ERM Program Manager
Job Details
- Experience
- Approximately 5 –10 years of experience in operational risk, Enterprise Risk Management (ERM), Governance, Risk, and Compliance (GRC), or compliance program management within a regulated financial institution, fintech, broker-dealer, or capital markets environment.
Requirements
- Approximately 5–10 years of experience in operational risk, ERM, GRC, or compliance program management in a regulated financial institution, fintech, broker-dealer, or capital markets environment.
- Demonstrated hands-on experience managing risk registers from intake and assessment through mitigation tracking and executive reporting.
- Strong understanding of risk identification, inherent and residual risk scoring, mitigation planning, risk ownership, and ongoing monitoring.
- Practical experience using GRC platforms to manage risk registers, workflows, controls, assessments, and reporting.
- Ability to coordinate and influence stakeholders across Legal, Compliance, Finance, Product, Security, and Operations without direct reporting authority.
- Familiarity with SEC and FINRA requirements, or equivalent experience in a regulated financial services environment.
- Written communication skills to develop risk statements, executive summaries, structured risk tables, and board-ready materials.
- Experience tracking mitigation actions, monitoring operational risk indicators, defining KRIs, and escalating issues through governance processes.
- Strong attention to detail, sound judgment, and ability to consolidate information from multiple sources into actionable insights.
- Ability to manage multiple priorities, maintain accurate documentation, and deliver reporting within deadlines.
- Preferred: exposure to broker-dealer, clearing, or custody operations; fintech ERM; cryptocurrency or digital asset risk; or multi-entity risk consolidation.
- Preferred: familiarity with Jira Service Management, COSO ERM, or ISO 31000, and experience preparing board, risk committee, or senior leadership materials.
Responsibilities
- Manage the end-to-end ERM intake process through tickets, interviews, surveys, incident reports, and operational channels.
- Maintain functional and enterprise risk registers in the designated GRC platform, including risk owners, scores, mitigation measures, and status updates.
- Apply the established ERM risk scoring model and validate residual risk ratings with risk owners.
- Map identified risks to established Level 1 and Level 2 risk categories and enterprise risk scenarios.
- Coordinate with functional risk leads, consolidate inputs, and follow up on outstanding actions and blockers.
- Track mitigation plans, owners, target dates, and progress, and escalate overdue actions and significant exposures.
- Collaborate with data owners to define and monitor key risk indicators, including proxy metrics where needed.
- Prepare ERM reports, executive summaries, risk dashboards, and board materials.
- Support ERM Working Group meetings by preparing agendas, documenting minutes, and tracking decisions and actions.
- Coordinate quarterly risk updates across local entities and monitor emerging risks related to cryptocurrency, artificial intelligence, regulatory developments, and multi-jurisdictional operations.