- Fraud detection models running continuously across money movement, trading abuse, and document forgery
- Automated AML review: data aggregation, risk metric computation, high-risk client flagging
- Investigation portals that synthesise findings into unified risk profiles instead of scattered notes
Five things
sit with you. All of them cover the entire business — financial and
non-financial risk, every entity, every jurisdiction:
Risk
Framework Ownership — Owning the enterprise risk framework end to
end: taxonomy, appetite, assessment methodology and the control mapping
underneath it. Market, credit, counterparty, liquidity and capital risk sit
here alongside operational, technology, third-party, conduct, financial crime
and strategic risk.
Regulatory
Obligations Across Jurisdictions — Owning the
risk view of everything each licence demands: prudential and capital
requirements, client money and safeguarding, leverage and product rules,
conduct and client outcomes, financial crime, reporting, outsourcing,
resilience and governance. Keeping it consistent where jurisdictions differ, and
turning regulatory change into action with lead time.
Predictive
Risk — Building the forward-looking layer of the
risk function. Leading indicators, predictive models, emerging risk
identification and horizon scanning, so exposure gets flagged while it’s still
cheap to fix rather than explained after it isn’t.
Testing,
Monitoring & Remediation — Stress
testing, scenario design, control testing, KRIs and risk reporting — and then
chasing remediation until the exposure is measurably smaller, not just
documented.
AI-Driven
Transformation — Building the tools. Designing and deploying
the models, automated monitoring and analytics the risk function runs on,
embedding them into daily workflow, and governing them so the output can be
trusted.
Own the framework across the
whole business
• Build and maintain the risk framework covering
financial and non-financial risk — when it misses something, it's your problem
until it's fixed
• Monitor capital, liquidity, market, credit and
counterparty exposure against internal limits set above the regulatory floor,
not at it
• Map controls to every material risk, name the
risks running without one, and spot where several acceptable exposures combine
into one that isn't
Own the regulatory picture
• Keep one clear view of what every licence
requires — prudential, conduct, client money, financial crime, reporting,
outsourcing, resilience — and what the business is doing about each
• Track regulatory change and say what has to be
done differently, early enough for it to matter
• Give inspections, submissions and regulatory
requests risk data that holds up under examination
Predict, don't react
• Build leading indicators that move before the
risk does, and predictive models that flag exposure while it's still cheap to
fix
• Run horizon scanning across regulation,
markets, technology, competitors and geopolitics, and turn it into risks the
business recognises as its own
• Review new products, new markets and major
change before launch, and say what could go wrong while there's still time to
design it out
Test it, then drive it down
• Design stress tests that actually stress
something, and defend the results when they're inconvenient
• Set KRIs with thresholds specific enough to be
breached, escalate with a recommendation attached, and report one connected
picture to management, committees and the board
• Chase action plans to closure and verify the
exposure actually fell — measured on the indicator, not asserted in an email
Build the AI the function runs
on
• Design and deploy models, automated monitoring
and analytics yourself — this is a build role, not a role that uses someone
else's tools
• Embed them into how the team works day to day,
so analyst time goes to judgment instead of data collection
• Govern what you build: inventory, validation,
performance monitoring. Know when a flag is noise and when it's the start of
something real, and push back when a dashboard calls something a risk that
isn't
You've
managed risk across a whole business, not one segment of it. 5-8 years in risk management within financial services, trading or a
regulated brokerage, covering financial and non-financial risk. You can go from
a capital calculation to a vendor concentration issue to a conduct risk
assessment in the same week and be credible in all three. You think in
exposure, not in process — you can see where an operation is fragile before a
test proves it.
You've built
a framework someone actually used. Taxonomy,
appetite, methodology, indicators, reporting. You know which parts change
behaviour and which parts just generate paper. And you finish things: you
follow actions to closure and check the risk moved, because an action closed on
a tracker that left the exposure where it was isn't closed.
You know CFD
products, the platforms they run on, and the regulation around both. Required. Leverage, margin, negative balance protection, hedging
models, client positioning — and how each turns into exposure. Prudential and
capital frameworks: IFR/IFD, Basel principles as applied to investment firms,
MiFID II conduct requirements. You can read a licence condition in any
jurisdiction and say what it means operationally.
You work
forward, not backward. You're more interested
in what's coming than what already happened, and you can point to a time you
flagged something before it became a problem and explain how you knew. You've
built leading indicators or predictive analysis that changed a decision, not
just a report.
You build AI,
you don't just use it. Comfortable in large
datasets and confident with the statistics behind a model. You've built or
deployed something that runs in production — automated monitoring, a predictive
model, an analytics pipeline — and embedded it into how a team works, not left
it as a proof of concept. You understand where models are strong, where they
need a person, and how to govern the difference. You don't need direct reports
to have influence: when your assessment says something matters, people act on
it because the reasoning holds.
Skills Required
- 5-8 years of risk management experience within financial services or trading
- Experience assessing real-world risk exposure, not only theoretical modeling
- Understanding of predictive models, AI-assisted monitoring, and their limitations
- FRM, PRM, or equivalent risk management certification
- Ability to design stress tests and scenario analyses
- Ability to influence stakeholders and present findings to executives
- Ability to partner with compliance on regulatory risk requirements
What We Do
Deriv is a regulated online brokerage group that connects millions of customers in more than 150 countries to global financial markets. It offers contracts for difference (CFDs) and other derivatives covering forex, stocks and indices, cryptocurrencies, commodities, and Derived Indices. The company also provides online trading platforms and tools, including mobile trading, TradingView, Deriv MT5, cTrader, Deriv Trader, and Deriv Bot.








