About Capital Vault
Capital Vault (CV) is a crypto infrastructure provider under the Capital.com Group umbrella, focused on delivering regulated crypto custody, spot exchange, payment processing, and wallet services.
Role Summary
The Head of Risk Management is a senior leadership position responsible for establishing, overseeing, and continuously enhancing CV's enterprise-wide risk framework. This includes financial, operational, cyber, and crypto‑asset‑specific risks. The role is critical in meeting the SCA/CySEC/FCA regulatory expectations and ensuring the company operates within its defined risk appetite across all business lines.
Responsibilities
- Strategic Risk Oversight
- Design, implement, and maintain a risk management framework tailored for a regulated crypto firm
- Identify and assess material risks across CV's business: custody, exchange, wallets, payments and staking
- Define and update the firm's risk appetite and tolerance thresholds in collaboration with the Board
- Risk Governance & Reporting
- Lead the Risk Management Committee and prepare regular risk reports to the Board and regulators
- Maintain the Risk Register and ensure timely escalation of emerging risks
- Work closely with Compliance and Internal Audit to maintain a robust control environment
- Operational Risk
- Develop risk scenarios
- Monitor and respond to service disruptions and operational control failures
- Drive implementation of internal controls and conduct Risk & Control Self‑Assessments (RCSAs)
- Market, Liquidity & Credit Risk
- Assess risks linked to CV's trading with external liquidity providers (e.g., default, slippage, settlement failure)
- Review pricing sources, aggregation logic, and back‑to‑back execution mechanisms
- Custody & Technology Risk
- Evaluate risk controls around hot/cold wallet segregation, private key management (e.g., Fireblocks), and internal ledger accuracy
- Collaborate with cybersecurity teams to mitigate key threats such as wallet compromise, ransomware, or DDoS attacks
- Regulatory Risk
- Monitor compliance with SCA's risk‑related requirements (e.g., capital adequacy, outsourcing, incident reporting)
- Ensure risk systems, documentation, and controls remain audit‑ready and up to date
- Product Risk
- Perform product risk assessments for new crypto offerings before go‑live
- Ensure end‑user risk disclosures and internal risk control measures align with regulatory expectations
Qualifications
- Required:
- Bachelor's degree in Risk Management, Finance, Economics, Engineering, or a related field
- 7+ years of experience in risk management, with at least 3 in crypto, fintech, or capital markets
- Strong understanding of crypto‑specific risks, including custody, blockchain analytics, and liquidity sourcing
- Experience working with SCA or other financial regulators in the UAE or GCC
- Knowledge of MiCA, SCA Cat7, and UK MLR2017 risk‑related obligations is a plus
- Preferred:
- Risk certifications such as FRM (GARP), PRM, or equivalent
- Exposure to regulatory capital calculations and stress testing methodologies for crypto businesses
- Familiarity with ISO 27001, NIST, or other information security frameworks
Benefits
- Competitive Salary: We believe great work deserves great pay! Your skills and talents will be rewarded with a salary that makes you feel valued and motivated
- Work‑Life Harmony: Join a company that genuinely cares about you - because your life outside of work matters just as much as your time on the clock
- Annual Performance Bonus: Your hard work doesn't go unnoticed! Celebrate your achievements with a well‑deserved annual bonus tied to your performance
- Generous Time Off: Need a breather? Our annual leave policy lets you recharge and enjoy life outside of work without a worry
- Employee Referral Program: Love working here? Share the love! Bring your talented friends on board and get rewarded for growing our awesome team
- Comprehensive Health & Pension Benefits: From medical insurance to pension plans, we've got your back. Plus, location‑specific benefits and perks!
- Workation Wonderland: Live your digital nomad dreams with 30 extra days to work remotely from anywhere in the world (some restrictions apply). Adventure awaits!
- Volunteer Days: Make a difference! Take two additional paid days each year to support causes you care about and give back to the community