الوصف
الفرصة
يُنفَّذ مشروع بنية تحتية جديدة لسوق المال في عمان، مدعوم من قبل مستثمرين مؤسسيين بارزين ويعمل وفق إطار القانون الدولي العام. المنصة هي مُحوّلة مركزيّة للأوراق المالية معروفة التنظيم بموجب مبادئ CPMI-IOSCO لبُنى أسواق المال.
نحن نوظِّف قائد التنظيم والمخاطر لقيادة خط الدفاع الثاني. الدور مسؤول عن إطار مخاطر المؤسسة، والعلاقة التنظيمية والامتثال، ومنع الجريمة المالية، والإشراف على أمن المعلومات. النية أن ينتقل شاغل المنصب إلى دور رئيس المخاطر والامتثال في مرحلة التشغيل (Run).
وظائف الخط الأول تمتلك تنفيذ الأنشطة اليومية والضوابط المحيطة بها. يقوم قائد التنظيم والمخاطر بمراجعة مستقلة وتحدّي وتقديم تقارير عن تنفيذ الخط الأول؛ تحديد السياسات والمعايير الإطارية التي يجب أن يعمل ضمنها؛ وامتلاك العلاقة مع الجهة التنظيمية في جميع المسائل باستثناء التقارير التنظيمية التشغيلية الخاصة. يجب أن يكون شاغل المنصب مستعداً وقادراً على تحدّي نظرائه، بمن فيهم من هم فوقه، دون تردد، والتصعيد إلى مجلس الإدارة عند الضرورة.
ما يغطيه الدور
- تصميم إطار مخاطر المؤسسة من صفحة فارغة: التصنيف المخاطر، الشهية للمخاطر، الم tolerances للمخاطر، مؤشرات المخاطر الرئيسية، الحوكمة والتقارير
- امتلاك العلاقة اليومية مع الجهة التنظيمية في جميع مسائل الامتثال والإشراف؛ قيادة الاستجابة للفحوصات والاستفسارات الإشرافية
- امتلاك خطة التفاعل التنظيمي: الإشعارات، التقديمات الدورية، اجتماعات الإشراف، المراجعات الموضوعية، والطلبات العشوائية
- توفير الإشراف من الخط الثاني على الالتزام بمبادئ CPMI-IOSCO لبنى أسواق المال؛ قيادة التواصل مع مقيمي PFMI والجهات الإشرافية الدولية
- تصميم وامتلاك إطار الجرائم المالية: مكافحة غسل الأموال، تمويل الإرهاب، العقوبات، ومكافحة الرشوة والفساد؛ أداء أو تعيين مسؤول مكافحة غسل الأموال (MLRO) بشكل مسؤول
- تحديد إطار سياسات أمن المعلومات وتوفير الإشراف من الخط الثاني على أمن المعلومات في الخط الأول؛ امتلاك تقارير مواجهة المنظمين حول قضايا الأمن السيبراني
- امتلاك إطار السياسات: الهيكل، التسلسلية، الملكية، دورات المراجعة، وشهادة الالتزام
- توفير تقارير مستقلة من الخط الثاني إلى لجنة المخاطر بمجلس الإدارة حول المخاطر، الامتثال، الجريمة المالية، وأمن المعلومات
- إدارة فريق مدير الأمن السيبراني وأمن المعلومات، خبير KYC/الامتثال، وفريق المخاطر والامتثال الأوسع أثناء بنائه
المتطلبات
من نبحث عنه
- ما لا يقل عن 12 عاماً في مخاطر، امتثال، أو أدوار تنظيمية في الخدمات المالية، مع وقت كبير كجزء من الخط الثاني في مؤسسة مُحدَّدة التنظيم؛ خبرة مباشرة قابلة للإثبات كمالك مخاطر وامتثال في الخط الثاني، أو كعضو كبير في وظيفة الخط الثاني، في بنية سوق مالي، بنك حفظ، بورصة، نظام دفع، أو مؤسسة مالية مُنظَّمة كبرى: هذا أمر لا يمكن التنازل عنه.
- خبرة مباشرة في التواصل مع جهة تنظيمية كبيرة للخدمات المالية حول الترخيص، مسائل الإشراف، التفتيش، وتطوير السياسات. معرفة عملية بمبادئ CPMI-IOSCO لبنى أسواق المال.
- خبرة مباشرة في تصميم وتشغيل إطار مكافحة غسل الأموال والجريمة المالية، بما في ذلك مسؤولية MLRO أو دعم مقرب لـ MLRO.
