Enterprise Risk & Program Manager
๐ข BitPay - Career Page ยท all BitPay - Career Page jobs
๐ Remote ยท North America
๐
Posted 2026-08-03 ยท via RemoteIO
๐ท Risk Management,Internal Audit,Governance,Compliance,Fintech
Apply on original site โBitPay is seeking an experienced and strategic Enterprise Risk & Program Manager to establish, lead, and continuously enhance the enterprise risk management (ERM) and internal audit functions for a rapidly growing regulated crypto fintech. This individual will play a critical role in safeguarding the firm's resilience, ensuring regulatory compliance, strengthening governance, and enabling sustainable growth across digital asset products, payments, and financial services.
The successful candidate will be responsible for developing a risk-aware culture, implementing robust governance frameworks, overseeing the enterprise-wide risk management program, and delivering an independent internal audit function that provides assurance to executive management and the Board. This role requires deep expertise in financial services risk management, digital assets, regulatory compliance, operational resilience, and technology-enabled controls.
Responsibilities:
Enterprise Risk Management
- Develop, implement, and maintain the firm's Enterprise Risk Management (ERM) framework.
- Define the firm's risk appetite and risk tolerance statements in partnership with executive management and the Board.
- Lead enterprise-wide risk identification, assessment, monitoring, mitigation, and reporting.
- Maintain the enterprise risk register and oversee key risk indicators (KRIs).
- Complete the annual Enterprise Risk Assessment and map identified risks to the integrated internal audit plan.
- Conduct periodic enterprise risk assessments covering strategic risk, operational risk, financial risk, market risk, liquidity risk, counterparty risk, technology and cyber risk, digital asset risk, regulatory and compliance risk, third-party/vendor risk, fraud risk, business continuity and operational resilience, and other enterprise risks as they arise.
- Facilitate risk workshops and challenge business assumptions to ensure effective risk ownership.
- Monitor emerging risks within the crypto and fintech ecosystem.
- Drive Enterprise Risk and Internal Audit Committees with reporting, dashboards, and governance materials.
Internal Audit
- Build and lead an independent, risk-based internal audit function.
- Enhance the internal audit plan using a risk-based methodology.
- Partner with stakeholders to execute audits across all business functions, including: - Finance
- Compliance & Risk
- Cybersecurity
- Evaluate the effectiveness of internal controls using recognized control frameworks.
- Track and report on audit findings through remediation and validation.
- Present audit reports and recommendations to senior management and the Board Audit Committee.
- Coordinate with external auditors and regulators.
Requirements :
- Bachelor's degree in Business, Risk Management and Governance, Economics, or a related field.
- One or more professional certifications preferred, including: - Certified Internal Auditor (CIA)
- Certified Information Systems Auditor (CISA)
- Certified Anti-Money Laundering Specialist (CAMS)
- Certified Fraud Examiner (CFE)
- Certified Risk Manager (CRM)
- At least 5 years leading enterprise risk, internal audit, governance or operational risk programs within a regulated financial services environment, preferably in the crypto industry
- At least 5 years in a senior leadership role.
- Experience working with regulated fintechs, digital asset firms, banks, payment institutions, or capital markets organizations.
- Demonstrated program and project management experience leading cross-functional initiatives.
- Demonstrated experience interacting with regulators and Board committees.
- Experience with payments and money transmission
- Experience with a fintech environment and global regulatory regimes. Strong knowledge pertaining Enterprise Risk Management and COSO internal Control Framework.
- Technical knowledge pertaining to operational risk management, regulatory reporting, financial crime controls, cyber