SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Cobre is Latin America's leading B2B instant payments platform, providing advanced financial infrastructure for enterprises to move money faster, securely, and efficiently. The company enables instant corporate payments—local or international, direct or via API—through a single platform serving fintechs, PSPs, banks, and financial teams.
We are seeking an Operational Risk Specialist to design and implement Cobre's corporate risk framework, ensuring identification, evaluation, and mitigation of operational risks aligned with corporate risk definitions. This role requires close collaboration with operations, technology, product, commercial, and customer-facing teams.
Key Responsibilities:
- Identify operational risks arising from process failures, people, technology platform issues, or external events (natural disasters, fraud, etc.)
- Evaluate probability and potential impact of operational risks through quantitative and qualitative analysis to prioritize critical risk management
- Design and implement policies and controls to mitigate operational risks while ensuring efficient and secure operations
- Continuously evaluate and monitor established controls for effectiveness and adherence; update and adjust controls as needed; maintain risk event and status records
- Assess technology risks including system failures, cybersecurity, service interruptions, technology fraud, and identity validation vulnerabilities, acting as a second line of defense
- Evaluate third-party and vendor risks, establishing appropriate controls to ensure compliance with Cobre's security and operational standards
- Establish real-time risk monitoring mechanisms and continuous monitoring processes to identify and rapidly respond to anomalies or risk events
- Actively identify opportunities to automate risk management—reporting, tracking, matrices—reducing manual work and hand-made processes
- Review digital processes to identify potential failures, inefficiencies, or risks from excessive automation; ensure critical decisions remain controlled
- Lead training programs educating Cobre employees on technology and operational risks, emphasizing management importance and prevention best practices
- Evaluate risks of introducing new technologies, products, or services, including API integrations and AI adoption in business decision-making
- Support planning and implementation of certifications and trust frameworks (ISO/IEC 27001) to strengthen information security maturity and governance
- Generate detailed reports on operational risks and controls with metrics and analysis to inform decision-making on process viability and security
- Provide immediate response availability for fraud or economic loss events, including outside regular hours
This is not a role executing a pre-defined framework. We seek someone who can build in ambiguity, solve undefined problems, and respond when events directly impact the area. The ideal candidate applies negotiation skills throughout the risk management cycle, using data analysis and timely risk event identification and reporting to enable the next stage of business growth.
Requirements:
- 5+ years as an operational risk specialist in highly regulated, mission-critical environments (processors, banks, payment gateways, stock exchanges)
- Degree in engineering, administration, economics, accounting, or related fields; postgraduate training in risk management, audit, or internal audit preferred
- Experience evaluating risks and designing controls for financial, transactional, and payment industries
- Proven experience implementing, evaluating, and monitoring internal control and operational risk systems—ideally building frameworks from scratch, not just executing pre-defined ones
- Real, hands-on experience implementing or maintaining ISO/IEC 27001 (theoretical knowledge alone is insufficient)
- Experience working with agile methodology teams in technology and operational processes, preferably in fintech
- Knowledge of risk management frameworks and standards: COSO, SARO, SOX, SAC, SARLAFT, and Colombian financial sector operational risk regulations
- Problem-solving mindset and "jack-of-all-trades" capability: ability to advance topics not formally documented and build trust with business and technology teams
- Desirable: experience in personal data protection and treatment