Now hiring

Head of Compliance & Risk @ ONE

MELLIEHA, MELLIEHAOnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

Head of Compliance & Risk

This role is based in Malta.

Company Overview

ONE.io was founded in 2017 as an OTC digital asset trading desk, serving high-net-worth individuals, corporates, and institutional clients globally. Recognising that our clients – generally in sectors underserved by the traditional banking system – were facing tremendous difficulty in the movement of fiat funds, we undertook to resolve this industry pain point by shifting our focus toward the provision of payment services. We subsequently acquired our PI licence from the FCA in 2020, and launched our proprietary payments platform in 2021.

Today we provide a unified end-to-end financial services solution for corporate clients through our core propositions - ONE.io Connect (Payments Platform), ONE.io Fusion (OTC Crypto Trading and Crypto Gateway). We leverage a strong network of banking partners and regulatory licenses to serve clients effectively on a global scale.

Through a single onboarding journey with us, clients get access to a full suite of products and services, including named IBANs in multiple fiat currencies, foreign exchange, and access to payment rails including SWIFT, SEPA, Faster Payments and CHAPS.

The ONE.io Group is very culture-driven and employees live by our values which include:

• Ingenuity: Constantly improving with creativity and confidence

• Integrity: Brave and tenacious in pursuit of equality

• Unity: A team empowered by shared beliefs and commitment

• Dedication: Intuitive to our customers needs and accountable for our actions

Role Overview

We are seeking a proactive and experienced Head of Compliance & Risk to support the establishment and ongoing regulatory compliance of Payment Institution (PI) and Crypto-Asset Service Provider (CASP) activities in Malta. This role will be instrumental during the pre-licensing phase and beyond, ensuring the business is built on a strong compliance foundation aligned with Malta Financial Services Authority (MFSA) expectations and EU regulatory frameworks, including PSD2, AML/CFT obligations, the Markets in Crypto-Assets Regulation (MiCA), and soon also PSD3.

Key Responsibilities

Licensing & Regulatory Engagement

• Liaise with regulators and assist in responding to queries, requests for information, and meeting licensing conditions.

• Ensure the business continuously meets all regulatory requirements for authorization, including governance, internal controls, and compliance frameworks.

Compliance Framework Development

• Design, implement, and maintain the company’s compliance framework, policies, and procedures in line with MFSA, EU Directives, and industry best practices.

• Assist in establishing compliance monitoring programs and internal control mechanisms.

• Ensure policies reflect requirements under PSD2, AML/CFT regulations, and MiCA where crypto-asset activities are relevant. In time, update policies to become PDS3 compliant.

• Product Oversight and Governance Framework Management

Regulatory Compliance & Advisory

• Provide ongoing advice to senior management on regulatory obligations and compliance risks.

• Interpret and apply regulatory requirements, ensuring business activities remain compliant.

• Monitor regulatory developments in Malta and the EU, including updates related to MiCA, and implement necessary changes.

• Safeguarding of Client Funds Oversight and Annual Audit Coordination

• Assess risks associated with crypto-asset services, including custody, trading, market abuse, volatility, and technological vulnerabilities.

• Ensure alignment with MiCA risk management, governance, and consumer protection requirements.

• Work closely with compliance and product teams to embed risk considerations into crypto-related offerings.

• Provider oversight of Custody and Private Key Governance Risk.

• Statutory Complaints Handling

Risk & Control Oversight

• Support the identification, assessment, and mitigation of compliance and regulatory risks.

• Assist in developing risk assessments, including compliance risk registers.

• Work closely with the MLRO to ensure alignment across compliance, AML/CFT, and enterprise risk frameworks.

• Identify, assess, and monitor key risks including operational, compliance, financial, liquidity, fraud, IT/cybersecurity, and crypto-asset risks.

• Conduct enterprise-wide risk assessments and scenario analyses, including stress testing.

• Develop and maintain risk registers at both enterprise and functional levels.

• Develop and maintain DORA Compliance and ICT Risk Management

Monitoring & Reporting

• Conduct compliance monitoring reviews and report findings to senior management.

• Track and ensure timely remediation of identified issues.

• Prepare regular compliance reports for the Board and relevant committees.

• MiCA Market Abuse Monitoring and SMAR Reporting

• Monitor risk exposures and ensure adherence to defined risk appetite.

• Prepare regular risk reports for senior management and the Board, including emerging risks and mitigation actions.

• Escalate material risks and incidents in a timely manner.

Training & Culture

• Support the development and delivery of compliance training programs.

• Promote a strong culture of compliance and ethical conduct across the organization.

Cross-Functional Collaboration

• Work closely with legal, product, operations, and technology teams to ensure compliance-by-design during product development and business processes.

• Provide input into onboarding processes, safeguarding arrangements, and payment flows.

Skills and Experience

Experience

• Measurable experience in compliance within financial services, fintech, or payments.

• Experience supporting regulatory licensing processes, preferably for a PI or similar regulated entity.

• Strong understanding of EU regulatory frameworks, including PSD2, AML/CFT requirements, MiCA and PSD3.

• Exposure to crypto-assets and knowledge of MiCA is highly desirable.

Skills

• Strong understanding of enterprise risk management principles and regulatory expectations.

• Ability to assess complex and emerging risks, particularly in fintech and crypto environments.

• Excellent analytical, problem-solving, and decision-making skills.

• Strong communication and stakeholder management abilities.

Qualifications

• Bachelor’s degree in Law, Finance, Business, or a related field.

• Professional certifications (e.g., ICA, CAMS, or equivalent) are an advantage.

ONE prides itself on being an equal opportunities employer. We will always hire people based on merit and will never discriminate against someone based on gender, race, religion, or background.

Unfortunately, we cannot offer sponsorship at present.

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores