Live opening · Posted 1 day ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
About Direct Crypto Limited
Direct Crypto Limited is a newly established Crypto-Asset Service Provider (CASP) within the Wirex Holdings Ltd group, headquartered in Cyprus.
We are building a compliance-first, institutionally focused crypto infrastructure platform, providing safekeeping, exchange, and transfer services to regulated financial institutions, fintechs, and Web3 businesses across the EEA.
This is an opportunity to join a new entity at an important stage of its development and contribute to building its culture, processes, and operational standards from the ground up.
The Role
We are looking for an ICT Risk & Incident Manager to join our Engineering & Infrastructure team in Cyprus.
In this role, you will act as the first line of defence for ICT risk management at the local entity level. You will work closely with the Global ICT Risk Manager and Group teams to ensure that ICT risks are identified, assessed, documented, monitored, and appropriately managed.
You will also coordinate the local response to significant ICT incidents and support regulatory incident reporting where required.
This is a hands-on and coordination-focused role, working closely with Compliance, Security, Infrastructure, Engineering, Operations, and Product teams.
ICT Risk Management
Own and coordinate day-to-day ICT risk management activities for the local entity.
Maintain the ICT risk register, ensuring risks are properly identified, assessed, documented, and monitored.
Ensure each risk has an assigned owner, mitigation plan, target date, and current status.
Track remediation activities and escalate overdue or material risks.
Coordinate ICT risk assessments covering systems, services, vendors, projects, and significant technology changes.
Support risk acceptance and exception processes.
Provide regular ICT risk reporting to management and relevant governance forums.
Policies & Governance
Support the implementation of Group ICT risk policies, standards, and procedures at the entity level.
Maintain entity-specific ICT policies, procedures, and supporting documentation where required.
Identify gaps between Group policies and local regulatory requirements and coordinate their resolution.
Ensure ICT governance documentation and supporting evidence are maintained and audit-ready.
Support local governance committees and management reporting on ICT risk matters.
Regulatory & Compliance
Support compliance with applicable ICT and operational resilience requirements, including MiCA, DORA, and CySEC obligations.
Support regulatory assessments, audits, inspections, and information requests relating to ICT risk.
Coordinate remediation of ICT-related regulatory findings and observations.
Maintain accurate records of ICT controls, risk assessments, governance activities, and remediation actions.
Work closely with Compliance to ensure regulatory requirements are reflected in local ICT risk processes.
Incident Management
Support the entity-level ICT incident management process.
Ensure significant ICT incidents are identified, classified, documented, and escalated appropriately.
Coordinate local responses to significant ICT incidents with relevant Group and local teams.
Ensure business and technical owners remain accountable throughout the incident lifecycle.
Track remediation actions, root cause analysis, and post-incident follow-up through to completion.
Maintain accurate incident records and supporting evidence.
Regulatory Incident Reporting
Support the assessment of ICT incidents against applicable regulatory reporting thresholds under DORA, MiCA, and CySEC requirements.
Coordinate with Compliance and the Global ICT Risk Manager on regulatory notifications and reporting.
Support the preparation of initial, intermediate, and final regulatory incident reports where required.
Track reporting deadlines and ensure supporting evidence is available.
Support follow-up activities and regulatory engagement resulting from significant or reportable incidents.
Group Coordination
Act as the primary ICT risk point of contact for Direct Crypto Limited.
Maintain close collaboration with the Global ICT Risk Manager.
Ensure local ICT risk activities remain aligned with Group methodologies, policies, controls, and reporting standards.
Escalate significant ICT risks, incidents, and regulatory concerns in a timely and structured manner.
Provide entity-level risk information for Group reporting and assessments.
Support the implementation of Group ICT risk initiatives at the local entity level.
Essential Requirements
Based in Cyprus.
Professional working proficiency in Greek, both written and verbal.
Professional working profic
Employment type
Full-Time
Work arrangement
No
More openings worth a look
Recently tracked roles with full details and direct application links.