412,158open jobs
14,541companies
72,770added this week
Browse all
Salary
$116k – $217k per year (Estimated)
Location
Remote/Hybrid (London, United Kingdom)
Seniority
Architect · 8+ years exp
Overview
Company
Impact
Profile match
Capital.com is a global fintech company and online trading platform headquartered in Limassol, Cyprus, and founded in 2016. The company provides access to over 5,500 financial instruments including contracts for difference (CFDs) on stocks, indices, commodities, forex, and cryptocurrencies. It operates internationally with offices in London, Melbourne, Warsaw, and Dubai, serving over three million registered accounts through its proprietary AI-powered web and mobile platforms.

The Head of Risk will be the accountable risk leader for the UK entity, responsible for ensuring that all material risks affecting UK clients, regulatory posture, and operational resilience are identified, assessed, monitored, and reported effectively. This is a broad role covering financial risk (excluding direct dealing oversight), operational risk, conduct risk, and third party/outsourcing risk.

A defining characteristic of this role is its operating model. Many core risk functions are delivered by the Group Risk team on an outsourced or shared services basis. The Head of Risk does not need to build and staff every capability locally. Instead, they must be skilled at managing outsourced service delivery: defining what the UK entity requires, holding Group Risk accountable for quality and timeliness, identifying gaps or conflicts between Group delivery and UK regulatory obligations, and escalating where service levels or outputs fall short.

This creates a dual mandate. The role holder must be a credible, senior risk professional who can engage substantively with risk content (frameworks, stress tests, MI, regulatory submissions). They must also be an effective governance operator who can manage intra group outsourcing relationships with the same rigour the FCA would expect for any outsourced critical or important function.

The role reports directly to the UK CEO with a functional dotted line to the Group CRO. The Head of Risk will be the primary risk voice in UK governance forums and the lead point of contact for FCA supervisory engagement on risk matters.

Responsibilities

    UK Risk Accountability and Framework Ownership

    • Own the UK enterprise risk management framework end to end, ensuring it is proportionate, current, and aligned with FCA expectations under SYSC, PRIN, and Consumer Duty

    • Maintain the UK Risk Register with clear ownership, assessment methodology, defined review cycles, and escalation triggers

    • Own the UK risk management framework and RAS, translating Group risk appetite into UK specific decision boundaries that reflect local regulatory constraints

    • Provide independent 2nd line oversight and challenge to 1st line risk owners across operations, technology, client services, and commercial functions (excluding dealing, which reports separately)

    • Outsourced Risk Service Management

      • Act as the intelligent client for risk services delivered by the Group Risk team, including but not limited to: market risk monitoring, credit/counterparty risk assessment, quantitative risk modelling, stress testing, and risk MI production

      • Define and document what the UK entity requires from Group Risk in terms of scope, quality, timeliness, and regulatory standard, formalised through an intra group service level framework or equivalent

      • Monitor and challenge the quality and completeness of Group Risk outputs before they are used in UK governance forums, board packs, or regulatory submissions

      • Identify gaps between Group Risk delivery and UK specific regulatory requirements, and escalate where those gaps create risk to the UK entity’s compliance posture

      • Maintain an outsourcing risk assessment for Group Risk services consistent with FCA expectations for oversight of outsourced critical or important functions under SYSC 8

      • Ensure that the UK entity retains sufficient knowledge and capability locally to oversee outsourced risk functions, avoiding inappropriate dependency on Group without independent local scrutiny

      • Regulatory, Prudential, and Conduct Risk

        • Lead or substantively oversee the UK ICARA (Internal Capital Adequacy and Risk Assessment) process, coordinating with Group Risk and Group Finance on stress testing, scenario analysis, and capital/liquidity adequacy

        • Ensure market risk, credit/counterparty risk, and concentration risk are monitored and reported to a standard that meets MIFIDPRU requirements, whether produced locally or by Group

        • Integrate conduct risk assessment into product governance, pricing decisions, and client outcome monitoring in line with Consumer Duty (PRIN 2A)

        • Oversee operational risk including business continuity, IT resilience, and third party risk, ensuring the UK entity maintains visibility even where platforms and infrastructure are managed at Group level

        • Reporting and Management Information

          • Deliver risk MI to the UK Board, UK ExCo, and relevant governance committees on a defined cadence, with clear narrative on trends, near breaches, breaches, and required actions

          • Own and maintain Key Risk Indicators (KRIs) across all material risk domains, each with predefined thresholds and mandatory escalation actions

          • Prepare risk sections for board packs, regulatory returns, and FCA supervisory engagement materials

          • Critically assess risk MI received from Group Risk before presenting to UK governance forums, ensuring it accurately reflects UK specific exposures and is not simply a Group level aggregation

          • Stakeholder Engagement

            • Act as the primary point of contact for risk matters with the FCA during supervisory interactions, skilled persons reviews, and thematic exercises

            • Maintain effective working relationships with the Group CRO and Group Risk team, balancing collaborative alignment with independent challenge where UK interests diverge from Group priorities

            • Collaborate with the Head of Compliance (SMF16/17) to ensure clear delineation of 2nd line responsibilities with no gaps or duplication

