Director - Enterprise Risk (Bengaluru)

Director - Enterprise Risk (Bengaluru)

22 Sep
|
Risk
|
Bengaluru

22 Sep

Risk

Bengaluru

The CoinDCX Journey: Building the Future of Finance:

At CoinDCX, our mission is transparent - to make crypto and blockchain accessible
to every Indian and enable them to participate in the future of finance.

As India’s first crypto unicorn valued at $2.45B, we are reshaping the
financial ecosystem by building safe, transparent, and scalable products that
power adoption at scale.

We believe that change starts together. It begins with bold ideas, relentless
execution and people who want to build what’s next.

If you’re driven by purpose and thrive in environments where your work
defines the next chapter of an industry, you’ll feel right at home here.

About the Role:

This role owns CoinDCX's Enterprise Risk Management framework end to end —
the Risk Appetite Statement, the enterprise risk register, the quarterly Risk
Control Self-Assessment (RCSA) process, and the consolidated Board risk report.
You'll bring Market, Credit, Technology, and Quant risk together into one
coherent view for the CRO and the Board each quarter, and you'll run the RCSA
cycle that gets every risk-owning team to formally assess their own controls on
a fixed schedule, rather than waiting for a problem to surface one. You'll set
risk policy for Web3, Token, and DeFi exposure, including Okto, and bring fiat
and VDA custody risk together into a single reporting line. You'll work closely
with every other Risk hire and with Compliance, Treasury, and InfoSec to keep
the framework grounded in what's actually happening across the business.

What You’ll Do:

Ongoing / BAU

* Maintain and operationalize the Enterprise Risk Management framework across
all 1st and 2nd line functions, including the Risk Appetite Statement and the
traffic-light escalation ladder (Green/Amber/Red/Black).
* Run the quarterly RCSA cycle — each risk-owning team formally assesses the
design and operating effectiveness of its own controls against the enterprise
risk register, with findings, ratings, and remediation owners tracked to
closure.
* Chair the Token Listing & Protocol Risk review, holding second-line
sign-off authority over new asset listings, bridge exposures, and DeFi/Okto
integrations before launch.
* Consolidate quarterly risk exposure reporting and the Board Risk Committee
deck — Market/Credit, Technology, Compliance, Quant, and RCSA findings, plus a
single consolidated custody risk line combining the AVP's fiat review and the
Technology Director's VDA review.
* Partner with Compliance/Legal on regulatory filings and statutory
governance deliverables that draw on the ERM framework and RCSA evidence —
Compliance owns the filing; this role owns the underlying framework and
evidence trail.

Tentative Deliverables — 3 Months

* Draft the first consolidated Enterprise Risk Register and Risk Appetite
Statement, using the CoinDCX ERM Framework's taxonomy and appetite tiers as the
starting structure, with metrics defined across all risk categories including
custody.
* Design the RCSA methodology — the assessment template, control-rating
scale, and cadence every risk-owning team will be evaluated against, modelled
on the approach used in the BitOasis framework.
* Inventory every risk model currently in use across the business — feeds
directly into the Risk Analytics Director's validation backlog.
* Inventory existing token-listing diligence practices and draft a
standardized second-line Token Risk Assessment framework.
* Meet with each of the other four Risk hires plus Compliance, InfoSec,
Treasury, and Trade Operations to map ownership — including the fiat/VDA
custody split — and draft an initial RACI.

Tentative Deliverables — 6 Months





* Secure Board sign-off on the Risk Appetite Statement and traffic-light
escalation limits.
* Run the first company-wide RCSA cycle across every functional business
unit, with findings rated, owned, and tracked — not just collected.
* Deliver the first consolidated Board Risk Pack, including RCSA results and,
for the first time, the joint fiat + VDA custody risk line.
* Publish an initial risk policy for token listings and Okto
protocol/bridge/DeFi treasury exposure.

Tentative Deliverables — 1 Year

* RCSA runs on a quarterly cadence with a demonstrated remediation track
record — findings from the first cycle are closed, and the second and third
cycles show fewer repeat issues.
* Board reporting is a repeatable quarterly process that doesn't depend on
chasing inputs.
* Every material risk model has a documented, independent validation record,
delivered in partnership with the Risk Analytics Director.
* Every new token listing and Okto/DeFi exposure decision is routed through a
documented governance gate.
* Custody risk (fiat and VDA) is a standing, consolidated line in every
quarterly Board report.

