Senior Compliance & Risk Manager

Atome

Wien

Hybrid

EUR 90.000 - 130.000

Vollzeit

14 Tage+
Bewerbungsgenerator

Hebe dich für diese Rolle von der Masse ab — erstelle in etwa einer Minute einen maßgeschneiderten Lebenslauf und ein Anschreiben.

Schaffe es an den ATS-Filtern vorbei

Benefits dieser Stelle

Vienna office location at Trabrennbahn
Team events
Snacks and Friday breakfasts
International team
Career development opportunities
Competitive salary and bonuses
Comprehensive benefits package

Zusammenfassung

KuCoin EU seeks a Senior Compliance & Risk Manager to strengthen TPRM, ICT risk governance, and BCM. You will ensure regulatory alignment with MiCAR, DORA, GDPR, and Austrian expectations, while coordinating with Head of Risk, CISO, and Management Board.

The role emphasizes cross-functional collaboration and timely reporting. The candidate brings 4+ years in compliance/risk and strong knowledge of EU GDPR, with fluency in English.

Qualifikationen

  • 4+ years of experience in compliance, risk management, audit, or internal control (financial services/fintech/crypto experience is a strong plus).
  • Practical expertise in Third-Party Risk Management, ICT risk governance, or EU GDPR-related compliance work.
  • Ability to interpret system diagrams, vulnerability reports, penetration tests, and security certifications.
  • Fluent in English; German proficiency is a strong plus.

Aufgaben

  • Lead and further develop the Third-Party Risk Management (TPRM) framework.
  • Maintain and enhance the ICT risk management framework and ICT risk register.
  • Coordinate BCM/DR planning and testing and prepare clear risk reports for senior management.
  • Collaborate with auditors/regulators and align with European/Austrian regulatory requirements.

Kenntnisse

TPRM
ICT risk governance
EU GDPR compliance
English proficiency

Ausbildung

University degree in Law/ Economics/ Finance/ Business/ IT Risk

Jobbeschreibung

As Senior Compliance & Risk Manager (f/m/d), you will lead KuCoin EU’s key operational resilience pillars, including Third-Party Risk Management (TPRM), ICT risk management, and Business Continuity Management (BCM). You will ensure that our governance, processes, and controls comply with MiCAR, DORA, EU GDPR, and Austrian regulatory expectations while supporting strong cross-functional collaboration. In this role, you will manage due diligence and oversight of external service providers, maintain the ICT risk framework and central risk register, coordinate BCM and Disaster Recovery activities, support incident and vendor monitoring, and prepare clear reporting for the Head of Risk, CISO, Management Board, and relevant committees.

  • Work at the heart of it.Our modern Vienna office is located directly at the historic Trabrennbahn in the Prater - a vibrant and accessible location.
  • Team culture matters.We believe in strong collaboration and organize regular team events to foster a positive and connected work environment.
  • We take care of the details.A daily selection of snacks, beverages, and weekly Friday breakfasts help keep our team energized.
  • An international mindset.Join a diverse, forward-thinking team that thrives on innovation and cross-border collaboration.
  • Invest in your development.We offer clear career progression, supported by learning and development opportunities tailored to your professional growth.
  • Rewarding performance.Benefit from a competitive salary, performance-based bonuses, and a comprehensive benefits package on top.
  • Shape the industry.Make a direct contribution to one of Europe’s most ambitious crypto platforms as we scale our regulatory capabilities.

What makes You special

  • You hold a university degree in Law, Economics, Finance, Business, IT Risk, or a related field
  • You have 4+ years of experience in compliance, risk management, audit, or internal control (financial services/fintech/crypto experience is a strong plus)
  • You bring practical expertise in TPRM, ICT risk governance, or EU GDPR-related compliance work
  • You can interpret system diagrams, vulnerability reports, penetration tests, and security certifications
  • You understand European and Austrian regulatory frameworks, including DORA, MiCAR, NIS2, and relevant ISO standards
  • You can translate regulatory requirements into clear, actionable, and scalable processes
  • You communicate well and collaborate effectively with cross-functional teams and external partners
  • You are proactive, detail-oriented, and comfortable working in a fast-evolving regulatory environment
  • You are fluent in English; German proficiency is a strong advantage

At KuCoin EU, you will be part of a team committed to innovation, integrity, and regulatory excellence. If you’re ready to contribute to the future of finance in a fast-moving, global environment - we look forward to hearing from you.

