Head of Risk
- Опыт
- C-Level
- Размер компании
- Средняя
В объявлении не сказано, откуда нанимают. Возможно, вакансия открыта по всему миру (уверенность 82 %). Это оценка, а не правило допуска — проверьте перед откликом.Сигналы: модель работы компании и офисы компании.
Коротко по делу
Senior Head of Risk for a fintech/crypto payments company. Requires 7+ years in financial services/fintech risk with 3+ years in senior risk leadership and direct experience in a licensed fintech/EMI/PSP/crypto environment.
Ключевые навыки
Обязательные навыки
Желательные навыки
Желательные языки
- Contract
- Risk
Paybis is a global fintech company operating at the intersection of crypto and traditional payments. Since 2014, we've been building products that help people and businesses buy, sell, and exchange cryptocurrency. We serve 8.6M+ customers across 180+ countries and operate as a self-funded company with ~200 people across Europe, Ukraine, and the US.
We hold a MiCA CASP authorisation and a Payment Institution (PSD2) licence in Latvia — one of a small group of companies in Europe holding both simultaneously — alongside FinCEN MSB and FINTRAC registrations, and a VASP registration in Poland.
We're building out our senior leadership team and are looking for a Head of Risk to own the enterprise risk function — and serve as a proactive, decision-oriented risk partner to the CEO and the business.
As Head of Risk at Paybis, you will own the risk function end-to-end: enterprise risk framework, DORA ICT risk and operational resilience, B2B partner risk, fraud risk appetite, capital adequacy under MiCA and PSD2, and product-launch risk gating.
You will report directly to the CEO and work daily with Compliance, Legal, Finance, Technology, and the B2B Partnerships team — bringing risk ownership and proactive escalation to a function that currently lacks a permanent, forward-looking owner.
This is a permanent hire into a function that has foundational elements in place — risk register, risk appetite framework, and DORA workstreams already initiated. What the function needs is a permanent owner who surfaces risk proactively, drives two parallel EMI risk frameworks to completion, and serves as a credible, commercially-oriented risk partner to the CEO and the business.
This is not a framework-writing role with someone else making the decisions. You will own the risk view, set risk appetite, and be accountable for the outcomes — in a self-funded company where every risk call lands directly on the business.
If you are energised by operating at the intersection of regulatory complexity and commercial pace — and you want to build and own a risk function that matters — this role is for you.
Enterprise Risk & Governance
• Own and maintain the enterprise risk framework: risk register, risk appetite statement, risk taxonomy, and escalation policy
• Drive the risk reporting cycle — structured risk updates to the CEO and senior leadership; regulatory risk reporting to Latvijas Banka, FCA, and FinCEN as applicable
• Chair or co-chair the risk committee: agenda, cadence, participants, and decision authority
• Build risk ownership culture across business units — risk is not only the risk function's responsibility
DORA & Operational Resilience
• Own the DORA ICT risk management framework and lead the Register of Information workstream to meet the January 2027 hard regulatory deadline
• Own business continuity and disaster recovery planning — documented recovery objectives and tested plans for critical services
• Own third-party and vendor risk management: risk assessment of critical service providers, concentration risk, and exit planning
• Own the PSD2 operational resilience framework: 4-hour major incident reporting to Latvijas Banka, important business services definition, and impact tolerances
• Partner with the CTO and Head of Security on technology and cloud risk
EMI & Regulatory Risk
• Lead the operational risk framework and capital adequacy/safeguarding design for two parallel EMI applications (Latvia hub + UK EMI)
• Own ongoing capital adequacy monitoring under MiCA and PSD2 PI — maintain required buffers and escalate breaches
• Own risk-focused regulatory examination preparation and serve as the primary internal contact for risk-related regulator queries
• Coordinate with the VP of Legal on regulatory legal obligations and with the Global Chief of Compliance on AML/CTF risk appetite and financial crime risk thresholds
B2B Partner & Counterparty Risk
• Design and own the B2B partner risk assessment framework — onboarding risk scoring, ongoing due diligence, risk-tiered monitoring
• Own risk sign-off on material B2B partnerships — define thresholds beyond which CEO approval is required, and ensure high-risk review is fast and credible — a commercial enabler, not a friction point
• Define the risk-based conditions for which partner industries, geographies, and business models Paybis will and will not serve
• Manage partner concentration risk and delegated-compliance liability as B2B volume scales
Fraud & Financial Crime Risk
• Establish a unified fraud risk framework and appetite across the relevant business functions — creating clear ownership, consistent thresholds, and a single escalation path
• Set fraud risk appetite by channel, product, and geography — and own the decision when escalations breach threshold
• Coordinate with the Global Chief of Compliance on the fraud-AML/CTF intersection: typologies, SAR referrals, and financial crime risk appetite
• Own the sanctions screening risk framework and escalation policy for high-risk jurisdictions and counterparties
Product & Financial Risk
• Own product-launch risk gating for new products and markets — new products, geographies, and business lines as they enter the pipeline
• Manage crypto price volatility exposure on open positions: conversion timing, settlement risk, and liquidity buffers
