Enterprise Risk & Program Manager

Bitpay, Inc.
United States
15 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
1 year minimum
Working hours
Regular working hours

Tech stack

Cyber Security Information Systems Digital Assets Fraud Prevention and Detection

Job description

Hiring Remotely in United States Senior level Lead design and execution of the firm’s ERM and independent internal audit functions for a regulated crypto fintech. Build ERM framework, define risk appetite, run enterprise risk assessments, maintain risk register/KRIs, conduct risk-based audits across finance, compliance, and cybersecurity, track remediation, present findings to senior management and the Board, and coordinate with external auditors and regulators. The summary above was generated by AI

BitPay is seeking an experienced and strategic Enterprise Risk & Program Manager to establish, lead, and continuously enhance the enterprise risk management (ERM) and internal audit functions for a rapidly growing regulated crypto fintech. This individual will play a critical role in safeguarding the firm’s resilience, ensuring regulatory compliance, strengthening governance, and enabling sustainable growth across digital asset products, payments, and financial services.

The successful candidate will be responsible for developing a risk-aware culture, implementing robust governance frameworks, overseeing the enterprise-wide risk management program, and delivering an independent internal audit function that provides assurance to executive management and the Board. This role requires deep expertise in financial services risk management, digital assets, regulatory compliance, operational resilience, and technology-enabled controls.

Responsibilities:

Enterprise Risk Management

  • Develop, implement, and maintain the firm’s Enterprise Risk Management (ERM) framework.
  • Define the firm’s risk appetite and risk tolerance statements in partnership with executive management and the Board.
  • Lead enterprise-wide risk identification, assessment, monitoring, mitigation, and reporting.
  • Maintain the enterprise risk register and oversee key risk indicators (KRIs).
  • Complete the annual Enterprise Risk Assessment and map identified risks to the integrated internal audit plan.
  • Conduct periodic enterprise risk assessments covering strategic risk, operational risk, financial risk, market risk, liquidity risk, counterparty risk, technology and cyber risk, digital asset risk, regulatory and compliance risk, third-party/vendor risk, fraud risk, business continuity and operational resilience, and other enterprise risks as they arise.
  • Facilitate risk workshops and challenge business assumptions to ensure effective risk ownership.
  • Monitor emerging risks within the crypto and fintech ecosystem.
  • Drive Enterprise Risk and Internal Audit Committees with reporting, dashboards, and governance materials.

Internal Audit

  • Build and lead an independent, risk-based internal audit function.
  • Enhance the internal audit plan using a risk-based methodology.
  • Partner with stakeholders to execute audits across all business functions, including:
  • Finance
  • Compliance & Risk
  • Cybersecurity
  • Evaluate the effectiveness of internal controls using recognized control frameworks.
  • Track and report on audit findings through remediation and validation.
  • Present audit reports and recommendations to senior management and the Board Audit Committee.
  • Coordinate with external auditors and regulators.

Requirements

  • At least 5 years leading enterprise risk, internal audit, governance or operational risk programs within a regulated financial services environment, preferably in the crypto industry
  • Experience working with regulated fintechs, digital asset firms, banks, payment institutions, or capital markets organizations.
  • Demonstrated program and project management experience leading cross-functional initiatives.
  • Demonstrated experience interacting with regulators and Board committees.

  • Experience with payments and money transmission
  • Experience with a fintech environment and global regulatory regimes. Strong knowledge pertaining Enterprise Risk Management and COSO internal Control Framework.
  • Technical knowledge pertaining to operational risk management, regulatory reporting, financial crime controls, cybersecurity, third party risk management and operational resilience.
  • Strategic mindset with the ability to translate complex risks into actionable business decisions.
  • Strong written and verbal communication.
  • Ability to challenge constructively while maintaining collaborative relationships.
  • Bachelor’s degree in Business, Risk Management and Governance, Economics, or a related field.
  • One or more professional certifications preferred, including:
  • Certified Internal Auditor (CIA)
  • Certified Information Systems Auditor (CISA)
  • Certified Anti-Money Laundering Specialist (CAMS)
  • Certified Fraud Examiner (CFE)
  • Certified Risk Manager (CRM)

Benefits & conditions

  • Collaborate with a team of intelligent, enthusiastic individuals.
  • Thrive in a rapidly expanding crypto company with global reach, where your contributions make a tangible impact.
  • Work remote with a generous vacation policy, including the opportunity to take a sabbatical and select your own holidays.
  • Access to continuous learning and development opportunities, supported by professional development reimbursement.
  • Competitive salary package with comprehensive benefits, including fully covered medical and dental plans. We also offer telemedicine, life insurance, disability insurance, vision coverage, 401k, travel assistance, and more.
  • Option to receive payment in cryptocurrency, along with a crypto match program.
  • Stock option awards available to all employees.
  • Home office allowance, reimbursement for internet/cell expenses, complimentary Amazon Prime and Spotify subscriptions.

IMPORTANT NOTICE: We are committed to a safe and secure hiring process. All roles and communications are shared only through our official channels and with employees of BitPay, and applications are posted via our official careers page. We will not message you via social media direct messages or websites not affiliated with BitPay to recruit or collect personal information. To protect yourself from fraud, please ensure that you are applying to BitPay through our official BitPay Career Page and take the following steps if you notice anything suspicious.

BitPay will never ask you to:

  • Install remote-access tools (TeamViewer, AnyDesk, etc.)
  • Share SSN or banking details before a formal, written offer from BitPay People Ops
  • Interview via personal email domains, text, or messaging apps
  • Pay fees, purchase equipment, or send money/crypto/gift cards for any reason

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on bitpay.applytojob.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

4:47 min

Navigating digital copyability and centralized digital assets

Jimmy Song · World Congress 2021

1:44 min

Background and career journey in regulated software systems

Martin Hynie · Coffee With Developers

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

1:31 min

Abstracting regulatory compliance and fraud prevention behind interfaces

Arik Shtilman · World Congress 2023

Videos

See all

Related articles

See all