KuCoin EU is an equal opportunity employer.We are committed to building a diverse and inclusive workplace. All qualified applicants will be considered for employment without regard to race, religion, gender, sexual orientation, gender identity, national origin, disability, or age. We welcome applications from people of all backgrounds and experiences.

Detailed Job Description

Your Mission

As a Senior Compliance & Risk Manager, you will play a key role in strengthening our compliance and risk management framework, including Third-Party Risk Management (TPRM) and ICT Risk Management. You will also be developing, overseeing and coordinating the company's Business Continuity Management (BCM) framework. Working across Compliance and Risk Management, you will ensure the company meets its regulatory obligations underMiCAR, DORA, MiFID II, PSD IIand related frameworks, while building a robust governance environment and effectively mitigating risks arising from external service providers. You are also expected to prepare regular risk and continuity reports for the Head of Risk, CISO, Management Board and relevant committees.

What You Will Do

Third-Party Risk Management

  • Lead and further develop the company’s Third-Party Risk Management (TPRM) framework, ensuring alignment withDORA, MiCAR, EU GDPR, and ICT risk expectations
  • Conduct pre-contract due diligence, risk classification, and criticality assessments—including EU GDPR data protection impact assessments where relevant
  • Maintain and enhance the DORA-compliantICT Third-Party Register, ensuring complete, accurate, and up-to-date documentation
  • Ensure that ICT outsourcing and third-party contracts include mandatory clauses required by DORA and EU GDPR (including audit/access rights, data protection terms, breach notification, subcontractor conditions, termination, and exit rights)
  • Lead theongoing monitoring of third-party service providers, including performance reviews, compliance checks, EU GDPR adherence, and ICT risk assessments
  • Drive the oversight of critical ICT service providers, coordinating with ICT Security, Risk Management, and Legal to ensure enhanced governance
  • Support the development and maintenance ofexit strategies, contingency plans, business continuity, and data protection mitigation plansfor outsourced ICT services
  • Support the ICT Incident Manager by coordinating third-party activities related to ICT incident monitoring and reporting
  • Support broader enterprise risk management processes by identifying, assessing, and mitigating operational, ICT, compliance, and data protection risks related to third parties
  • Prepare compliance and risk reportsfor senior management, risk committees, and the Board
  • Collaborate with auditors and regulators during examinations, audits, and information requests
  • Provide subject-matter guidance to internal stakeholders on regulatory expectations relating to compliance, outsourcing, ICT risk, and EU GDPR requirements
  • Own and maintain the ICT risk management framework within the enterprise risk management system.
  • Define ICT risk taxonomy, categories, and mapping to enterprise-wide risk.
  • Develop and maintain ICT risk assessment methodologies, templates, and guidelines (systems, applications, vendors, projects, changes).
  • Define ICT-related KRIs and thresholds aligned to risk appetite, in coordination with the Head of Risk and CISO.
  • Maintain the central ICT risk register and ensure accurate risk documentation and classification.
  • Ensure every ICT risk has a designated 1st line risk owner, clear action plan, timelines, and remediation status.
  • Monitor the progress of remediation activities; follow up and elevate overdue items as per defined procedures.
  • Regularly review the register for completeness, consistency, and timeliness.
  • Develop and maintain an annual ICT risk assessment plan (systems, infrastructure, applications, vendors, critical projects).
  • Plan, coordinate, and facilitate risk assessment workshops and interviews with system owners, business stakeholders, CISO, and IT teams.
  • Analyse system architectures, process documentation, vendor materials, and security reports to identify risk scenarios.
  • Document ICT risks, inherent/residual ratings, and recommended treatments using approved methodology.
  • Ensure consistent application of risk scales, criteria, and risk appetite across all reviews.

Business Continuity Management (BCM)

  • Develop, maintain, and enhance Business Continuity and Disaster Recovery policies, standards, and procedures.
  • Conduct Business Impact Analyses (BIA) to identify critical functions, dependencies, and recovery requirements.
  • Work with Business and IT Units to design and implement Business Continuity Plans (BCP) and Disaster Recovery Plans (DRP).
  • Coordinate and support continuity testing programmes, including BCP/DR simulations, tabletop exercises, and post-exercise reporting.
  • Ensure alignment of BCP/DR practices with ICT risk management frameworks and regulatory expectations (e.g., DORA operational resilience requirements).
  • Monitor continuity risks, gaps, and readiness; track remediation of continuity-related findings.
  • Serve as a central coordinator during disruptions or crisis management events, working with Business, IT, CISO, and leadership teams.
  • Promote awareness and training on business continuity roles, responsibilities, and procedures across the organisation.