• Own counterparty credit risk: liquidity providers, banking partners, card scheme exposure, and B2B client credit risk
• Oversee treasury risk: fiat and crypto balance management, currency exposure, and concentration risk
Must have:
• 7+ years in financial services or fintech risk management, with at least 3 years at senior risk leadership level (Head of Risk, VP Risk, or equivalent scope) in a regulated institution
• Direct experience owning risk obligations in a licensed fintech, EMI, PSP, payments institution, or crypto company — not advisory or consultancy exposure only
• Hands-on experience with at least one of: DORA ICT risk framework, MiCA capital adequacy and risk management requirements, PSD2 operational resilience, or FCA operational resilience framework
• Fraud risk ownership experience: has set fraud risk appetite, owned a fraud P&L outcome, and made real fraud decisioning calls — not just governed a fraud team from a distance
• B2B partner or counterparty risk experience: has assessed and approved high-risk commercial relationships, not only consumer or retail risk
• Ability to make a risk decision and stand behind it under CEO or commercial pressure — framework writers who cannot take a position are the wrong profile for this role
• High autonomy operating mode: surfaces risk proactively, proposes a route, and closes actions without waiting for direction
• Ability to give B2B commercial teams a fast, credible risk answer — risk sign-off that enables deal velocity, not one that blocks it
• Fluent professional English — all risk reporting, regulatory communication, and leadership interaction is in English
• Ability to work within European business hours
Nice to have:
• Prior Head of Risk, VP Risk, or CRO title at a regulated fintech, EMI, PSP, or crypto company
• DORA Register of Information preparation experience — given the January 2027 hard deadline, this is a meaningful differentiator
• FCA operational resilience framework experience — maps directly to DORA and is highly relevant given UK pipeline
• MiCA post-authorisation obligations: capital adequacy reporting, CASP risk management framework requirements
• Experience building a risk function from scratch or taking an early-stage risk framework to operational maturity
• Third-party/vendor risk management at scale — relevant given Paybis's B2B infrastructure model and DORA VRM obligations
• Capital adequacy and safeguarding framework design for an EMI or PI application
• Travel rule risk implementation across multiple jurisdictions (FATF/EU TFR)
• FRM (GARP), PRM, or equivalent professional risk qualification
• Russian language — practical advantage in Paybis's multilingual team environment
• Report directly to the CEO — your risk view shapes company decisions, not just supports them
• Own the DORA Register of Information workstream with a hard January 2027 deadline — your work has real, visible regulatory consequences
• Lead both EMI risk frameworks (Latvia + UK) from day one — two of the most consequential regulatory workstreams the business is running
• One of Europe's most interesting regulatory portfolios: MiCA CASP + PSD2 PI already granted, with UK EMI, EMI Latvia, Jersey, and Australia in pipeline
• Build the unified fraud risk framework for a business combining B2C retail, B2B infrastructure, onramp, and custody — operationally rich and technically complex
• Self-funded, stable company — no investor pressure shaping risk decisions, no funding-round clock
• Remote-first with high autonomy and minimal micromanagement
• Medical insurance, L&D budget, performance-based financial bonus, English classes, regular team-building activities
• Fintech and crypto domain — regulatory complexity is the norm, not the exception
• HR interview
• Cross-functional interview with Global Chief of Compliance + CTO
• CEO interview
• Reference check
Paybis is an equal opportunity employer. We welcome risk professionals who take ownership seriously, make decisions under uncertainty, and want to build a risk function that a company at our regulatory and commercial stage actually needs.
Чем предстоит заниматься
- Own and maintain the enterprise risk framework: risk register, risk appetite, taxonomy and escalation policy; drive structured risk reporting to CEO and senior leadership.
- Own DORA ICT risk and operational resilience: lead Register of Information workstream, business continuity and disaster recovery planning, and PSD2 operational resilience obligations.
- Lead EMI & regulatory risk for two parallel EMI applications (Latvia + UK): design operational risk and capital adequacy/safeguarding frameworks and ongoing monitoring under MiCA/PSD2.
- Design and own B2B partner and counterparty risk framework: onboarding risk scoring, ongoing due diligence, risk-tiered monitoring and risk sign-off on material partnerships.
- Establish a unified fraud risk framework and appetite, sanctions screening policy, and own product-launch risk gating and financial/counterparty exposure management.
Что требуется
- 7+ years in financial services or fintech risk management, with at least 3 years at senior risk leadership level (Head/VP or equivalent).
- Direct experience owning risk obligations in a licensed fintech, EMI, PSP, payments institution, or crypto company (not advisory/consultancy).
- Hands-on experience with at least one of: DORA ICT risk framework, MiCA capital adequacy and risk management, PSD2 operational resilience, or FCA operational resilience.
- Proven fraud risk ownership: set fraud risk appetite, owned fraud P&L outcomes and made operational decisioning calls.
- Fluent professional English and ability to work within European business hours.
Преимущества
- Remote-first workplace
- Medical insurance
- L&D budget
- Performance-based financial bonus
- English classes and regular team-building activities
Paybis is a fintech/crypto company that helps individuals and enterprises buy, sell, exchange, and transfer cryptocurrency through regulated infrastructure in 180+ countries.