Director - Operational Risk
Quick Summary
Overview Role Overview StoneX Financial Ltd. is seeking an experienced Director of Operational Risk to lead the operational risk agenda for the UK legal entity from our London office.
StoneX Financial Ltd. is seeking an experienced Director of Operational Risk to lead the operational risk agenda for the UK legal entity from our London office. Reporting to the Global Head of Enterprise Risk and SFL Head of Risk, this is a senior Second Line of Defense (2LOD) role responsible for the design, oversight and continuous improvement of the operational risk framework across the Firm’s regulated activities.
The candidate will act as a trusted, self-directed risk leader who can independently own and discharge the entity’s local operational risk and regulatory obligations — including engagement with the Financial Conduct Authority (FCA), compliance with the Digital Operational Resilience Act (DORA), and coordination with the National Futures Association (NFA) and other applicable authorities. A defining expectation of the role is the ability to escalate promptly and transparently to the Global Head of Enterprise Risk and the SFL Head of Risk (SMF4) at the earliest indication of any local risk concern, control weakness, incident or emerging regulatory matter.
Responsibilities
~3 min read2.1 Regulatory Oversight & Engagement
- →Serve as the primary operational risk point of contact for UK and applicable overseas regulators, including the FCA and NFA, managing information requests, thematic reviews, and supervisory engagement independently and to a high professional standard.
- →Own the entity’s compliance with the EU/UK Digital Operational Resilience Act (DORA), including ICT risk management, digital operational resilience testing, ICT third-party risk oversight, and major ICT-related incident reporting obligations.
- →Maintain current knowledge of the FCA Handbook (SYSC, SM&CR), operational resilience requirements (important business services, impact tolerances and mapping) and the MIFIDPRU / ICARA regime as it relates to operational risk.
- →Interpret new and evolving regulations, assess entity impact, and translate requirements into practical, embedded controls and framework updates without requiring day-to-day direction.
- →Prepare regulator-ready responses, attestations and submissions, ensuring language is accurate, proportionate and defensible.
2.2 Business-as-Usual (BAU) Operational Risk Management
- →Independently manage the day-to-day operational risk activities of the UK entity, including Risk & Control Self-Assessments (RCSA), control monitoring plans, key risk indicators (KRIs) and risk appetite monitoring.
- →Oversee the operational risk event / loss data capture process, ensuring timely recording, root-cause analysis, and remediation tracking to closure.
- →Provide 2LOD challenge and oversight to First Line of Defense (1LOD) risk and control activities across front office, operations and support functions.
- →Support operational risk scenario analysis and capital assessment inputs feeding the entity’s ICARA, including frequency and severity calibration where required.
- →Produce clear, concise operational risk reporting for senior management, risk committees and the Board.
2.3 Incident Management
- →Lead the operational risk aspects of the entity’s incident management lifecycle — identification, triage, escalation, coordination, resolution and post-incident review — in line with FCA operational resilience and DORA incident-reporting expectations.
- →Ensure incidents that breach impact tolerances or regulatory reporting thresholds are escalated immediately and reported to the relevant authority within required timeframes.
- →Drive lessons-learned and root-cause analysis, converting incident findings into sustainable control improvements and framework enhancements.
- →Escalate to the Global Head of Enterprise Risk at the earliest sign of a material incident or emerging local concern, providing a clear, factual assessment and recommended actions.
2.4 Third-Party Risk Management (TPRM)
- →Provide 2LOD oversight and challenge of the third-party / outsourcing risk management lifecycle.
- →Ensure ICT third-party arrangements are managed in line with DORA and FCA outsourcing and operational resilience requirements, with appropriate identification of critical or important suppliers and concentration risk.
- →Coordinate with TPRM and procurement teams on control testing, contractual risk provisions and remediation of legacy third-party arrangements.
2.5 Escalation & Stakeholder Engagement
- →Act as an early-warning function for the Global Head of Enterprise Risk, proactively flagging any local operational risk, control, incident or regulatory concern before it escalates, then informing the SFL Head of Risk.
- →Build effective working relationships with 1LOD business heads, Compliance, Legal, Internal Audit (3LOD), and global risk colleagues across EMEA, APAC, North and Latin America.
- →Represent operational risk at relevant governance forums and risk committees, presenting balanced, evidence-based assessments.
Requirements
~2 min read3.1 Essential Experience & Qualifications
- Substantial experience in operational risk management within a regulated financial services firm (brokerage, investment firm, banking or capital markets), at a Director level.
- Demonstrable, hands-on experience of direct regulatory engagement with the FCA and familiarity with the NFA and other applicable EMEA regulators.
- Working knowledge of DORA and the ability to operationalize its ICT risk management, resilience testing and incident-reporting requirements.
- Strong command of operational resilience, RCSA methodology, incident management, and operational risk reporting.
- Understanding of third-party / outsourcing risk management and the associated regulatory expectations.
- Proven ability to work autonomously — self-managing a portfolio of local regulatory obligations with minimal supervision while knowing when and how to escalate.
- Excellent written and verbal communication skills, with the ability to produce regulator-ready and Board-ready material.
3.2 Desirable
- Exposure to the MIFIDPRU / ICARA regime and operational risk capital assessment (e.g. scenario analysis, Loss Distribution Approach).
- Experience operating within a multi-entity, multi-jurisdiction group structure (EMEA, APAC, North America, Latin America).
- Relevant professional qualifications.
- Familiarity with GRC tooling such as Workiva or LogicGate.
3.3 Key Competencies
- Self-starter with sound judgement and a strong sense of ownership and accountability.
- Rigorous, detail-oriented and evidence-based approach to risk decisions.
- Confident escalator — able to raise concerns early, clearly and constructively.
- Credible influencer able to challenge the first line and engage senior stakeholders and regulators with authority.
This role reports directly to the Global Head of Enterprise Risk in the US and the SFL Head of Risk, forming part of the 2LOD. The role holder is expected to operate with a high degree of independence in managing local operational risk regulatory requirements, while maintaining an open and timely escalation channel to both the Global Head of Enterprise Risk and SFL Head of Risk on all matters of local concern.
Location & Eligibility
Listing Details
- Posted
- September 28, 2024
- First seen
- September 28, 2026
- Last seen
- September 28, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 18%
- Scored at
- September 28, 2026
Signal breakdown
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.