Risk Officer
As the Risk Officer, you will perform the analytical work that keeps a growing digital asset firm's risk framework operational and credible. You will work across risk domains and help the organization grow hands-on. This is not a head-of-risk role; you are the person who ensures the analytical work gets done. The role offers direct exposure to regulatory risk management, with real scope, real responsibility, and no bureaucratic distance from the work.
What you do
- Maintain the risk register: Keep entries current, track status, and flag emerging risks as they surface.
- Execute risk assessments: Run periodic and event-driven assessments across operational and ICT risk domains. Apply quantitative and qualitative methodologies and document findings clearly.
- Prepare Risk Committee materials: Pack the agenda, write the risk updates, and ensure the committee has what it needs to make decisions.
- Track treatment plans: Follow risk treatment plans from agreement through to completion. Chase owners, track progress, and escalate where plans are slipping.
- Support regulatory reporting: Support regulatory reporting cycles to regulators. Gather evidence, structure submissions, and flag where gaps need addressing.
- Develop risk scenarios: Play a leading role in developing risk scenarios, controls, and mitigations across risk frameworks to support operations, product development, and business strategy.
- Build risk awareness: Design and run risk awareness campaigns and training for staff so a risk-aware culture is sustained in practice.
- Contribute to DORA work: Contribute to the ongoing DORA implementation, particularly the ICT risk management requirements under Articles 5 to 15.
What they ask
- 2 to 4 years of experience in risk management, preferably at a regulated financial institution: a bank, payment institution, investment firm, or CASP.
- Working knowledge of risk assessment methodologies, both quantitative and qualitative, including likelihood and impact scoring and defining treatment plans.
- Familiarity with at least one of: DORA, MiCAR, Wft, Wwft, or comparable EU financial regulation.
- A clear understanding of the three lines of defence model and where a second-line risk analyst sits within it.
- Experience maintaining risk registers and producing risk reporting for management or boards.
- An analytical mindset: comfortable with data, identifying patterns, and turning findings into recommendations someone can act on.
- Strong written English. Dutch is a plus.
- Bachelor's degree in finance, economics, risk management, or a related field. FRM, PRM, or working toward one is a plus but not required.
- Comfortable in a fast-paced scale-up where processes are still being built, and the expectation is that you help build them.
Wishes.
- Experience with crypto-assets, custody, or DeFi risk.
- Familiarity with Vanta or similar GRC tooling.
- Experience with ICT risk assessments under DORA Articles 5 to 15.
How to apply
View the full assignment text and application details once your tailored application is ready.
Order a tailored application to view the full assignment and application details.
More context, less searching.
You get enough context to judge whether this job is relevant. The full brief, client details and next steps stay available inside the app.