            • Engage with internal and external auditors on risk related findings, ensuring timely remediation and structural fixes

            • Team and Capability Building

              • Build the UK risk function progressively as the office grows, identifying where local capability is needed versus where Group delivery remains appropriate

              • Embed a risk aware culture across the UK office through training, practical challenge, and visible engagement with 1st line teams

Requirements

    • Substantial experience (typically 8+ years) in risk management within FCA regulated financial services, with demonstrable exposure to CFD, spread betting, or leveraged derivatives businesses

    • Deep working knowledge of FCA regulatory expectations for risk management under SYSC, PRIN, Consumer Duty (PRIN 2A), and MIFIDPRU prudential requirements

    • Proven experience managing outsourced or shared service risk functions, including defining service requirements, monitoring delivery quality, and escalating shortfalls. This is a critical differentiator for this role

    • Experience designing and operating enterprise risk frameworks including risk registers, risk appetite statements, KRI frameworks, and ICARA/ICAAP processes

    • Strong understanding of financial risk (market, credit/counterparty, liquidity), operational risk, and conduct risk in the context of a retail leveraged trading platform

    • Experience preparing and critically reviewing risk MI for boards and senior governance forums, including the ability to identify where MI masks underlying issues

    • Experience engaging with the FCA in a supervisory context, whether directly or as a substantive contributor to supervisory dialogue

    • Understanding of the 3 lines of defence model and comfort operating independently within a structure where many 2nd line services are delivered centrally by a Group function

    • Strong governance instincts: the ability to distinguish between aligned Group support and inappropriate delegation of UK regulatory accountability

    • Desirable

      • Experience with FCA expectations for oversight of outsourced critical or important functions under SYSC 8 and the FCA’s broader outsourcing and third party risk guidance (FG16/5)

      • Experience with CASS client money and asset requirements, particularly CASS 7 and CASS 6 audit processes

      • Familiarity with the Complaints, Claims, and Indemnity (CCI) regime under PS25/20

      • Professional qualifications: IRM Certificate/Diploma, FRM, PRM, or equivalent

      • Experience within a multi entity group structure where local regulatory obligations must be balanced against Group efficiency and standardisation pressures

      • Proficiency with risk analytics tools including Python/R for quantitative analysis and Tableau for risk dashboards

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
412,158 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
London
Remote/Hybrid • Full-Time • Krasnodar
Python
SQL
PowerShell
Databases
MS SQL
Firebird
DevOps
Zabbix
Yandex Cloud
Windows Server
Grafana
Proxmox VE
Apply
Remote • 2+ years exp • Moscow
Python
Java
SQL
Java
Liquibase
Databases
PostgreSQL
ClickHouse
AI/ML
Airflow
DevOps
GitLab CI
CI/CD
Jenkins
Git
SLI/SLO/SLA
GitLab
Analytics
ETL/ELT
Management
Confluence
Jira
Apply
In office • Full-Time • 5+ years exp • Pune
Python
JavaScript
Java
Node JS
Bash
Java
Maven
DevOps
Terraform
Puppet
Ansible
GCP
CloudFormation
Azure
CI/CD
Jenkins
Git
AWS
Docker
Configuration Management
GitHub
Apply
In office • Moscow
Python
PowerShell
Databases
PostgreSQL
MS SQL
DevOps
Zabbix
Proxmox VE
Hyper-V
Apply
In office • 6+ years exp • PhD
Python
Go
DevOps
Terraform
GCP
GitHub Actions
Azure
CI/CD
GitOps
AWS
AWS Lambda
GitHub
Cybersecurity
Threat Modeling
Apply
Security Architect 6 days ago
$71k – $132k per year (Estimated) • Remote/Hybrid • 8+ years exp • Warsaw
Cybersecurity
ISO 27001
PCI DSS
Apply
$39k – $92k per year (Estimated) • Remote/Hybrid • 7+ years exp • Bachelor's Degree • São Paulo
Apply
$42k – $99k per year (Estimated) • Remote/Hybrid • 2+ years exp • Bachelor's Degree • Melbourne
Apply
Senior Recruiter 26 days ago
$26k – $61k per year (Estimated) • Remote/Hybrid • Sofia
Apply
$19k – $48k per year (Estimated) • Remote/Hybrid • 3+ years exp • Sofia
Cybersecurity
GDPR
Apply
$52k – $113k per year (Estimated) • In office • 3+ years exp • Bachelor's Degree • London
AI/ML
Copilot
DevOps
Incident Management
Cybersecurity
Microsoft Entra ID
Management
Outlook
Apply
$131k – $270k per year (Estimated) • In office • Bachelor's Degree • London
DevOps
Configuration Management
Management
ServiceNow
Apply
$41k – $112k per year (Estimated) • In office • London
Management
Outlook
Apply
$78k – $188k per year (Estimated) • In office • London
Management
Outlook
Apply
$44k – $96k per year (Estimated) • In office • 2+ years exp • London
Apply
See all jobs
This is one of many
412,158 more open roles from verified company boards, updated every day.