Powering the next generation of global finance

Director, Enterprise Risk Management

Powering the next generation of global finance


About us

Founded in 2018, Bakkt, Inc. is a regulated financial technology company building infrastructure for the future of finance. Bakkt's platform serves financial institutions, fintechs, and consumer finance products — providing the compliance, security, and scale required to deliver trusted financial services at a global level. Through its core business pillars, Bakkt powers institutional-grade trading capabilities, AI-enabled programmable finance, and cross-border payment infrastructure.


Role Summary

We are seeking a hands-on, results-driven Director, Enterprise Risk Management to support the design, oversight, and continuous improvement of Bakkt’s Enterprise Risk Management (ERM) framework. Reporting to the Head of Risk, this is a hands-on Second Line of Defense role that will oversee and drive risk mitigation across the enterprise while supporting business-centric risk initiatives, including counterparty risk, market risk, and operational resilience.


The Director will provide strategic direction for risk programs across the firm, validate the design and implementation of First Line controls, and ensure alignment with Bakkt’s corporate strategy and regulatory obligations in the digital asset space. This is an individual contributor role with no direct reports; the Director will drive execution through cross-functional influence rather than owning First Line controls or remediation activities directly.


We are looking for a builder and creator — not an administrator. The ideal candidate is energized by embracing AI and agentic workflows to make Second Line work faster, sharper, and more scalable, and is relentlessly focused on continuous improvement in how risks are identified, tracked, and remediated.


Key Responsibilities

ERM Framework & Governance

  • Design, implement, and continuously improve the Enterprise Risk Management framework, risk taxonomy, risk registers, and risk appetite statements specific to digital assets and regulated financial services.
  • Provide strategic direction for risk mitigation and operational improvement initiatives, guiding them from conception through completion in partnership with First Line business owners.
  • Validate the design and implementation of sustainable controls established by the First Line to address identified risks, audit findings, and compliance gaps.
  • Maintain and evolve risk policies, standards, and procedures aligned with regulatory expectations (including NYDFS) and industry best practices.

Business Risk Support (Counterparty, Market & Operational)

  • Oversee and drive risk mitigation efforts related to counterparty exposure, including the assessment and ongoing monitoring of institutional partners, custodians, market makers, and liquidity providers.
  • Support business-centric risk initiatives across market risk, liquidity risk, and operational risk — providing Second Line challenge and guidance to First Line owners.
  • Partner with business and product teams on the risk-clearing process for new product launches, token listings, and partner integrations, providing independent Second Line review.

Risk Assessment & Monitoring

  • Conduct enterprise-wide risk assessments across financial, operational, strategic, and technological domains — including crypto-specific risks such as custody, stablecoin peg stability, and on-chain exposure — to evaluate enterprise risk levels.
  • Monitor emerging risks (regulatory, market, technology, and cyber) and provide early warning and recommended actions to the Head of Risk and executive team.

Remediation Oversight

  • Oversee and drive risk mitigation tied to audit findings, regulatory exam observations, and self-identified issues, holding First Line owners accountable for execution and sustainability.
  • Validate the design and implementation of remediation actions, track progress to closure, and report status to leadership and the Risk Committee of the Board.

Change Management & Cross-Functional Influence

  • Lead change management associated with ERM transformations, supporting smooth adoption of new risk policies, frameworks, and systems across the enterprise.
  • Partner with department heads, Legal, Compliance, Internal Audit, Finance, and Technology/Product teams to coordinate effective risk strategies — driving execution through cross-functional influence rather than direct ownership of First Line controls.

AI, Tooling & Continuous Improvement

  • Embrace AI and agentic workflows to increase the speed, accuracy, and scalability of Second Line activities — including risk assessments, control validation, issue tracking, and reporting.
  • Maintain a hard focus on continuous improvement in how risks are identified, escalated, tracked, validated, and remediated — challenging legacy approaches and removing manual friction wherever possible.
  • Identify, evaluate, and help operationalize new tools, automations, and data-driven approaches to risk monitoring; partner with Technology, Data, and First Line teams to bring them to life.
  • Operate as a builder and creator — designing better ways of working, prototyping improvements, and measurably raising the bar over time — rather than administering existing processes for their own sake.

Reporting & Communication

  • Prepare risk reporting, analysis, and materials in support of the Head of Risk, who serves as the primary interface to executive leadership, the Risk Committee of the Board, and regulators (including NYDFS).
  • Translate complex risk scenarios into clear, actionable insights for technical and non-technical audiences.

Qualifications and Skills

  • Education: Bachelor’s degree in Business Administration, Finance, Economics, Law, or a related field. Relevant certifications (e.g., FRM, PRM, CRISC, or CRMA) are a plus.
  • Experience: 7–10 years of progressive, hands-on experience in enterprise risk management, internal audit, or compliance — including direct experience designing risk frameworks, performing risk assessments, and executing Second Line monitoring and challenge activities.
  • Execution & Influence: Ability to drive execution through cross-functional influence, operating effectively as an individual contributor in the Second Line — overseeing rather than performing First Line activities.
  • Industry Knowledge: Solid understanding of the crypto and blockchain ecosystem, digital assets, and their unique risk profiles (e.g., custody models, Layer 1/Layer 2 architectures, DeFi primitives, stablecoin dynamics).
  • Regulated Environment Experience: Track record working within a regulated financial, banking, or digital asset environment; familiarity with NYDFS, SEC, MiCA, or comparable regulatory regimes preferred.
  • Counterparty & Market Risk Acumen: Working knowledge of counterparty risk assessment, market and liquidity risk concepts, and operational risk frameworks.
  • Builder Mindset: A builder/creator orientation — energized by designing and improving processes rather than administering them. Curious, resourceful, and willing to prototype, automate, and iterate.
  • AI & Agentic Workflow Fluency: Demonstrated interest in (and ideally hands-on use of) AI tools, agentic workflows, and automation to make risk and control work faster, sharper, and more data-driven.
  • Continuous Improvement Bias: A hard focus on continuous improvement in how risks are tracked, validated, and remediated — challenges status quo, identifies friction, and proposes better approaches.
  • Change Management: Proven ability to support strategic change initiatives, navigate resistance, and drive cultural alignment around risk management principles.
  • Communication Skills: Strong stakeholder management and executive presence, with the ability to articulate complex risk scenarios to non-technical audiences, the Head of Risk, the Board, and regulators.


Bakkt is devoted to having diversity in its workforce and is proud to be an equal opportunity employer. Bakkt does not make any employment decisions based on race, color, religion, sex, national origin, veteran status, disability, age, sexual orientation, gender identity or any other characteristic protected by law. Must successfully pass a post-offer background check and drug screen. 



Compliance

Poland

Dubai, United Arab Emirates

Deel met:

Algemene voorwaardenPrivacyCookiesPowered by Rippling