KOHO logo
KOHO

A quickly scaling Fintech that helps Canadians gain control over their money with a no-fee spending and savings account.

Director, Operational Risk Management

RiskRiskFull TimeRemoteLeadTeam 201-500Since 2014H1B No SponsorCompany SiteLinkedIn

Location

Canada

Posted

9 days ago

Salary

$180K - $210K / year

Seniority

Lead

Bachelor Degree10 yrs expEnglish

Job Description

Director, Operational Risk Management

KOHO

• Lead and evolve KOHO’s operational risk management framework and practices aligned with applicable OSFI Guidelines (E-21, B-10, E-13) and banking industry standards. • Own the end-to-end development and implementation of a Second Line Controls Testing program, including methodology, governance, and reporting standards. • Provide regular and comprehensive operational risk profile reporting to Senior Management, committees and/or forums. • Identify emerging operational risks and trends and develop implementation strategies. • Conduct regular operational risk assessments across the business and operations. • Provide strategic oversight of operational risk issues, events, and root cause analysis to ensure timely identification and remediation of control deficiencies. • Design and execute a risk-based controls testing strategy to independently assess the design effectiveness, operating effectiveness, and control suite coverage of First Line controls across business units. • Drive lessons learned and thematic reviews to prevent issue recurrence and strengthen the control environment. • Establish and maintain operational risk appetite metrics, thresholds, and escalation protocols. • Collaborate cross-functionally with Risk Management, Compliance, and Internal Audit to ensure integrated risk coverage and oversight. • Build and lead a high-performing risk team that scales with growth. • Build strong relationships with First Line business partners, acting as trusted advisor and constructive challenger. • Drive risk culture and awareness initiatives across the organization through training, communication, and engagement programs. • Leverage advanced analytics, artificial intelligence (AI), and machine learning (ML) capabilities to enhance risk identification, monitoring, and predictive insights. • Stay current on industry trends, RegTech solutions, and best practices in operational risk innovation, bringing forward recommendations to enhance the function. • Foster a culture of innovation within the team, encouraging experimentation and the adoption of new approaches to solve complex risk challenges.

Job Requirements

  • 10+ years of progressive experience in operational and enterprise risk management, controls testing, internal audit, or compliance within financial services.
  • Deep knowledge in operational and compliance risk frameworks and possess a solid understanding of the connectivities across non-financial risk domains (compliance, third party, business continuity, tech/cyber, etc.)
  • Strong understanding of the Three Lines of Defense model and regulatory expectations
  • Experience in regulated fintech, neobank, or direct-to-consumer financial institutions.
  • Strategic thinker with the ability to translate complex risk concepts into an actionable and practical approach to execution.
  • Passionate about innovation, inclusion, and empowering financial wellness.

Benefits

  • Opportunity to shape the future of fintech and financially empower a generation of Canadians
  • Competitive compensation & equity
  • Fantastic, Deeply Engaged Team
  • Generous vacation + Wellness days + Flex Days + holiday closure
  • Remote-first environment + coworking support + yearly all hands retreat
  • Access to coaching & growth programs
  • Parental top-up & leave policies
  • Comprehensive health benefits
  • Power-up budgets for books, home office setup, phone & internet, AI tools, and professional development

Related Categories

Related Job Pages

More Risk Jobs

CNA Insurance logo

Risk Control Consultant

CNA Insurance

CNA (NYSE: CNA) is a leading commercial property and casualty insurance company serving the global business community.

Risk9 days ago
Full TimeRemoteTeam 5,001-10,000Since 1897H1B No Sponsor

• Perform workplace/work site risk evaluation and consultative risk improvement services • Provides risk assessment information on complex accounts • Develops and conducts education, training, and presentations

Ohio
Tenpo logo

Analista de Riesgo Operacional

Tenpo

Tenpo | Una cuenta muy tú. Ya somos más de 2.2MM de clientes, únete 🚀 💚.

