Operational & Technology Risk Lead
Job description
About the role
Reporting to the Head of Risk Management, the Lead of Operational & Technology Risk owns the enterprise operational and resiliency risk program across a regulated, globally distributed brokerage platform. This is a builder's role where you will design the operational risk framework, including the enterprise risk taxonomy and appetite structure, stand up risk assessment and control assurance programs, own issue and risk event management, and build AI-native tooling that makes risk management faster, sharper, and practical for the people who actually own it. Success requires someone who thrives with autonomy, builds risk practices that hold up under scale and regulatory scrutiny while still letting the business move quickly, and can translate operational risk into decisions the business, executives, and the Board will act on. You will partner closely with Engineering, Product, Operations, Treasury, Security, Legal, and Compliance, which separately owns programs that integrate with the firm-wide operational risk framework.
Key facts
What you'll do
DriveWealth is seeking an Operational & Technology Risk Lead to build and own the operational risk framework for a regulated, globally distributed brokerage platform. You will establish the enterprise risk taxonomy, risk appetite statements, and supporting policy architecture that defines how risk is measured and managed across the business. Lead and facilitate the operational risk and resiliency forum, driving genuine challenge and alignment rather than status review to ensure risk considerations are embedded in strategic decisions. Produce clear, decision-oriented reporting to the Global Risk Committee and the Board that provides a distinct point of view and prompts timely executive action. Establish decision frameworks, escalation thresholds, and exception governance that hold up under regulatory and partner scrutiny while enabling controlled innovation. Own risk assessment for new products, partners, markets, and platform capabilities, including emerging asset classes, tokenized securities, and international market entry to identify and mitigate issues before launch. Build a structured change risk process that accelerates safe product launches rather than creating unnecessary friction for go-to-market teams. Establish and run the RCSA program across a global, partner-dependent operating model, ensuring coverage is appropriate and results drive improvement. Serve as a trusted risk advisor to Operations, Product, Security, and Engineering leaders throughout the product development lifecycle, embedding risk thinking into design and delivery. Own the enterprise methodology that every risk program conforms to, including taxonomy, rating scale, assessment approach, defense in depth control framework, and KRI design conventions to ensure consistency. Build and manage the operational control testing program covering ICOC and key operational controls, including methodology, sampling, deficiency classification, and remediation tracking to closure with owners. Aggregate output from programs executed by other assurance functions to provide a unified view of operational risk posture and emerging themes to leadership. Implement AI-native tooling that makes risk management faster, sharper, and practical for business owners, improving insight and decision speed. Define and monitor key risk indicators (KRIs) that provide early warning of emerging risk, enabling proactive management and control refinement. Partner with Compliance, Legal, Security, and Technology teams to ensure the operational risk framework integrates effectively with enterprise risk management and regulatory requirements.
Requirements
Candidates for this role must meet the following eligibility and hard bars as defined by the source requirements. You must possess a bachelor's degree or equivalent practical experience, with a strong preference for advanced degrees in relevant fields such as finance, risk management, or engineering. Demonstrate a minimum of eight years of relevant professional experience in operational risk, technology risk, or a related field within highly regulated environments, with proven ability to operate in fast-paced, ambiguous situations. Show a track record of building and scaling risk management programs that can withstand regulatory examination while supporting business velocity. Bring experience designing enterprise risk taxonomies, risk appetite frameworks, and governance models that drive decision-making at executive and board levels. Have direct experience managing issue and risk event management processes, including root cause analysis, remediation planning, and tracking to closure. Demonstrate expertise in control frameworks, testing methodologies, and assurance integration across distributed teams and third-party partners. Possess strong written and verbal communication skills, with the ability to translate complex operational risk concepts into clear, actionable guidance for business and executive audiences. Show comfort working with emerging technologies, including API platforms, cloud infrastructure, and automation tools, with an understanding of how these technologies introduce new risk vectors and mitigation approaches.
Nice to have
Preferred qualifications that would strengthen your candidacy include prior experience in financial services or regulated industries where operational and technology risk programs are subject to regulatory oversight. Experience working with global partners and distributed teams across multiple jurisdictions, including familiarity with international market entry and cross-border regulatory expectations. Background in fintech, trading platforms, or brokerage operations, providing practical understanding of how risk programs support rapid innovation while maintaining controls. Familiarity with AI-native tooling, data analytics, and risk modeling techniques that can enhance the efficiency and insight of operational risk management. Experience with frameworks such as COSO, ISO 31000, or similar risk management standards, and knowledge of regulatory expectations around operational resilience and technology risk.
Practical notes
This role requires availability during standard business hours as determined by the needs of the global business, with occasional after-hours support for incident response or critical launches depending on market conditions. Travel may be required between office locations and to partner sites or regulatory engagements as necessary. Employment is contingent on successful completion of background checks and verification of professional credentials. The position is open until filled, and early applications are encouraged to ensure full consideration.