- Experience
- 8–10 yrs
- Salary
- —
- Openings
- 1
- Posted
- 4 days ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Role
As the Senior Manager of Technology Risk, you will spearhead the creation and supervision of the Technology Risk Management Framework for the company's worldwide digital asset trading and payments operations. This position functions as an independent second-line risk authority, offering comprehensive oversight and challenge to teams in Technology, Engineering, Product, Cybersecurity, and Operations to ensure technology risks are identified, evaluated, monitored, and mitigated effectively. The role encompasses governance over technology, cyber risks, operational resilience, infrastructure, change controls, third-party technology risks, and critical operational risks linked to technology and business processes.
Key Duties
- Direct the advancement and continual refinement of the Technology Risk Management Framework across global business units.
- Formulate policies, set standards, define risk appetite, and establish key risk indicators (KRIs) and control measures related to technology risks.
- Independently challenge Engineering, Product, IT, and Cybersecurity divisions on technology risk issues and controls.
- Evaluate risks stemming from new products, systems, platforms, infrastructure, and strategic projects.
- Oversee risks around system architecture, cloud infrastructure, application security, software development processes, change management, and day-to-day technology operations.
- Conduct thorough risk assessments for critical systems including APIs, wallet structures, exchange platforms, and related technology environments.
- Scrutinize management of vulnerabilities, access controls, cybersecurity threats, and control deficiencies.
- Ensure compliance with established Technology Risk Management practices, cybersecurity mandates, and regulatory standards.
- Provide second-line supervision for technology resilience efforts including Business Continuity Planning (BCP) and Disaster Recovery (DR) processes.
- Evaluate and challenge resilience testing, recovery preparedness, and cyber resilience exercises concerning vital systems.
- Monitor risks related to third-party technology and infrastructure service providers under a Third-Party Risk Management framework.
- Oversee operational risks emerging from technological breakdowns, system incidents, and essential business workflows.
- Lead Risk and Control Self-Assessment (RCSA) programs for critical technology and operational functions.
- Establish and track KRIs and other risk metrics for significant technology and operational exposures.
- Manage second-line reviews of technology, cyber, and operational incidents including Root Cause Analysis (RCA) and remediation tracking.
- Identify repetitive weaknesses in controls and drive enhancements in the risk and control framework.
- Serve as the main risk liaison with regulators during audits, licensing checks, and supervisory reviews relating to technology and operational risks.
- Interpret regulatory directives into actionable expectations for technology risk management.
- Prepare and present technology risk reports for senior executives and risk committees.
- Collaborate closely with Technology, Engineering, Cybersecurity, Product, and Operations leadership to bolster the overall risk posture.
Professional Experience and Expertise
- A minimum of 8 to 10 years in Technology Risk, IT Risk, Cyber Risk, or Operational Risk roles, especially within financial services, fintech, or regulated sectors.
- Proven competency in second-line technology risk governance, control frameworks, IT risk assessments, resilience strategies, and change management.
- Strong comprehension of cybersecurity principles, cloud infrastructure, application security, access management, vulnerability mitigation, and technology architectures.
- Expertise in risk methodologies including Risk and Control Self-Assessment (RCSA), Key Risk Indicator (KRI) monitoring, incident management, scenario testing, risk evaluations, and Root Cause Analysis.
- Experience collaborating with financial regulators and managing technology risk and operational resilience in a regulated environment.
- Ability to influence and challenge senior stakeholders across Technology, Engineering, Cybersecurity, Product, and Operations teams.
- Familiarity with digital asset technologies such as blockchain infrastructure, custody systems, smart contract risks, digital asset exchanges, or payment platforms is advantageous.
About OSL
OSL is recognized as the first digital asset platform licensed by the SFC in Hong Kong and a pioneer in PayFi innovation. Utilizing stablecoin payments, cross-border settlement, and global licenses, OSL is constructing the future payments network. Stablecoins serve as ubiquitous currency in emerging markets, regarded as blockchain's leading application, with a strategic shift toward enterprise and consumer adoption, particularly in cross-border B2B payments.
OSL holds licenses across Hong Kong, Japan, Australia, Bermuda, and Indonesia and is expanding into Europe, Brazil, Southeast Asia, and Africa through acquisitions and licensing. Through its offerings such as OSL Pay and StableX, OSL integrates stablecoin settlement into banking and card networks, supports over 150 digital assets, and provides continuous fiat-stablecoin conversion. As a regulated pioneer with a startup mindset, OSL invites passionate builders in crypto and payments to contribute toward a compliant and global payment infrastructure.