You’ll Excel in This Role If You:

* Have 8+ years in enterprise risk management, risk governance, or regulatory
consulting within a regulated financial institution, fintech, or crypto
exchange.
* Have designed and run an RCSA (or equivalent control self-assessment)
program before — you know how to get honest self-ratings out of teams who'd
rather not surface their own gaps, and how to turn findings into tracked
remediation, not a filed PDF.
* Having built or run an ERM framework before — familiarity with COSO, ISO
31000, or a comparable three-lines-of-defense model is a strong plus.
* Have working knowledge of the regulatory landscape relevant to crypto
exchanges (VARA, MiCA, MAS, DORA) — enough to build a framework that would hold
up under one of them, even though Compliance owns the actual filings.
* Are comfortable evaluating token/smart-contract/DeFi risk well enough to
set policy, even though you won't build the underlying technical controls
yourself.
* Have used, or can quickly learn, a GRC platform (e.g. LogicGate,
MetricStream, Archer) or equivalent workflow tooling.
* Can turn five teams' worth of inconsistent risk reporting into one
coherent, Board-ready narrative.
* Can hold a room of Directors and VPs accountable to a governance process
without formal authority over their teams.
* Write clearly and concisely for a Board audience.
* Hold a Bachelor's or Master's degree, or equivalent experience, in Finance,
Risk Management, Law, or a related field.

You’ll Know You’re Winning When:

At 6 Months

* The Board has formally signed off on a Risk Appetite Statement and ERM
framework that didn't exist before.
* The first company-wide RCSA cycle is complete, with every finding rated and
assigned an owner.
* Every candidate token listing is evaluated against the standardized
second-line Token Risk framework before launch.
* The first consolidated Board risk report has been delivered on schedule —
including a joint fiat + VDA custody risk line.

At 12 Months

* RCSA runs on a quarterly cadence with a visible drop in repeat findings —
teams are fixing what the last cycle surfaced, not re-surfacing it.




* Board reporting runs on a quarterly cadence without you chasing inputs from
other teams.
* Every material model has a documented validation record.
* The token listing / Okto governance gate is in active, routine use.
* Custody risk is a standing quarterly fixture in Board reporting.

Scope, Ownership & Boundaries (cross-referenced to the Risk Architecture)

* You own: the Risk Appetite Statement, enterprise risk register, the RCSA
program — methodology, cadence, and remediation tracking, not just running it
once — and consolidated Board reporting (BitOasis's RO-style quarterly cadence;
CoinDCX ERM and RACI); Web3/Token/Okto/DeFi risk policy (CEX Risk Architecture,
Pillar 5 — Protocol & Token Listing Risk); the consolidated custody risk line
in Board reporting, bringing together the AVP's fiat custody review and the
Technology Director's VDA custody review into one view.
* You do not own: execution of individual risk domains — Technology,
Financial/Liquidity, and Quant/Fraud sit with the other three hires, and that
includes the underlying fiat and VDA custody reviews themselves: you
consolidate and report the findings, you don't run the reviews; day-to-day
Compliance/AML program ownership and regulatory filings, which stay with
Compliance/Legal — you own the framework and RCSA evidence trail those filings
draw on, not the filing itself; actual model-building and validation execution,
which the Risk Analytics Director owns (you own the requirement that it happens
on schedule, and RCSA is one of the mechanisms that surfaces whether it did).

Why This Role Matters & What’s In It For You:

You gain the unique opportunity to establish the definitive "single source of
truth" at scale, moving beyond mere reporting to drive high-stakes innovation
in the Web3 space. This is a platform to exercise true ownership, where you
will solve industry-defining challenges and elevate the organization's
analytical maturity through visionary leadership and continuous analytical
evolution.

Hiring Process:

Here’s what your journey with us looks like:

* Application Review – We assess for skills, alignment, and intent
* Recruiter Connect – A short conversation to understand you better
* Functional Round(s) – Deep dive into your approach, craft, and
problem-solving
* Assignment / Simulation Round –
* A take-home task or live problem-solving exercise to understand how you
think and execute in real scenarios
* Culture & Values Discussion – A conversation to understand our ways of
working and how you thrive best
* Founder Conversation (Optional) – For certain roles and senior levels, you
may meet our founders to explore strategic alignment and long-term fit

Where We Work:

We believe the best ideas emerge when people build together. Collaboration,
speed and trust come alive when teams share the same space.

With this belief, we operate as a work-from-office organisation. This role is
based out of our Bangalore office, where energy, alignment and innovation move
in real time.

Perks That Empower You:

We believe great people deserve great experiences.

* Design Your Own Benefits: Flexible perks to match your lifestyle
* Unlimited Wellness Leaves: Rest and recharge as you need
* Mental Wellness Support: Access to therapy and wellness resources
* Learning Sessions: Bi-weekly learning and growth opportunities

Ready to Build What’s Next?

If you’re looking for a role that gives you direct access to high-stakes
decisions, deep impact and a chance to build the future of finance, this is it.

Join CoinDCX and help us make crypto accessible to every Indian, together.

📌 Director - Enterprise Risk (Bengaluru)
🏢 Risk
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: director - enterprise risk (bengaluru) / bengaluru