SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
BIT (formerly Matrixport) is a global digital asset financial services and infrastructure group headquartered in Singapore, managing over US$7 billion in assets and facilitating more than US$7 billion in monthly trading volume. The company offers custody, trading, asset and wealth management, liquidity and financing solutions, and tokenised real-world assets (RWA) to institutional and professional investors globally, with regulated operations across Singapore, Hong Kong, Switzerland, the United Kingdom, the United States, and Bhutan.
You will lead operational risk management for BIT Group's Major Payment Institution (MPI), Fly Wing Technologies Pte Ltd, reporting to the CEO of the MPI with dotted reporting to the Group Chief Compliance Officer. This is a strategic leadership role owning the enterprise-wide risk framework, governance infrastructure, and control environment.
Key responsibilities include:
• Developing and maintaining the Enterprise-Wide Risk Assessment (EWRA) framework across all business lines, entities, and jurisdictions, with focus on operational and technology risks.
• Establishing and embedding a robust risk appetite framework defining risk tolerances across key categories.
• Developing risk policies covering operational risk, business continuity management, third-party risk management, model risk, AI risk, and technology risk.
• Leading risk identification, assessment, and monitoring across all business functions, including technology, cybersecurity, people and conduct, process failures, third-party, AI, and business continuity risks.
• Establishing and maintaining a comprehensive risk register with clear accountability and mitigation tracking.
• Designing and implementing key risk indicators (KRIs) and risk dashboards providing real-time visibility to CEO, Board, and senior leadership.
• Overseeing operational loss event data collection, root cause analysis, and lessons-learned processes.
• Conducting periodic risk and control self-assessments (RCSA) across key business processes.
• Ensuring systematic identification, assessment, and management of technology, cyber, and AI/model risks across the organization.
• Owning the Business Continuity Management and Disaster Recovery framework, including business impact assessments and recovery time objectives.
• Leading crisis management and incident response frameworks for operational risk events, system outages, cyber incidents, and market disruptions.
• Establishing and governing the third-party risk management framework covering due diligence, ongoing monitoring, and exit planning.
• Serving as primary risk management representative in regulatory examinations and supervisory dialogues.
• Preparing and presenting risk management reports to the Board and Senior Management.
REQUIREMENTS:
• Bachelor's degree in Finance, Economics, Mathematics, Engineering, or related discipline (Master's degree or MBA advantageous).
• Minimum 10 years of progressive experience in risk management within financial services, fintech, or digital asset environments.
• Proven track record of developing or significantly enhancing risk management frameworks and policies.
• Experience operating in a regulated financial institution under MAS (Monetary Authority of Singapore) or equivalent, with direct involvement in regulatory examinations and supervisory engagement.
• Background in digital assets, cryptocurrency business, or financial technology strongly preferred; candidates from traditional banking with genuine interest in digital assets will be considered.
• Strong knowledge of technology and cyber risk, including cloud risk, API dependency risk, and exchange infrastructure risk in digital asset context.
• Familiarity with model risk management principles including validation, governance, and ongoing monitoring of quantitative models.
• Strategic thinker with strong execution capability, able to set risk framework direction and drive implementation across complex, multi-entity organizations.
• Analytically strong with ability to design and interpret risk metrics, dashboards, and quantitative risk assessments.
• Collaborative and influential, able to drive risk culture change without direct authority over all business functions.