What Makes You Special

  • You hold a university degree in Law, Economics, Finance, Business, IT Risk, or a related field
  • You bring4+ years of experiencein compliance, risk management, internal control, or audit—experience in financial services, fintech, or crypto is a strong advantage
  • You have demonstrable expertise inThird-Party Risk Management, ICT/outsourcing governance, or risk/compliance work involvingEU GDPR
  • Ability to understand and interpret:
  • High-level system and data flow diagrams
  • Security reports (vulnerability scans, penetration test reports, SOC 2 / ISO 27001 reports)
  • You possess an excellent understanding of European and Austrian regulatory frameworks, especially knowledge of regulatory frameworks: DORA, NIS2, EBA/ESMA guidelines, ISO 27001, ISO 22301 (preferred).
  • You are able to translate regulatory expectations into practical, actionable processes
  • You are fluent in English; German proficiency is a strong plus

At KuCoin EU, you will be part of a team committed to innovation, integrity, and regulatory excellence. If you’re ready to contribute to the future of finance in a fast-moving, global environment - we look forward to hearing from you.

KuCoin EU is an equal opportunity employer.We are committed to building a diverse and inclusive workplace. All qualified applicants will be considered for employment without regard to race, religion, gender, sexual orientation, gender identity, national origin, disability, or age. We welcome applications from people of all backgrounds and experiences.

Detailed Job Description

Your Mission

As a Senior Compliance & Risk Manager, you will play a key role in strengthening our compliance and risk management framework, including Third-Party Risk Management (TPRM) and ICT Risk Management. You will also be developing, overseeing and coordinating the company's Business Continuity Management (BCM) framework. Working across Compliance and Risk Management, you will ensure the company meets its regulatory obligations underMiCAR, DORA, MiFID II, PSD IIand related frameworks, while building a robust governance environment and effectively mitigating risks arising from external service providers. You are also expected to prepare regular risk and continuity reports for the Head of Risk, CISO, Management Board and relevant committees.

What You Will Do

Third-Party Risk Management

  • Lead and further develop the company’s Third-Party Risk Management (TPRM) framework, ensuring alignment withDORA, MiCAR, EU GDPR, and ICT risk expectations
  • Conduct pre-contract due diligence, risk classification, and criticality assessments—including EU GDPR data protection impact assessments where relevant
  • Maintain and enhance the DORA-compliantICT Third-Party Register, ensuring complete, accurate, and up-to-date documentation
  • Ensure that ICT outsourcing and third-party contracts include mandatory clauses required by DORA and EU GDPR (including audit/access rights, data protection terms, breach notification, subcontractor conditions, termination, and exit rights)
  • Lead theongoing monitoring of third-party service providers, including performance reviews, compliance checks, EU GDPR adherence, and ICT risk assessments
  • Drive the oversight of critical ICT service providers, coordinating with ICT Security, Risk Management, and Legal to ensure enhanced governance
  • Support the development and maintenance ofexit strategies, contingency plans, business continuity, and data protection mitigation plansfor outsourced ICT services
  • Support the ICT Incident Manager by coordinating third-party activities related to ICT incident monitoring and reporting
  • Support broader enterprise risk management processes by identifying, assessing, and mitigating operational, ICT, compliance, and data protection risks related to third parties
  • Prepare compliance and risk reportsfor senior management, risk committees, and the Board
  • Collaborate with auditors and regulators during examinations, audits, and information requests
  • Provide subject-matter guidance to internal stakeholders on regulatory expectations relating to compliance, outsourcing, ICT risk, and EU GDPR requirements
  • Own and maintain the ICT risk management framework within the enterprise risk management system.
  • Define ICT risk taxonomy, categories, and mapping to enterprise-wide risk.
  • Develop and maintain ICT risk assessment methodologies, templates, and guidelines (systems, applications, vendors, projects, changes).
  • Define ICT-related KRIs and thresholds aligned to risk appetite, in coordination with the Head of Risk and CISO.
  • Maintain the central ICT risk register and ensure accurate risk documentation and classification.
  • Ensure every ICT risk has a designated 1st line risk owner, clear action plan, timelines, and remediation status.
  • Monitor the progress of remediation activities; follow up and elevate overdue items as per defined procedures.
  • Regularly review the register for completeness, consistency, and timeliness.
  • Develop and maintain an annual ICT risk assessment plan (systems, infrastructure, applications, vendors, critical projects).
  • Plan, coordinate, and facilitate risk assessment workshops and interviews with system owners, business stakeholders, CISO, and IT teams.
  • Analyse system architectures, process documentation, vendor materials, and security reports to identify risk scenarios.
  • Document ICT risks, inherent/residual ratings, and recommended treatments using approved methodology.
  • Ensure consistent application of risk scales, criteria, and risk appetite across all reviews.

