Head of Risk Management

Ha Noi · On-site

About this role

ACG3715JOB
Our client, a leading company in financial services sector in Vietnam, is looking for a qualified candidate to join their firm.

KEY RESPONSIBILTIES
  • Lead the establishment, implementation, and continuous enhancement of the Company's Enterprise Risk Management Framework (ERMF) as well as risk management framework for material risks to seek approval from the Company's Board, ensuring alignment with the business model, regulatory requirements and VPB Group risk management principles and standards;
  • Lead the development, review and ongoing monitoring of the Company's Risk Appetite Statement, risk limits, early warning systems for material risks, ensuring risk exposure is measured as well as control measures and remediation plans are developed, monitored, and reported in a timely manner;
  • Lead the development and implementation of the Company's risk governance model, including the Three Lines of Defense, risk committee/council governance, escalation mechanism and risk reporting structure; and interaction with VPB Group Risk;
  • Oversee the identification, assessment, monitoring and reporting of material risks arising from the Company's current and planned business activities, including crypto-asset trading market services, proprietary trading, custody and asset protection, and asset tokenization/issuance-related services;
  • Lead the risk oversight of IT and Cybersecurity risk, including technology architecture risk, system availability/resilience, cyber threat and vulnerability management, penetration testing and red-teaming oversight, security incident response, third-party/vendor technology risk, and alignment with international standards (e.g. ISO 27001, NIST) and applicable regulatory requirements for crypto-asset trading infrastructure;
  • Lead the risk oversight of Custody and Digital Asset Protection, including wallet architecture risk (hot/warm/cold storage), private key management and multi-signature/MPC controls, custody operational controls, asset segregation, proof-of-reserves practices, and third-party custody/sub-custody arrangements;
  • Regularly evaluate the effectiveness of risk management policy, regulations/processes and risk appetite/limits; and propose to BOD for review and modification as necessary;
  • Report to BOD on the status of risk management activities and propose risk mitigation measures/solutions based on co-operation with relevant stakeholders, including review of risk reports prepared by risk functions prior to submission to senior leadership;
  • Provide independent oversight and challenge over risk assessments relating to new products/services/platforms, material technology changes and strategic initiatives, with particular focus on cybersecurity, IT resilience and custody control readiness prior to go-live;
  • Lead the implementation of core risk management tools and programs, including but not limited to RCSA, risk incident & loss data collection & analysis, issue/action tracking, scenario analysis, stress testing, business continuity risk oversight and control readiness assessment for trading, IT/cyber and custody functions;
  • Build and promote a sound risk culture across the organization and lead the Risk Management function, including defining risk governance structure, roles and responsibilities, capability requirements and coordination mechanisms with relevant internal and Group stakeholders. Direct the risk functions to closely co-ordinate with compliance, IT security and custody operations to ensure effectiveness and efficiency of established risk management frameworks;
  • Decide and approve matters related to risk management within the authority of Head of Risk Management, authorized by the Board. For material risk management issues, seek the opinion of the CAEX Board as well as VPB CRO (where applicable) prior to exercising the delegated authority, in accordance with the Group Governance Framework and the applicable delegation of authority.

Requirements

  • Bachelor's degree or above in Finance, Economics, Risk Management, Information Technology, Computer Science, Data Science, Fintech or a related field;
  • Minimum 10 years of relevant experience in risk management, enterprise risk management, risk governance across financial services, fintech, securities, trading platform, payment, digital banking, crypto/digital asset business or consulting; including experience in a risk leadership role, leading a diverse team of risk professionals across risk disciplines;
  • Strong understanding of enterprise risk management principles, risk governance, Risk Appetite Statement, limit framework, risk taxonomy, Three Lines of Defense, risk reporting, escalation, stress testing, and leading risk management tools;
  • Strong understanding of IT and Cybersecurity risk management, including security architecture, threat and vulnerability management, security incident response and cyber resilience frameworks;
  • Solid understanding of custody and digital asset protection risk, including wallet infrastructure, key management practices (multi-signature/MPC), and asset segregation controls;
  • Solid understanding of other key risk areas relevant to crypto-asset exchange operations, including market risk, liquidity risk, third-party risk, compliance risk, AML risk and reputational risk;
  • Strategic thinking and strong business acumen with a risk control mindset, with the ability to balance business growth, regulatory expectations, customer protection and prudent risk management;
  • Strong stakeholder management, communication and presentation skills, with the ability to engage effectively with the Board, Executive Management, regulators, business units, technology teams and external partners;
  • Proficient in English, with the ability to communicate and work effectively with domestic and international stakeholders.
Prefered Qualifications
  • Experience working with or advising digital asset exchanges, trading platforms, fintech companies, securities firms, payment companies, custody infrastructure providers, wallet/key management providers, blockchain companies or other regulated financial institutions;
  • Experience establishing or scaling a risk management function, ERMF, Risk Appetite Statement, risk committee governance, risk reporting framework, or IT/cybersecurity/custody control readiness program from an early-stage setup;
  • Experience in a 24/7 trading, digital asset, financial market infrastructure, brokerage, payment or technology-driven operating environment;
  • Professional certifications such as FRM, CFA, PRM, CIA, CISA, CRISC, CISSP, ISO 27001, ISO 22301, or other relevant risk, audit, cybersecurity, technology or financial market certifications.
Contact: Thao Phan or Giang Van or Huy Le
Due to the immense number of applicants, only shortlisted candidates will be contacted.

Company at a glance

Our vision is "To be the leading consulting firm in South East Asia, focused on leveraging human elements and technology to lead our partners towards higher growth and performance together with joy"

Founded2021
Team Size11-50 employees
WorkspaceOn-site
IndustryStaffing and Recruiting
Location
Hà Nội, Vietnam

Tired of cold applications?

Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.

Know someone who'd be great for this?