Risk9 days ago
Full TimeRemoteTeam 51-200H1B No Sponsor

• Apoyar la identificación, análisis y monitoreo de riesgos tecnológicos de Tenpo. • Contribuir a la implementación de controles efectivos. • Elaboración de reportes regulatorios. • Desarrollar una cultura de riesgo alineada a la normativa CMF y los estándares de Basilea. • Evaluación de riesgos operacionales y tecnológicos. • Desarrollar e implementar mejoras a los procesos internos de evaluación de riesgo tecnológico. • Mantener un catálogo de riesgo tecnológico. • Promover y coordinar los planes de mitigación y gestión de requerimientos. • Elaborar reportes periódicos sobre el estado de los riesgos tecnológicos.

Chile

Technical Leader II - Nuclear Risk Assessment and Applications

EPRI

EPRI participates in E-Verify, an online system operated jointly by the Department of Homeland Security and the Social Security Administration (SSA). EPRI uses the system to check the work status of new hires by comparing information from the employee's I-9 form against SSA and Department of Homeland Security databases. EPRI is an equal opportunity employer. EEO/AA/M/F/VETS/Disabled Together . . . Shaping the Future of Energy. www.epri.com

Risk9 days ago

Role Description EPRI seeks an experienced engineer with expertise in Probabilistic Risk Assessment (PRA), risk-informed applications, and nuclear safety analysis to support research and member programs within the Nuclear Risk and Safety Management area. The successful candidate will contribute to research involving internal events, internal flooding, external hazards, and emerging PRA applications for existing and advanced nuclear power plants. This role provides an opportunity to work across a broad range of PRA disciplines while helping shape the next generation of risk-informed decision support capabilities for the nuclear industry. - Support and lead research projects involving probabilistic risk assessment, risk-informed applications, and nuclear safety analysis. - Contribute to EPRI's internal flooding PRA research program, including member support, technology transfer, methodology development, and application of industry guidance. - Support development, maintenance, quantification, and application of PRA models addressing internal events, flooding, external hazards, and integrated risk assessments. - Utilize EPRI's Integrated Risk Toolkit (IRT) and other PRA software tools to support member applications and research initiatives. - Apply PRA insights to support risk-informed decision making, online maintenance, configuration risk management, operational risk assessments, and emerging applications. - Collaborate with utilities, regulators, vendors, consultants, and industry organizations to identify emerging technical needs and develop practical research solutions. - Support technical workshops, training activities, and knowledge transfer initiatives. - Contribute to proposals, business development activities, and strategic planning for future PRA research programs. - Evaluate and apply modern analytical, automation, and AI-enabled tools to improve engineering productivity, technical communication, knowledge management, and member value. Qualifications - Bachelor's degree in Engineering (Nuclear Engineering preferred). - Approximately 5–10 years of experience supporting PRA model development, PRA applications, nuclear safety analysis, or risk-informed engineering activities. - Working knowledge of PRA methods, including fault tree analysis, event tree analysis, risk quantification, and PRA applications. - Familiarity with one or more PRA technical areas, including internal events, internal flooding, fire PRA, seismic PRA, external hazards, reliability analysis, or risk-informed applications. - Strong analytical, problem-solving, and communication skills. - Ability to work independently and effectively engage with technical stakeholders. Requirements - Experience with internal flooding PRA methodologies and applications. - Familiarity with the ASME/ANS PRA Standard and PRA peer review processes. - Experience using EPRI's Integrated Risk Toolkit (IRT), CAFTA, RiskSpectrum, SAPHIRE, or equivalent PRA tools. - Experience supporting risk-informed applications, configuration risk management, online maintenance, operational risk assessments, or risk-informed decision making. - Experience supporting advanced reactor or SMR safety assessments. - Experience using modern analytical and productivity tools, including Python, data analytics, automation tools, generative AI platforms, engineering knowledge management tools, or digital engineering environments. - Demonstrated ability to improve engineering productivity, technical communication, or technical workflows through effective use of analytical, automation, or AI-assisted tools. - Experience supporting technical training, technology transfer, mentoring, or workforce development activities. Benefits - The salary range for this position is $138,000 USD to $150,000 USD annually. - This role is eligible to participate in EPRI’s annual incentive program. - This role is eligible to participate in EPRI’s standard employee benefit programs, which currently include medical, dental, vision, 401k, STD/LTD and paid family leave, life and accident insurance, paid time off (flexible vacation, sick leave, and holiday pay). Company Description EPRI participates in E-Verify, an online system operated jointly by the Department of Homeland Security and the Social Security Administration (SSA). EPRI uses the system to check the work status of new hires by comparing information from the employee's I-9 form against SSA and Department of Homeland Security databases. EPRI is an equal opportunity employer. EEO/AA/M/F/VETS/Disabled Together . . . Shaping the Future of Energy. www.epri.com