Business Continuity Management (BCM)

  • Develop, maintain, and enhance Business Continuity and Disaster Recovery policies, standards, and procedures.
  • Conduct Business Impact Analyses (BIA) to identify critical functions, dependencies, and recovery requirements.
  • Work with Business and IT Units to design and implement Business Continuity Plans (BCP) and Disaster Recovery Plans (DRP).
  • Coordinate and support continuity testing programmes, including BCP/DR simulations, tabletop exercises, and post-exercise reporting.
  • Ensure alignment of BCP/DR practices with ICT risk management frameworks and regulatory expectations (e.g., DORA operational resilience requirements).
  • Monitor continuity risks, gaps, and readiness; track remediation of continuity-related findings.
  • Serve as a central coordinator during disruptions or crisis management events, working with Business, IT, CISO, and leadership teams.
  • Promote awareness and training on business continuity roles, responsibilities, and procedures across the organisation.

What Makes You Special

  • You hold a university degree in Law, Economics, Finance, Business, IT Risk, or a related field
  • You bring4+ years of experiencein compliance, risk management, internal control, or audit—experience in financial services, fintech, or crypto is a strong advantage
  • You have demonstrable expertise inThird-Party Risk Management, ICT/outsourcing governance, or risk/compliance work involvingEU GDPR
  • Ability to understand and interpret:
  • High-level system and data flow diagrams
  • Security reports (vulnerability scans, penetration test reports, SOC 2 / ISO 27001 reports)
  • You possess an excellent understanding of European and Austrian regulatory frameworks, especially knowledge of regulatory frameworks: DORA, NIS2, EBA/ESMA guidelines, ISO 27001, ISO 22301 (preferred).
  • You are able to translate regulatory expectations into practical, actionable processes
  • You are fluent in English; German proficiency is a strong plus
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

ICT Risk Manager
ICT Risk Manager

KuCoin EU • Wien

Vor Ort
EUR 90.000 - 130.000
Team events
Snack & beverages
Friday breakfasts
+2
IT Audit Manager New Vienna, Austria
IT Audit Manager New Vienna, Austria

Bybit Limited • Wien

Hybrid
EUR 100.000 - 140.000
Study Growth Fund
Internal Events
Global Collaboration
+2
Head of ICT & Operations and CISO(AUSTRIA) Posted on 2026-06-04 | Legal & Compliance Legal & Co[...]
Head of ICT & Operations and CISO(AUSTRIA) Posted on 2026-06-04 | Legal & Compliance Legal & Co[...]

Atome • Wien

Vor Ort
EUR 180.000 - 250.000
Senior Compliance & Risk Leader — ICT, TPRM & BCM
Senior Compliance & Risk Leader — ICT, TPRM & BCM

Atome • Wien

Hybrid
EUR 90.000 - 130.000
Vienna office location at Trabrennbahn
Team events
Snacks and Friday breakfasts
+4
Managing Director at a MiCAR-regulated company Vienna, Austria • 7+ years of experience •
Managing Director at a MiCAR-regulated company Vienna, Austria • 7+ years of experience •

WhiteBIT Group • Wien

Vor Ort
EUR 180.000 - 240.000
25 business days of paid leave
Modern equipment
Inspiring environment
Head of Legal
Head of Legal

WhiteBIT • Wien

Vor Ort
EUR 120.000 - 170.000
25 paid leave days
Extra days off for holidays
Senior KYC Specialist
Senior KYC Specialist

Bitget • Österreich

Vor Ort
EUR 75.000 - 110.000
MiFID Compliance Manager - Crypto Exchange
MiFID Compliance Manager - Crypto Exchange

Park Brown International • Wien

Vor Ort
EUR 90.000 - 130.000
[EU ] Internal Audit Expert
[EU ] Internal Audit Expert

Bybit • Wien

Vor Ort
EUR 90.000 - 130.000
Study Growth Fund
Internal Events
Global Collaboration
+2
DevSecOps Engineer
DevSecOps Engineer

Ketryx • Wien

Hybrid
EUR 90.000 - 120.000
Competitive compensation
Positive impact in healthcare
Global team
+1