ONE
Head of Compliance & Risk
MELLIEHA, MELLIEHA
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.4M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Seniority
- Lead / management
- Country
- MT
- Work mode
- On-site / unstated
- First seen by hirly
- 20 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
Head of Compliance & Risk
This role is based in Malta.
Company Overview
ONE.io was founded in 2017 as an OTC digital asset trading desk, serving high-net-worth individuals, corporates, and institutional clients globally. Recognising that our clients – generally in sectors underserved by the traditional banking system – were facing tremendous difficulty in the movement of fiat funds, we undertook to resolve this industry pain point by shifting our focus toward the provision of payment services. We subsequently acquired our PI licence from the FCA in 2020, and launched our proprietary payments platform in 2021.
Today we provide a unified end-to-end financial services solution for corporate clients through our core propositions - ONE.io Connect (Payments Platform), ONE.io Fusion (OTC Crypto Trading and Crypto Gateway). We leverage a strong network of banking partners and regulatory licenses to serve clients effectively on a global scale.
Through a single onboarding journey with us, clients get access to a full suite of products and services, including named IBANs in multiple fiat currencies, foreign exchange, and access to payment rails including SWIFT, SEPA, Faster Payments and CHAPS.
The ONE.io Group is very culture-driven and employees live by our values which include:
Ingenuity: Constantly improving with creativity and confidence
Integrity: Brave and tenacious in pursuit of equality
Unity: A team empowered by shared beliefs and commitment
Dedication: Intuitive to our customers needs and accountable for our actions
Role Overview
We are seeking a proactive and experienced Head of Compliance & Risk to support the establishment and ongoing regulatory compliance of Payment Institution (PI) and Crypto-Asset Service Provider (CASP) activities in Malta. This role will be instrumental during the pre-licensing phase and beyond, ensuring the business is built on a strong compliance foundation aligned with Malta Financial Services Authority (MFSA) expectations and EU regulatory frameworks, including PSD2, AML/CFT obligations, the Markets in Crypto-Assets Regulation (MiCA), and soon also PSD3.
Key Responsibilities
Licensing & Regulatory Engagement
Liaise with regulators and assist in responding to queries, requests for information, and meeting licensing conditions.
Ensure the business continuously meets all regulatory requirements for authorization, including governance, internal controls, and compliance frameworks.
Compliance Framework Development
Design, implement, and maintain the company’s compliance framework, policies, and procedures in line with MFSA, EU Directives, and industry best practices.
Assist in establishing compliance monitoring programs and internal control mechanisms.
Ensure policies reflect requirements under PSD2, AML/CFT regulations, and MiCA where crypto-asset activities are relevant. In time, update policies to become PDS3 compliant.
Product Oversight and Governance Framework Management
Regulatory Compliance & Advisory
Provide ongoing advice to senior management on regulatory obligations and compliance risks.
Interpret and apply regulatory requirements, ensuring business activities remain compliant.
Monitor regulatory developments in Malta and the EU, including updates related to MiCA, and implement necessary changes.
Safeguarding of Client Funds Oversight and Annual Audit Coordination
Assess risks associated with crypto-asset services, including custody, trading, market abuse, volatility, and technological vulnerabilities.
Ensure alignment with MiCA risk management, governance, and consumer protection requirements.
Work closely with compliance and product teams to embed risk considerations into crypto-related offerings.
Provider oversight of Custody and Private Key Governance Risk.
Statutory Complaints Handling
Risk & Control Oversight
Support the identification, assessment, and mitigation of compliance and regulatory risks.
Assist in developing risk assessments, including compliance risk registers.
Work closely with the MLRO to ensure alignment across compliance, AML/CFT, and enterprise risk frameworks.
Identify, assess, and monitor key risks including operational, compliance, financial, liquidity, fraud, IT/cybersecurity, and crypto-asset risks.
Conduct enterprise-wide risk assessments and scenario analyses, including stress testing.
Develop and maintain risk registers at both enterprise and functional levels.
Develop and maintain DORA Compliance and ICT Risk Management
Monitoring & Reporting
Conduct compliance monitoring reviews and report findings to senior management.
Track and ensure timely remediation of identified issues.
Prepare regular compliance reports for the Board and relevant committees.
MiCA Market Abuse Monitoring and SMAR Reporting
Monitor risk exposures and ensure adherence to defined risk appetite.
Prepare regular risk reports for senior management and the Board, including emerging risks and mitigation actions.
Escalate material risks and incidents in a timely manner.
Training & Culture
Support the development and delivery of compliance training programs.
Promote a strong culture of compliance and ethical conduct across the organization.
Cross-Functional Collaboration
Work closely with legal, product, operations, and technology teams to ensure compliance-by-design during product development and business processes.
Provide input into onboarding processes, safeguarding arrangements, and payment flows.
Skills and Experience
Experience
Measurable experience in compliance within financial services, fintech, or payments.
Experience supporting regulatory licensing processes, preferably for a PI or similar regulated entity.
Strong understanding of EU regulatory frameworks, including PSD2, AML/CFT requirements, MiCA and PSD3.
Exposure to crypto-assets and knowledge of MiCA is highly desirable.
Skills
Strong understanding of enterprise risk management principles and regulatory expectations.
Ability to assess complex and emerging risks, particularly in fintech and crypto environments.
Excellent analytical, problem-solving, and decision-making skills.
Strong communication and stakeholder management abilities.
Qualifications
Bachelor’s degree in Law, Finance, Business, or a related field.
Professional certifications (e.g., ICA, CAMS, or equivalent) are an advantage.
ONE prides itself on being an equal opportunities employer. We will always hire people based on merit and will never discriminate against someone based on gender, race, religion, or background.
Unfortunately, we cannot offer sponsorship at present.
Similar jobs
- Manager, Compliance Risk ManagementJj · 5 LocationsFirst seen yesterday
- FCC Compliance Risk Analytics ManagerCapgemini · New York, USFirst seen 2d ago
- FCC Compliance Risk Analytics ManagerCapgemini · New York, USFirst seen 2d ago
- Investment Conduct & Compliance Risk ManagerLbg · 4 LocationsFirst seen 2d ago
- Investment Conduct & Compliance Risk ManagerLbg · 4 LocationsFirst seen 2d ago
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job