controls, or audit.
- Proven project management and execution capabilities, with the ability to manage multiple concurrent, time-sensitive initiatives and deliver results in a dynamic, fast-paced environment.
- Prior experience in management consulting or project management is highly desirable.
- Bilingual English/Mandarin is required to be able to coordinate with overseas partners and stakeholders.
- Experience in operational risk management, internal/external audit, compliance, or IT security is an advantage.
- Positive attitude with excellent interpersonal, communication, and stakeholder management skills.
- Ability to work effectively under pressure and consistently meet tight deadlines.
- Relevant professional certifications such as CPA, CISA, CISM, CISSP, CRISC, or ISO/IEC 27001 Lead Auditor are a plus.