Risk Operations
Job description
About the role
You will own the end to end execution of critical Risk programs across third party risk, information security, model risk, privacy, financial and operational risk. You will act as the operational backbone for the Risk function by designing and running the systems that keep our risk infrastructure reliable and compliant. You will translate ambiguous risk signals into clear processes and controls that protect the business while enabling responsible growth. You will partner deeply with Engineering, Compliance, Legal, and People to ensure risk initiatives are aligned with business objectives and technical constraints. You will be the person who ensures that complex risk activities are predictable, auditable, and scalable as we grow. You will bring a builder mindset to risk, focusing on tooling, automation, and continuous improvement rather than only oversight.
Key facts
What you'll do
- Plug into whichever Risk program needs the most support at a given moment - third-party risk management, information security, model risk, privacy, financial, operational, etc. - and figure out what's broken, slow, or missing.
- Learn each program from the ground up - understand what it's actually protecting against, how it works in practice, and where the gaps are. Then re-design it so it's faster and more consistent.
- Build the tooling that makes the next version of a process possible - scripts, internal dashboards, AI-assisted review workflows, system integrations.
- Support third-party diligence and monitoring, helping assess vendor/supplier risk and turning your findings into concrete remediation steps.
- Help design business continuity and disaster recovery (BC/DR) exercises that test how Column and its partners actually respond when things go wrong.
- Take our privacy program to the next level, and make sure privacy considerations are part of the way we diligence prospective customers from the start.
- Own the maintenance and improvement of our risk policies, standards, and control frameworks to ensure they reflect current best practices and regulatory expectations.
- Partner with Compliance and Legal to interpret new regulations and translate them into operational controls that can be implemented consistently across the business.
- Track and report on key risk metrics, documenting issues, resolutions, and trends in a way that is clear to both technical and non-technical stakeholders.
- Work closely with Engineering to integrate risk checks and workflows into existing systems, ensuring that controls are effective without blocking innovation.
- Define and run training sessions for cross functional teams so that risk processes are understood and followed by everyone who touches them.
- Maintain a clear view of our risk posture by consolidating data from different sources and surfacing insights that help leadership make informed decisions.
- Support audits and examinations by preparing documentation, walking through processes, and demonstrating how controls are designed and executed.
- Continuously look for ways to simplify and standardize risk activities, reducing manual effort and increasing reliability across the stack.
- Act as the day to day owner of risk operations, making decisions on priorities, trade offs, and escalations in partnership with Risk leadership.
- Contribute to the development of playbooks and runbooks that codify how risk programs operate on a recurring basis.
- Collaborate with People to improve how risk knowledge is shared across the organization, including hiring, onboarding, and internal mobility.
Requirements
- 2+ years of doing something hard. This could be in consulting, technical operations, software engineering, or any role where you had to make sense of a complex system, improve it, and get others to adopt the change. Prior risk experience is not required - we'll teach you the domain.
- You get up to speed fast. You're the person who can be handed an unfamiliar problem, spend a week understanding it, and come back with a point of view.
- You have an optimization instinct. When you see a manual process, your first question is "could this be automated?" and you have the skills to actually build the tooling necessary to make that happen. You've automated meaningful pieces of your own job before.
- Technical fluency is no problem for you. You're comfortable in the terminal, writing or modifying Python, Go, Apps Script code. Querying databases with SQL, working with APIs, and reasoning about systems is familiar territory. You can speak the same language as our engineering team and ask thoughtful questions to help yourself understand our environment.
- Written communication is a strong suit. You can take a vague alert, messy vendor review, or unclear audit finding and turn it into a well-articulated response memo, policy update, or control narrative that holds up under scrutiny from auditors and regulators.
- Your projects are hyper-organized. You're comfortable juggling multiple concurrent workstreams across stakeholders with varying priorities, surfacing tradeoffs early, getting people to commit to a shared goal, and knowing when something needs to be escalated vs. decided in the moment.
- You are comfortable working in a fast moving startup environment where priorities can shift quickly and you are able to manage ambiguity without needing a perfect plan before taking action.
- You respect confidentiality and are comfortable working with sensitive information, understanding that risk data often includes private details about our business, customers, and vendors.
Practical notes
Hours
Full-time
Travel
Not stated
Visa
Not stated
Deadlines
Not stated
Confidentiality
You will be exposed to sensitive internal risk data, vendor information, and audit findings, and you are expected to maintain strict confidentiality at all times.
Application instructions
Not stated