Director - Enterprise Risk
CoinDCX · Bengaluru
- Experience8–9 yrs
- SalaryNot disclosed
- Work modeonsite
- Levelexecutive
- Posted17 Sept 2026
About CoinDCX
CoinDCX is hiring in Bengaluru in financial services. This role looks for around 8+ years of experience.
Skills
- Enterprise Risk Management
- Risk Governance
- Regulatory Consulting
- RCSA
- GRC platforms
- Crypto Regulatory Compliance
- Token Risk
- DeFi Risk
- Risk Reporting
- Board Governance
The role
An enterprise risk manager at a crypto financial services company establishes enterprise risk management frameworks and governs token and DeFi exposures through RCSA, COSO, and ISO 31000, producing board-ready risk reporting. The role applies regulatory risk expertise and GRC platforms to coordinate custody, technology, market, credit, and compliance risk.
Full job description
The CoinDCX Journey: Building the Future of Finance:
At CoinDCX, our mission is clear - to make crypto and blockchain accessible to every Indian and enable them to participate in the future of finance.
As India’s first crypto unicorn valued at $2.45B, we are reshaping the financial ecosystem by building safe, transparent, and scalable products that power adoption at scale.
We believe that change starts together. It begins with bold ideas, relentless execution and people who want to build what’s next.
If you’re driven by purpose and thrive in environments where your work defines the next chapter of an industry, you’ll feel right at home here.
About the Role:
This role owns CoinDCX's Enterprise Risk Management framework end to end — the Risk Appetite Statement, the enterprise risk register, the quarterly Risk Control Self-Assessment (RCSA) process, and the consolidated Board risk report. You'll bring Market, Credit, Technology, and Quant risk together into one coherent view for the CRO and the Board each quarter, and you'll run the RCSA cycle that gets every risk-owning team to formally assess their own controls on a fixed schedule, rather than waiting for a problem to surface one. You'll set risk policy for Web3, Token, and DeFi exposure, including Okto, and bring fiat and VDA custody risk together into a single reporting line. You'll work closely with every other Risk hire and with Compliance, Treasury, and InfoSec to keep the framework grounded in what's actually happening across the business.
What You’ll Do:
Ongoing / BAU
Maintain and operationalize the Enterprise Risk Management framework across all 1st and 2nd line functions, including the Risk Appetite Statement and the traffic-light escalation ladder (Green/Amber/Red/Black). Run the quarterly RCSA cycle — each risk-owning team formally assesses the design and operating effectiveness of its own controls against the enterprise risk register, with findings, ratings, and remediation owners tracked to closure. Chair the Token Listing & Protocol Risk review, holding second-line sign-off authority over new asset listings, bridge exposures, and DeFi/Okto integrations before launch. Consolidate quarterly risk exposure reporting and the Board Risk Committee deck — Market/Credit, Technology, Compliance, Quant, and RCSA findings, plus a single consolidated custody risk line combining the AVP's fiat review and the Technology Director's VDA review. Partner with Compliance/Legal on regulatory filings and statutory governance deliverables that draw on the ERM framework and RCSA evidence — Compliance owns the filing; this role owns the underlying framework and evidence trail.
Tentative Deliverables — 3 Months
Draft the first consolidated Enterprise Risk Register and Risk Appetite Statement, using the CoinDCX ERM Framework's taxonomy and appetite tiers as the starting structure, with metrics defined across all risk categories including custody. Design the RCSA methodology — the assessment template, control-rating scale, and cadence every risk-owning team will be evaluated against, modelled on the approach used in the BitOasis framework. Inventory every risk model currently in use across the business — feeds directly into the Risk Analytics Director's validation backlog. Inventory existing token-listing diligence practices and draft a standardized second-line Token Risk Assessment framework. Meet with each of the other four Risk hires plus Compliance, InfoSec, Treasury, and Trade Operations to map ownership — including the fiat/VDA custody split — and draft an initial RACI.
Tentative Deliverables — 6 Months
Secure Board sign-off on the Risk Appetite Statement and traffic-light escalation limits. Run the first company-wide RCSA cycle across every functional business unit, with findings rated, owned, and tracked — not just collected. Deliver the first consolidated Board Risk Pack, including RCSA results and, for the first time, the joint fiat + VDA custody risk line. Publish an initial risk policy for token listings and Okto protocol/bridge/DeFi treasury exposure.
Tentative Deliverables — 1 Year
RCSA runs on a quarterly cadence with a demonstrated remediation track record — findings from the first cycle are closed, and the second and third cycles show fewer repeat issues. Board reporting is a repeatable quarterly process that doesn't depend on chasing inputs. Every material risk model has a documented, independent validation record, delivered in partnership with the Risk Analytics Director. Every new token listing and Okto/DeFi exposure decision is routed through a documented governance gate. Custody risk (fiat and VDA) is a standing, consolidated line in every quarterly Board report.
