ICT Risk & Incident Manager
- Hiring from
- Cyprus
- Work type
- Hybrid
- Posted
- Sep 28, 2026
About Direct Crypto Limited
Direct Crypto Limited is a newly established Crypto-Asset Service Provider (CASP) within the Wirex Holdings Ltd group, headquartered in Cyprus.
We are building a compliance-first, institutionally focused crypto infrastructure platform, providing safekeeping, exchange, and transfer services to regulated financial institutions, fintechs, and Web3 businesses across the EEA.
This is an opportunity to join a new entity at an important stage of its development and contribute to building its culture, processes, and operational standards from the ground up.
The Role
We are looking for an ICT Risk & Incident Manager to join our Engineering & Infrastructure team in Cyprus.
In this role, you will act as the first line of defence for ICT risk management at the local entity level. You will work closely with the Global ICT Risk Manager and Group teams to ensure that ICT risks are identified, assessed, documented, monitored, and appropriately managed.
You will also coordinate the local response to significant ICT incidents and support regulatory incident reporting where required.
This is a hands-on and coordination-focused role, working closely with Compliance, Security, Infrastructure, Engineering, Operations, and Product teams.
ICT Risk Management
- Own and coordinate day-to-day ICT risk management activities for the local entity.
- Maintain the ICT risk register, ensuring risks are properly identified, assessed, documented, and monitored.
- Ensure each risk has an assigned owner, mitigation plan, target date, and current status.
- Track remediation activities and escalate overdue or material risks.
- Coordinate ICT risk assessments covering systems, services, vendors, projects, and significant technology changes.
- Support risk acceptance and exception processes.
- Provide regular ICT risk reporting to management and relevant governance forums.
Policies & Governance
- Support the implementation of Group ICT risk policies, standards, and procedures at the entity level.
- Maintain entity-specific ICT policies, procedures, and supporting documentation where required.
- Identify gaps between Group policies and local regulatory requirements and coordinate their resolution.
- Ensure ICT governance documentation and supporting evidence are maintained and audit-ready.
- Support local governance committees and management reporting on ICT risk matters.
Regulatory & Compliance
- Support compliance with applicable ICT and operational resilience requirements, including MiCA, DORA, and CySEC obligations.
- Support regulatory assessments, audits, inspections, and information requests relating to ICT risk.
- Coordinate remediation of ICT-related regulatory findings and observations.
- Maintain accurate records of ICT controls, risk assessments, governance activities, and remediation actions.
- Work closely with Compliance to ensure regulatory requirements are reflected in local ICT risk processes.
Incident Management
- Support the entity-level ICT incident management process.
- Ensure significant ICT incidents are identified, classified, documented, and escalated appropriately.
- Coordinate local responses to significant ICT incidents with relevant Group and local teams.
- Ensure business and technical owners remain accountable throughout the incident lifecycle.
- Track remediation actions, root cause analysis, and post-incident follow-up through to completion.
- Maintain accurate incident records and supporting evidence.
Regulatory Incident Reporting
- Support the assessment of ICT incidents against applicable regulatory reporting thresholds under DORA, MiCA, and CySEC requirements.
- Coordinate with Compliance and the Global ICT Risk Manager on regulatory notifications and reporting.
- Support the preparation of initial, intermediate, and final regulatory incident reports where required.
- Track reporting deadlines and ensure supporting evidence is available.
- Support follow-up activities and regulatory engagement resulting from significant or reportable incidents.
Group Coordination
- Act as the primary ICT risk point of contact for Direct Crypto Limited.
- Maintain close collaboration with the Global ICT Risk Manager.
- Ensure local ICT risk activities remain aligned with Group methodologies, policies, controls, and reporting standards.
- Escalate significant ICT risks, incidents, and regulatory concerns in a timely and structured manner.
- Provide entity-level risk information for Group reporting and assessments.
- Support the implementation of Group ICT risk initiatives at the local entity level.
Essential Requirements
- Based in Cyprus.
- Professional working proficiency in Greek, both written and verbal.
- Professional working proficiency in English, both written and verbal.
- Experience in ICT risk management, technology risk, information security, operational risk, or technology compliance.
- Solid understanding of ICT risk management frameworks, controls, and risk registers.
- Experience maintaining risk registers, policies, remediation plans, and governance documentation.
- Practical understanding of ICT incident management, including escalation, classification, and post-incident reviews.
- Ability to collaborate effectively with Compliance, Security, Technology, Operations, and business teams.
- Strong analytical, documentation, coordination, and communication skills.
- Ability to work independently, manage multiple priorities, and operate effectively in a fast-moving environment.
Nice to Have
- Familiarity with MiCA and DORA, particularly ICT risk and operational resilience requirements.
- Knowledge of Cyprus financial services regulation and CySEC supervisory expectations.
- Experience with ISO/IEC 27001, PCI DSS, NIST, or equivalent frameworks.
- Experience in third-party ICT risk, outsourcing governance, or vendor due diligence.
- Experience supporting regulatory incident reporting or regulatory audits.
- Previous experience in financial services, fintech, payments, or crypto.
- Professional certifications such as CRISC, CISM, or CISA are desirable but not required.
How You Work
We’re looking for someone who is:
- Proactive and organized: Takes ownership and follows through.
- Detail-oriented: Understands the importance of accurate and complete documentation in a regulated environment.
- Collaborative: Works effectively across local and Group teams.
- A clear communicator: Able to explain ICT risk topics to both technical and non-technical stakeholders.
- Calm under pressure: Able to coordinate effectively during incidents and tight deadlines.
- Improvement-focused: Continuously looks for ways to strengthen ICT risk practices.
- Quality-driven: Takes pride in maintaining high standards in a compliance-first environment.
What We Offer
- Flexible working hours with hybrid working options.
- Annual training allowance and professional development support.
- Financial support towards relevant professional certifications.
- The opportunity to help build a MiCA-regulated entity from the ground up.
- Career growth opportunities within an innovative, globally regulated FinTech group.
Why Join Direct Crypto Limited?
This is more than a traditional compliance role. You will join at an early stage of the entity's development and have the opportunity to help build the compliance and financial crime framework that will underpin its regulated operations.
Your work will have a direct impact on how Direct Crypto Limited operates, manages risk, meets regulatory expectations, and builds trust with institutional clients and partners across the EEA.
Equal Opportunity
Direct Crypto Limited is an equal opportunity employer. We value diverse perspectives and are committed to creating an inclusive and professional working environment.