United States
$138K - $150K / year

Senior Risk Advisory GRC Consultant

Echelon Risk + Cyber

We are committed to creating an inclusive environment for our team with unquestioned integrity. One of our core values is "People with Personality," and we want to allow you the space to bring your full self to work. We value a diverse workforce and a culture of inclusivity and belonging. All employment decisions shall be made without regard to age, race, creed, color, religion, gender, national origin, ancestry, disability status, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, citizenship status, or any other basis as protected by federal, state, or local law. Echelon Risk + Cyber is an Equal Opportunity Employer.

Risk9 days ago

Role Description We seek a highly skilled and experienced Senior Risk Advisory GRC Consultant to join our dynamic team at Echelon Risk + Cyber, a leading cybersecurity consulting firm. This team member will be passionate about cybersecurity and ready to use their knowledge to be an Entrepreneurial Problem Solver and work alongside their Echelon team members to build creative solutions. As a Senior Risk Advisory GRC Consultant, you will: - Lead client engagements focused on information security, compliance, and risk management across frameworks such as SOC 2, ISO 27001, PCI DSS, HITRUST, HIPAA, and CMMC. - Serve as a trusted advisor to clients, helping them assess security risks, strengthen control environments, achieve compliance objectives, and improve overall cybersecurity maturity. - Manage multiple engagements, provide strategic guidance, mentor junior team members, and deliver high-quality consulting services. - Build strong client relationships and contribute to the growth of the practice. This is a remote position from anywhere in the USA. Qualifications - 5–7 years of hands-on experience in IT audit, compliance, cybersecurity consulting, or GRC advisory services. - Significant experience leading SOC 2 Type I/II audits, ISO 27001 assessments, and related attestation engagements. - Deep understanding of IT General Controls (ITGCs), Trust Services Criteria, and audit standards such as SSAE 18 and ISAE 3402. - Proven ability to lead risk assessments, compliance reviews, readiness evaluations, and remediation programs across frameworks. - Strong analytical and problem-solving skills. - Excellent communication, presentation, and stakeholder management skills. - Strong project and engagement management skills. - Demonstrated experience mentoring junior team members. - Prior experience at a Big 4 firm, mid-tier CPA/advisory firm, cybersecurity consulting firm, or boutique IT audit/attestation practice is strongly preferred. Requirements - Applicants must have authorization to work in the United States without current or future visa sponsorship. Preferred Qualifications - Certified in one or more of the following: CISA, CIA, CPA, CISSP, and/or ISO 27001 Lead Auditor. - Extensive experience leading the incident response lifecycle. - Experience developing project plans, engagement roadmaps, staffing models, and delivery timelines. - Proven track record leading high-volume SOC 2 and ISO 27001 engagements. - Experience with government and regulated-industry compliance frameworks. - Experience managing client relationships and contributing to business development initiatives. Benefits - Access to medical, dental, and vision insurance through Cigna, with the majority of the employee cost covered by the employer. - Employer funding to HSA accounts and FSA access. - Access to a 401(k) through Vanguard with a guaranteed employer contribution. - Flexible vacation policy that allows you to manage your schedule. - 11 holidays with flexibility based on what is important for you and those you love. - Employer-paid short-term and long-term disability, employer-paid life insurance, and access to additional life insurance. - Support for individual development through certifications, continued learning, conferences, and more. Company Description Echelon Risk + Cyber is committed to creating an inclusive environment for our team with unquestioned integrity. We value a diverse workforce and a culture of inclusivity and belonging. All employment decisions shall be made without regard to age, race, creed, color, religion, gender, national origin, ancestry, disability status, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, citizenship status, or any other basis as protected by federal, state, or local law. Echelon Risk + Cyber is an Equal Opportunity Employer.

United States