- سجل في تحدي قرارات الخط الأول بشكل مستقل وتصعيدها إلى مستوى المجلس عند الضرورة.
- إتقان اللغة الإنجليزية.
- مؤهل مهني (دبلوم ICA، CISI، ACAMS، أو ما يعادلها) ميزة. كما أن الإلمام بالإطار التنظيمي لهيئة IFC عمان، والخبرة المباشرة في CSD أو CCP أو بورصة، ومهارات اللغة العربية تعتبر ميزة.
ما هو هذا الدور
وظيفة الخط الثاني غير موجودة بعد. إطار المخاطر لم يُكتب بعد، وخطة الرقابة الامتثالية لم تُحدد، والعلاقة التنظيمية في مراحلها الأولى. الشخص الذي يتولى هذا الدور سيبني كل ذلك ويستمِر في الترخيص والتشغيل.
إذا كنت موثوقاً بلا شك للجهات التنظيمية العليا، تمتلك الاستقلالية للتحدّي عُلواً عند الحاجة إلى الأدلة، وتريد بناء وظيفة الخط الثاني في FMI مُنظَّم من صفحة بيضاء، فهذه تستحق نقاشاً.
Description
The opportunity
A new financial markets infrastructure venture is being established in Oman, backed by prominent institutional investors and operating under an international common law framework. The platform is a greenfield central securities depository regulated under the CPMI-IOSCO Principles for Financial Market Infrastructures.
We are hiring a Regulatory and Risk Lead to head the second line of defence. The role is accountable for the enterprise risk framework, regulatory relationship and compliance, financial crime prevention, and oversight of information security. The intention is that the post-holder progresses into the Head of Risk and Compliance role in the Run phase.
The first-line functions own the day-to-day execution and the controls that surround it. The Regulatory and Risk Lead independently reviews, challenges, and reports on that first-line execution; sets the policy and framework standards within which it must operate; and owns the relationship with the regulator across all matters except specific operational regulatory reporting. The post-holder must be willing and able to challenge their peers, including those above them, without flinching, and to escalate to the Board where necessary.
What the role covers
- Designing the enterprise risk framework from a blank sheet: risk taxonomy, risk appetite, risk tolerances, key risk indicators, governance, and reporting
- Owning the day-to-day relationship with the regulator on all compliance and supervisory matters; leading the response to inspections and supervisory enquiries
- Owning the regulatory engagement plan: notifications, periodic submissions, supervisory meetings, thematic reviews, and ad hoc requests
- Providing second-line oversight of adherence to CPMI-IOSCO Principles for Financial Market Infrastructures; leading engagement with PFMI assessors and international supervisory bodies
- Designing and owning the financial crime framework: AML, counter-terrorism financing, sanctions, and anti-bribery and corruption; discharging or designating MLRO accountability
- Setting the information security policy framework and providing second-line oversight of first-line information security; owning regulator-facing reporting on cyber matters
- Owning the policy framework: structure, hierarchy, ownership, review cycles, and attestation
- Providing independent second-line reporting to the Board Risk Committee on risk, compliance, financial crime, and information security
- Line managing the Cybersecurity and Information Security Manager, KYC/Compliance Expert, and wider Risk and Compliance team as it builds
Requirements
Who we are looking for
- At least 12 years in risk, compliance, or regulatory roles in financial services, with substantial time in a second-line capacity at a regulated firm. Direct, demonstrable experience as the second-line risk and compliance owner, or a senior member of the second-line function, at a financial market infrastructure, custody bank, exchange, payment system, or major regulated financial institution: this is non-negotiable.
- Direct experience engaging with a senior financial-services regulator on licensing, supervisory matters, inspections, and policy development. Working knowledge of CPMI-IOSCO Principles for Financial Market Infrastructures.
- Direct experience designing and operating an AML and financial crime framework, including MLRO accountability or close support of an MLRO.
- Track record of independently challenging first-line decisions and escalating to Board level where necessary.
- Fluent in English.
- A professional qualification (ICA Diploma, CISI, ACAMS, or equivalent) is an advantage. So is familiarity with the IFC Oman regulatory framework, direct experience in a CSD, CCP, or exchange, and Arabic language skills.
What this is
The second-line function does not exist yet. The risk framework has not been written, the compliance monitoring plan has not been set, and the regulatory relationship is in its earliest stages. The person who takes this role will build all of it and carry it through licensing and into operation.
If you are unquestionably credible with senior regulators, have the independence to challenge upward when the evidence demands it, and want to build a second-line function at a regulated FMI from a blank sheet, this is worth a conversation.