StoneX Group
Director - Operational Risk

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Overview
Role Overview
StoneX Financial Ltd. is seeking an experienced Director of Operational Risk to lead the operational risk agenda for the UK legal entity from our London office. Reporting to the Global Head of Enterprise Risk and SFL Head of Risk, this is a senior Second Line of Defense (2LOD) role responsible for the design, oversight, and continuous improvement of the operational risk framework across the Firm’s regulated activities.
The candidate will act as a trusted, self-directed risk leader who can independently own and discharge the entity’s local operational risk and regulatory obligations — including engagement with the Financial Conduct Authority (FCA), compliance with the Digital Operational Resilience Act (DORA), and coordination with the National Futures Association (NFA) and other applicable authorities. A defining expectation of the role is the ability to escalate promptly and transparently to the Global Head of Enterprise Risk and the SFL Head of Risk (SMF4) at the earliest indication of any local risk concern, control weakness, incident, or emerging regulatory matter.
Responsibilities
Key Responsibilities
2.1 Regulatory Oversight & Engagement
- Serve as the primary operational risk point of contact for UK and applicable overseas regulators, including the FCA and NFA, managing information requests, thematic reviews, and supervisory engagement independently and to a high professional standard.
- Own the entity’s compliance with the EU/UK Digital Operational Resilience Act (DORA), including ICT risk management, digital operational resilience testing, ICT third-party risk oversight, and major ICT-related incident reporting obligations.
- Maintain current knowledge of the FCA Handbook (SYSC, SM&CR), operational resilience requirements (important business services, impact tolerances, and mapping) and the MIFIDPRU / ICARA regime as it relates to operational risk.
- Interpret new and evolving regulations, assess entity impact, and translate requirements into practical, embedded controls and framework updates without requiring day-to-day direction.
- Prepare regulator-ready responses, attestations, and submissions, ensuring language is accurate, proportionate, and defensible.
2.2 Business-as-Usual (BAU) Operational Risk Management
- Independently manage the day-to-day operational risk activities of the UK entity, including Risk & Control Self-Assessments (RCSA), control monitoring plans, key risk indicators (KRIs), and risk appetite monitoring.
- Oversee the operational risk event / loss data capture process, ensuring timely recording, root-cause analysis, and remediation tracking to closure.
- Provide 2LOD challenge and oversight to First Line of Defense (1LOD) risk and control activities across front office, operations, and support functions.
- Support operational risk scenario analysis and capital assessment inputs feeding the entity’s ICARA, including frequency and severity calibration where required.
- Produce clear, concise operational risk reporting for senior management, risk committees, and the Board.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
2.3 Incident Management
- Lead the operational risk aspects of the entity’s incident management lifecycle — identification, triage, escalation, coordination, resolution, and post-incident review — in line with FCA operational resilience and DORA incident-reporting expectations.
- Ensure incidents that breach impact tolerances or regulatory reporting thresholds are escalated immediately and reported to the relevant authority within required timeframes.
- Drive lessons-learned and root-cause analysis, converting incident findings into sustainable control improvements and framework enhancements.
- Escalate to the Global Head of Enterprise Risk at the earliest sign of a material incident or emerging local concern, providing a clear, factual assessment and recommended actions.
2.4 Third-Party Risk Management (TPRM)
- Provide 2LOD oversight and challenge of the third-party / outsourcing risk management lifecycle.
- Ensure ICT third-party arrangements are managed in line with DORA and FCA outsourcing and operational resilience requirements, with appropriate identification of critical or important suppliers and concentration risk.
- Coordinate with TPRM and procurement teams on control testing, contractual risk provisions, and remediation of legacy third-party arrangements.
2.5 Escalation & Stakeholder Engagement
- Act as an early-warning function for the Global Head of Enterprise Risk, proactively flagging any local operational risk, control, incident, or regulatory concern before it escalates, then informing the SFL Head of Risk.
- Build effective working relationships with 1LOD business heads, Compliance, Legal, Internal Audit (3LOD), and global risk colleagues across EMEA, APAC, North, and Latin America.
- Represent operational risk at relevant governance forums and risk committees, presenting balanced, evidence-based assessments.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Qualifications
Candidate Profile
3.1 Essential Experience & Qualifications
- Substantial experience in operational risk management within a regulated financial services firm (brokerage, investment firm, banking, or capital markets), at a Director level.
- Demonstrable, hands-on experience of direct regulatory engagement with the FCA and familiarity with the NFA and other applicable EMEA regulators.
- Working knowledge of DORA and the ability to operationalize its ICT risk management, resilience testing, and incident-reporting requirements.
- Strong command of operational resilience, RCSA methodology, incident management, and operational risk reporting.
- Understanding of third-party / outsourcing risk management and the associated regulatory expectations.
- Proven ability to work autonomously — self-managing a portfolio of local regulatory obligations with minimal supervision while knowing when and how to escalate.
- Excellent written and verbal communication skills, with the ability to produce regulator-ready and Board-ready material.
3.2 Desirable
- Exposure to the MIFIDPRU / ICARA regime and operational risk capital assessment (e.g. scenario analysis, Loss Distribution Approach).
- Experience operating within a multi-entity, multi-jurisdiction group structure (EMEA, APAC, North America, Latin America).
- Relevant professional qualifications.
- Familiarity with GRC tooling such as Workiva or LogicGate.
3.3 Key Competencies
- Self-starter with sound judgment and a strong sense of ownership and accountability.
- Rigorous, detail-oriented, and evidence-based approach to risk decisions.
- Confident escalator — able to raise concerns early, clearly, and constructively.
- Credible influencer able to challenge the first line and engage senior stakeholders and regulators with authority.
Governance & Reporting Line
This role reports directly to the Global Head of Enterprise Risk in the US and the SFL Head of Risk, forming part of the 2LOD. The role holder is expected to operate with a high degree of independence in managing local operational risk regulatory requirements, while maintaining an open and timely escalation channel to both the Global Head of Enterprise Risk and SFL Head of Risk on all matters of local concern.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London