You’ll Excel in This Role If You:
Have 8+ years in enterprise risk management, risk governance, or regulatory consulting within a regulated financial institution, fintech, or crypto exchange. Have designed and run an RCSA (or equivalent control self-assessment) program before — you know how to get honest self-ratings out of teams who'd rather not surface their own gaps, and how to turn findings into tracked remediation, not a filed PDF. Having built or run an ERM framework before — familiarity with COSO, ISO 31000, or a comparable three-lines-of-defense model is a strong plus. Have working knowledge of the regulatory landscape relevant to crypto exchanges (VARA, MiCA, MAS, DORA) — enough to build a framework that would hold up under one of them, even though Compliance owns the actual filings. Are comfortable evaluating token/smart-contract/DeFi risk well enough to set policy, even though you won't build the underlying technical controls yourself. Have used, or can quickly learn, a GRC platform (e.g. LogicGate, MetricStream, Archer) or equivalent workflow tooling. Can turn five teams' worth of inconsistent risk reporting into one coherent, Board-ready narrative. Can hold a room of Directors and VPs accountable to a governance process without formal authority over their teams. Write clearly and concisely for a Board audience. Hold a Bachelor's or Master's degree, or equivalent experience, in Finance, Risk Management, Law, or a related field.
You’ll Know You’re Winning When:
At 6 Months
The Board has formally signed off on a Risk Appetite Statement and ERM framework that didn't exist before. The first company-wide RCSA cycle is complete, with every finding rated and assigned an owner. Every candidate token listing is evaluated against the standardized second-line Token Risk framework before launch. The first consolidated Board risk report has been delivered on schedule — including a joint fiat + VDA custody risk line.
At 12 Months
RCSA runs on a quarterly cadence with a visible drop in repeat findings — teams are fixing what the last cycle surfaced, not re-surfacing it. Board reporting runs on a quarterly cadence without you chasing inputs from other teams. Every material model has a documented validation record. The token listing / Okto governance gate is in active, routine use. Custody risk is a standing quarterly fixture in Board reporting.
Scope, Ownership & Boundaries (cross-referenced to the Risk Architecture)
You own: the Risk Appetite Statement, enterprise risk register, the RCSA program — methodology, cadence, and remediation tracking, not just running it once — and consolidated Board reporting (BitOasis's RO-style quarterly cadence; CoinDCX ERM and RACI); Web3/Token/Okto/DeFi risk policy (CEX Risk Architecture, Pillar 5 — Protocol & Token Listing Risk); the consolidated custody risk line in Board reporting, bringing together the AVP's fiat custody review and the Technology Director's VDA custody review into one view. You do not own: execution of individual risk domains — Technology, Financial/Liquidity, and Quant/Fraud sit with the other three hires, and that includes the underlying fiat and VDA custody reviews themselves: you consolidate and report the findings, you don't run the reviews; day-to-day Compliance/AML program ownership and regulatory filings, which stay with Compliance/Legal — you own the framework and RCSA evidence trail those filings draw on, not the filing itself; actual model-building and validation execution, which the Risk Analytics Director owns (you own the requirement that it happens on schedule, and RCSA is one of the mechanisms that surfaces whether it did).
Why This Role Matters & What’s In It For You:
You gain the unique opportunity to establish the definitive "single source of truth" at scale, moving beyond mere reporting to drive high-stakes innovation in the Web3 space. This is a platform to exercise true ownership, where you will solve industry-defining challenges and elevate the organization's analytical maturity through visionary leadership and continuous analytical evolution.
Hiring Process:
Here’s what your journey with us looks like:
Application Review – We assess for skills, alignment, and intent Recruiter Connect – A short conversation to understand you better Functional Round(s) – Deep dive into your approach, craft, and problem-solving Assignment / Simulation Round – A take-home task or live problem-solving exercise to understand how you think and execute in real scenarios Culture & Values Discussion – A conversation to understand our ways of working and how you thrive best Founder Conversation (Optional) – For certain roles and senior levels, you may meet our founders to explore strategic alignment and long-term fit
Where We Work:
We believe the best ideas emerge when people build together. Collaboration, speed and trust come alive when teams share the same space.
With this belief, we operate as a work-from-office organisation. This role is based out of our Bangalore office, where energy, alignment and innovation move in real time.
Perks That Empower You:
We believe great people deserve great experiences.
Design Your Own Benefits: Flexible perks to match your lifestyle Unlimited Wellness Leaves: Rest and recharge as you need Mental Wellness Support: Access to therapy and wellness resources Learning Sessions: Bi-weekly learning and growth opportunities
Ready to Build What’s Next?
If you’re looking for a role that gives you direct access to high-stakes decisions, deep impact and a chance to build the future of finance, this is it.
Join CoinDCX and help us make crypto accessible to every Indian, together.