Search Jobs

Search by job, company or skills

Head of Operational Risk and Governance

Head of Operational Risk and Governance

bit official
10-12 Years
Early Applicant
  • Posted 19 hours ago
  • Be among the first 10 applicants

Job Description

About BIT:

BIT (formerly Matrixport) is a global digital asset financial services and infrastructure group. Headquartered in Singapore and founded in 2019, BIT bridges traditional finance and digital assets through governance-driven financial services and technology.

The firm manages over US$7 billion in assets and facilitates more than US$7 billion in monthly trading volume. BIT offers services including custody, trading, asset and wealth management, liquidity and financing solutions, and tokenised real-world assets (RWA), serving institutional and professional investors globally.

BIT Group entities maintain a licensed and regulated footprint across Singapore, Hong Kong, Switzerland, the United Kingdom, the United States and Bhutan.

For more information, visit www.bit.com

Why Join Us:

At BIT, we tackle complex problems as a team. We encourage openness and promote transparency, respect, and inclusivity. Every team member is valued and has a voice that can be heard. We are always in search of intellectually curious and entrepreneurial individuals who are keen on making an impact in the crypto ecosystem and in building a better product for the next one billion users.

About the role

BIT Group through its Major Payment Institution (MPI), Fly Wing Technologies Pte Ltd is seeking a Head of Operational Risk to own and lead operational risk management framework — building and institutionalising a best-in-class risk culture, governance infrastructure, and control environment that can withstand regulatory scrutiny, support business growth, and underpin BIT's ambitions in both digital assets finance and traditional finance. The candidate will also look after Business Continuity and Disaster Recovery efforts and outsourcing requirements under MAS Outsourcing Guidelines. The role will report to CEO of the MPI with dotted reporting to the Group Chief Compliance Officer.

Key Responsibilities

1. Risk Framework & Governance

  • Own and continuously develop Enterprise-Wide Risk Assessment (EWRA) framework — ensuring it reflects the full spectrum of risks, primarily operational and technology risks, across all business lines, entities, and jurisdictions.
  • Establish and maintain a robust risk appetite framework — defining risk tolerances across key risk categories and ensuring they are embedded into business decision-making.
  • Develop and maintain the risk framework and policies — including operational risk policy, business continuity management, third-party risk management, model risk, artificial intelligence risk and technology risk policies.
  • Report on risk matters at Management Meetings — presenting risk reports, escalating material risks, and driving risk governance decisions at the highest level.

2. Risk Identification, Assessment & Monitoring

  • Lead the identification and assessment of risks across all business functions — including technology and cybersecurity, people and conduct, process and control failures, third-party, artificial intelligence risk, operational risk, and business continuity risk.
  • Establish and maintain risk register — ensuring all material risks are identified, assessed, owned, and mitigated with clear accountability.
  • Design and implement key risk indicators (KRIs) and risk dashboards — providing real-time visibility of the risk profile to the CEO, Board, and senior leadership.
  • Oversee operational loss event data collection (including near misses), root cause analysis, and lessons-learned processes — ensuring incidents drive systemic improvements rather than one-off fixes.
  • Conduct periodic risk and control self-assessments (RCSA) across all key business processes — identifying control gaps and driving remediation.

3. Technology, Cyber, Artificial Intelligence & Model Risk

  • Work with the leadership to ensure the technology risk and cybersecurity risk are systematically identified, assessed, and managed — including exchange infrastructure, custody systems, API and data dependencies, and cloud architecture.
  • Oversee artificial intelligence and model risk management — ensuring all quantitative models used in risk management, pricing, and trading are subject to appropriate validation, governance, and ongoing monitoring.
  • Assess and manage risks arising from AI and automation tools deployed across the Group — including model bias, explainability, and data integrity risks.

4. Business Continuity & Incident Management

  • Own and maintain the Business Continuity Management and Disaster Recovery framework — including business impact assessments, recovery time objectives, and continuity plans for all critical functions.
  • Lead the crisis management and incident response framework — ensuring rapid, coordinated responses to operational risk events including system outages, cyber incidents, and market disruptions.
  • Manage post-incident reviews and ensure learnings are embedded into risk controls and business processes.

5. Third-Party & Vendor Risk Management

  • Establish and govern the third-party risk management framework — covering due diligence, ongoing monitoring, and exit planning for critical vendors and counterparties.
  • Assess operational risks arising from key third-party dependencies — including banking API providers, custody sub-contractors, technology vendors, and data providers.

6. Regulatory Engagement & Board Reporting

  • Serve as the primary risk management representative in regulatory examinations, supervisory dialogues, and audit processes — providing a clear, credible, and comprehensive account of the risk framework.
  • Prepare and present risk management reports to the Board of Directors and Senior Management— translating complex risk data into clear, actionable governance insights.
  • Ensure risk management framework meets or exceeds the expectations of all relevant regulators.

Job Requirements

  • Bachelor's degree in Finance, Economics, Mathematics, Engineering, or a related discipline. Master's degree or MBA is advantageous.
  • Minimum 10 years of progressive experience in risk management within financial services, fintech, or digital asset environments.
  • Proven track record of developing or significantly enhancing risk management framework and policies
  • Experience operating in a regulated financial institution under MAS, or equivalent — with direct involvement in regulatory examinations and supervisory engagement.
  • Background in digital assets, cryptocurrency business, or financial technology is strongly preferred — candidates from traditional banking with a genuine interest in digital assets will also be considered.
  • Strong knowledge of technology and cyber risk — including cloud risk, API dependency risk, and exchange infrastructure risk in a digital asset context.
  • Familiarity with model risk management principles — validation, governance, and ongoing monitoring of quantitative models.
  • Strategic thinker with strong execution capability — able to set the risk framework direction and drive implementation across a complex, multi-entity organisation.
  • Analytically strong — able to design and interpret risk metrics, dashboards, and quantitative risk assessments.
  • Collaborative and influential — able to drive risk culture change without direct authority over all business functions.

By submitting a job application, you confirm that you have read and agree to our Candidate Privacy Policy. <https://www.bit.com/privacy-candidate>

More Info

Job Type:
Industry:
Employment Type:

Key Skills

Artificial Intelligence Risk

Regulatory Engagement

Model Risk Management

Cybersecurity Risk

Third-Party Risk Management

Quantitative Risk Assessment

About Company