Head of Risk UK (Crypto)
capital.comAs the Head of Risk UK (Crypto), you will build and lead the independent second line risk function for Capital Vault UK (CVUK), the FCA registered crypto-asset business of Capital Vault Group. This is a dual-hat role.
Alongside the CVUK mandate, you will act as deputy to the Group Head of Risk and take primary ownership of building the Group's financial and prudential risk framework which will be applied across the Group's regulated entities as they are onboarded.
You will report to the Group Head of Risk, set the local risk direction, maintain the risk appetite within Group boundaries, and ensure the business operates within approved limits while it scales.
This position carries regulatory responsibilities and is expected to be subject to FCA fit and proper assessment, with senior management accountability expected to formalise as the UK cryptoasset regime transitions into the FSMA authorisation framework. You will be accountable for risk governance, effective oversight of prudential and market risks, and ensuring growth is matched by strong controls, clear escalation, and Board level visibility.
Responsibilities
-
Strategic Risk Leadership: Own and drive the CVUK risk strategy, aligned with the Group risk strategy, the business plan, and FCA expectations. Set and maintain the local risk appetite within the boundaries of the Group Risk Appetite Statement
-
Financial and Prudential Risk (group ): Own and lead the Group's financial and prudential risk framework - credit, liquidity, capital, cost, market, and concentration risk. Lead the Group and entity ICARA (or equivalent) processes end to end, including capital planning and wind down planning.
-
Stress Testing and Scenario Analysis: Design and lead the stress testing programme covering crypto market shocks, client behaviour, liquidity withdrawal, counterparty failure, and operational disruption.
-
Counterparty and Credit Risk: Set and monitor risk limits for crypto liquidity providers, exchanges, custodians, and banking partners. Oversee counterparty due diligence, concentration risk, and contingency planning for counterparty disruption.
-
Custody and Safeguarding Risk: Provide second line oversight of crypto-asset custody arrangements, key management, client asset safeguarding, and on-chain settlement risk.
-
Operational Risk and Controls: Oversee the CVUK RCSA cycle, incident and issue management, control testing, and KRI monitoring in the Group GRC platform.
-
Technology and Resilience Risk: Provide oversight of operational resilience, cybersecurity risk, and change management, leveraging group technology risk arrangements.
-
Outsourcing and Third Party Risk: Oversee CVUK's critical third party arrangements, including custody, cloud, and blockchain analytics providers. Ensure robust due diligence, ongoing monitoring, and exit plans.
-
Monitoring and Reporting: Maintain the CVUK risk register and KRIs. Deliver decision ready reporting to the CVUK Board and Audit and Risk Committee, including appetite breaches, emerging risks, incidents, and remediation progress.
-
Regulatory Alignment: Maintain close relationships with the FCA and support regulatory submissions, inspections, and remediation of findings. Ensure audit readiness and disciplined evidence management.
Requirements
-
Crypto-Assets & Digital Assets (essential): Proven, hands-on experience with crypto-assets and digital assets is required for this role.
-
Education & Experience: Experience in risk management within regulated financial services, with required, demonstrable depth in financial and prudential risk — credit, liquidity, capital, market, concentration, and cost risk. Brokerage or trading platform experience is an advantage.
-
Regulatory Knowledge: Strong expertise in FCA requirements, including the UK cryptoasset regime, prudential frameworks (IFPR, ICARA or ICAAP). Prior FCA approval or fit and proper clearance is a strong advantage.
-
Outsourced Service Management: Proven experience managing outsourced or shared service risk functions: defining service requirements, monitoring delivery quality, and escalating shortfalls. This is a critical differentiator for this role.
-
Governance: Proven experience engaging with Boards and committees, managing escalation processes, and supporting regulatory inspections and audits.
-
Technical Strength: Strong command of capital adequacy, liquidity and market risk, stress testing and scenario design, wind down planning, and counterparty risk. Understanding of crypto market structure, custody models, and on-chain risk is highly valued.
-
Leadership: Proven ability to build and lead an independent risk function in a fast-paced environment, deputise credibly at group level, and challenge senior stakeholders with clarity and discipline.
-
Integrity: High ethical standards, independence of judgment, and ability to meet FCA fit and proper expectations. Professional risk qualifications (FRM, PRM, CFA) are an advantage.