Senior Compliance & Risk Manager
Job Description
About the JobAs Senior Compliance & Risk Manager (f/m/d), you will lead KuCoin EU’s key operational resilience pillars, including Third-Party Risk Management (TPRM), ICT risk management, and Business Continuity Management (BCM). You will ensure that our governance, processes, and controls comply with MiCAR, DORA, EU GDPR, and Austrian regulatory expectations while supporting strong cross-functional collaboration. In this role, you will manage due diligence and oversight of external service providers, maintain the ICT risk framework and central risk register, coordinate BCM and Disaster Recovery activities, support incident and vendor monitoring, and prepare clear reporting for the Head of Risk, CISO, Management Board, and relevant committees.Working at KuCoin EUWork at the heart of it. Our modern Vienna office is located directly at the historic Trabrennbahn in the Prater - a vibrant and accessible location.Team culture matters. We believe in strong collaboration and organize regular team events to foster a positive and connected work environment.We take care of the details. A daily selection of snacks, beverages, and weekly Friday breakfasts help keep our team energized.An international mindset. Join a diverse, forward-thinking team that thrives on innovation and cross-border collaboration.Invest in your development. We offer clear career progression, supported by learning and development opportunities tailored to your professional growth.Rewarding performance. Benefit from a competitive salary, performance-based bonuses, and a comprehensive benefits package on top.Shape the industry. Make a direct contribution to one of Europe’s most ambitious crypto platforms as we scale our regulatory capabilities.What makes You specialYou hold a university degree in Law, Economics, Finance, Business, IT Risk, or a related fieldYou have 4+ years of experience in compliance, risk management, audit, or internal control (financial services/fintech/crypto experience is a strong plus)You bring practical expertise in TPRM, ICT risk governance, or EU GDPR-related compliance workYou can interpret system diagrams, vulnerability reports, penetration tests, and security certificationsYou understand European and Austrian regulatory frameworks, including DORA, MiCAR, NIS2, and relevant ISO standardsYou can translate regulatory requirements into clear, actionable, and scalable processesYou communicate well and collaborate effectively with cross-functional teams and external partnersYou are proactive, detail-oriented, and comfortable working in a fast-evolving regulatory environmentYou are fluent in English; German proficiency is a strong advantageJoin us.At KuCoin EU, you will be part of a team committed to innovation, integrity, and regulatory excellence. If you’re ready to contribute to the future of finance in a fast-moving, global environment - we look forward to hearing from you.KuCoin EU is an equal opportunity employer. We are committed to building a diverse and inclusive workplace. All qualified applicants will be considered for employment without regard to race, religion, gender, sexual orientation, gender identity, national origin, disability, or age. We welcome applications from people of all backgrounds and experiences.Detailed Job DescriptionYour MissionAs a Senior Compliance & Risk Manager, you will play a key role in strengthening our compliance and risk management framework, including Third-Party Risk Management (TPRM) and ICT Risk Management. You will also be developing, overseeing and coordinating the company's Business Continuity Management (BCM) framework. Working across Compliance and Risk Management, you will ensure the company meets its regulatory obligations under MiCAR, DORA, MiFID II, PSD II and related frameworks, while building a robust governance environment and effectively mitigating risks arising from external service providers. You are also expected to prepare regular risk and continuity reports for the Head of Risk, CISO, Management Board and relevant committees.What You Will DoThird-Party Risk ManagementLead and further develop the company’s Third-Party Risk Management (TPRM) framework, ensuring alignment with DORA, MiCAR, EU GDPR, and ICT risk expectationsConduct pre-contract due diligence, risk classification, and criticality assessments—including EU GDPR data protection impact assessments where relevantMaintain and enhance the DORA-compliant ICT Third-Party Register, ensuring complete, accurate, and up-to-date documentationEnsure that ICT outsourcing and third-party contracts include mandatory clauses required by DORA and EU GDPR (including audit/access rights, data protection terms, breach notification, subcontractor conditions, termination, and exit rights)Lead the ongoing monitoring of third-party service providers, including performance reviews, compliance checks, EU GDPR adherence, and ICT risk assessmentsDrive the oversight of critical ICT service providers, coordinating with ICT Security, R