Cyberjaya, Malaysia | Posted on 30/07/2026
Individual Contributor role — you'll lead through analysis and judgment, not people management.
We're not hiring someone to fill out risk registers. We're hiring someone to figure out why a risk model missed something last quarter — and build the system that catches it next time.
Why this matters
Deriv's mission is Trading for Anyone, Anywhere, Anytime. Millions of traders, in multiple currencies, across regulatory regimes, around the clock. At that scale, risk doesn't wait for a quarterly review cycle — it moves as fast as the market does.
Real money, real regulations, real consequences. We're already building risk operations that run continuously: dozens of fraud detection models flagging money-movement patterns and trading abuse in production, AML review pulling risk metrics automatically instead of by hand, and vendor risk assessments run through document analysis instead of a checklist. Not experiments — systems that are already catching things a person reviewing spreadsheets would miss. You'll own the next layer of that.
We're in production, not planning.
- Fraud detection models running continuously across money movement, trading abuse, and document forgery
- Automated AML review: data aggregation, risk metric computation, high-risk client flagging
- Investigation portals that synthesise findings into unified risk profiles instead of scattered notes
We've proved the model works. You're not waiting for a pilot to get approved — you're extending something that already runs.
Scope of Work
Five things sit with you. All of them cover the entire business — financial and non-financial risk, every entity, every jurisdiction:
- RiskFramework Ownership — Owning the enterprise risk framework end toend: taxonomy, appetite, assessment methodology and the control mapping underneath it. Market, credit, counterparty, liquidity and capital risk sithere alongside operational, technology, third-party, conduct, financial crimeand strategic risk.
- RegulatoryObligations Across Jurisdictions — Owning the risk view of everything each licence demands: prudential and capitalrequirements, client money and safeguarding, leverage and product rules, conduct and client outcomes, financial crime, reporting, outsourcing, resilience and governance. Keeping it consistent where jurisdictions differ, andturning regulatory change into action with lead time.
- PredictiveRisk — Building the forward-looking layer of the risk function. Leading indicators, predictive models, emerging riskidentification and horizon scanning, so exposure gets flagged while it’s stillcheap to fix rather than explained after it isn’t.
- Testing,Monitoring & Remediation — Stresstesting, scenario design, control testing, KRIs and risk reporting — and thenchasing remediation until the exposure is measurably smaller, not justdocumented.
- AI-DrivenTransformation — Building the tools. Designing and deployingthe models, automated monitoring and analytics the risk function runs on,embedding them into daily workflow, and governing them so the output can betrusted.
What You'll Do
Own the framework across the whole business
- Build and maintain the risk framework coveringfinancial and non-financial risk — when it misses something, it's your problem until it's fixed
- Monitor capital, liquidity, market, credit and counterparty exposure against internal limits set above the regulatory floor, not at it
- Map controls to every material risk, name the risks running without one, and spot where several acceptable exposures combine into one that isn't
Own the regulatory picture
- Keep one clear view of what every licence requires — prudential, conduct, client money, financial crime, reporting, outsourcing, resilience — and what the business is doing about each
- Track regulatory change and say what has to be done differently, early enough for it to matter
- Give inspections, submissions and regulatory requests risk data that holds up under examination
Predict, don't react
- Build leading indicators that move before the risk does, and predictive models that flag exposure while it's still cheap tofix
- Run horizon scanning across regulation, markets, technology, competitors and geopolitics, and turn it into risks thebusiness recognises as its own
- Review new products, new markets and major change before launch, and say what could go wrong while there's still time to design it out
Test it, then drive it down
- Design stress tests that actually stress something, and defend the results when they're inconvenient
- Set KRIs with thresholds specific enough to be breached, upscale with a recommendation attached, and report one connected picture to management, committees and the board
- Chase action plans to closure and verify the exposure actually fell — measured on the indicator, not asserted in an email
Build the AI the function runson
- Design and deploy models, automated monitoringand analytics yourself — this is a build role, not a role that uses someoneelse's tools
- Embed them into how the team works day to day,so analyst time goes to judgment instead data collection
- Govern what you build: inventory, validation, performance monitoring. Know when a flag is noise and when it's the start ofsomething real, and push back when a dashboard calls something a risk thatisn't
Who You Are
- You'vemanaged risk across a whole business, not one segment of it. 5-8 years in risk management within financial services, trading or aregulated brokerage, covering financial and non-financial risk. You can go froma capital calculation to a vendor concentration issue to a conduct riskassessment in the same week and be credible in all three. You think inexposure, not in process — you can see where an operation is fragile before atest proves it.
- You've builta framework someone actually used. Taxonomy,appetite, methodology, indicators, reporting. You know which parts changebehaviour and which parts just generate paper. And you finish things: youfollow actions to closure and check the risk moved, because an action closed ona tracker that left the exposure where it was isn't closed.
- You know CFDproducts, the platforms they run on, and the regulation around both. Required. Leverage, margin, negative balance protection, hedgingmodels, client positioning — and how each turns into exposure. Prudential andcapital frameworks: IFR/IFD, Basel principles as applied to investment firms,MiFID II conduct requirements. You can read a licence condition in anyjurisdiction and say what it means operationally.
- You workforward, not backward. You're more interestedin what's coming than what already happened, and you can point to a time youflagged something before it became a problem and explain how you knew. You'vebuilt leading indicators or predictive analysis that changed a decision, notjust a report.
- You build AI,you don't just use it. Comfortable in largedatasets and confident with the statistics behind a model. You've built ordeployed something that runs in production — automated monitoring, a predictivemodel, an analytics pipeline — and embedded it into how a team works, not leftit as a proof of concept. You understand where models are strong, where they need a person, and how to govern the difference. You don't need direct reportsto have influence: when your assessment says something matters, people act onit because the reasoning holds.
The Honest Reality
This is demanding work. You'll own outcomes with incomplete data, because incomplete data is the only kind risk work ever gets. You'll navigate friction between trading, compliance, and leadership when they all want different answers. You'll establish standards that other analysts get measured against, and defend a risk finding to stakeholders who'd rather it wasn't true.
But you'll build frameworks that outlast the quarter they were written for. You'll work with AI tools that make your analysis sharper instead of slower. And you'll know that when you flag something, it's the reason it got fixed before it became a headline.
If you want risk work that's mostly documentation, this isn't it. If you want to find what the models miss, it might be.