Change Oversight & Third Party Operations Manager

Posted:
6/10/2026, 5:17:19 AM

Experience Level(s):
Mid Level ⋅ Senior

Field(s):
Operations & Logistics

Building the Future of Open Finance

Payward - the parent company behind Kraken, NinjaTrader, Breakout, xStocks, Payward Services and CF Benchmarks - has spent the last 15 years building one of the most modern and globally accessible financial infrastructure platforms in the industry, built to advance an open, global financial system.


Before you apply, we encourage you to explore our culture page to understand what drives us and how we work.

The team

Founded in 2011, Kraken is one of the world's longest-standing crypto platforms, trusted by over 10 million individuals and institutions across the globe. It offers spot trading, margin, futures, staking, and OTC services, with products built for both individual investors and institutional clients.

As the global crypto market transforms under the Markets in Crypto-Assets Regulation (MiCAR) and many more regulatory frameworks, Kraken is building the blueprint for how a global exchange scales compliantly — while unlocking new growth across products, markets, and partnerships.

The opportunity

Change Oversight and Change Management

  • Support the ongoing development, implementation, and operation of Kraken’s IT General Control (“ITGC”) oversight and technology governance framework across regulated entities and core operational environments.

  • Partner with Product, Engineering, Data, Finance, Compliance, and operational teams to identify, assess, and manage risks arising from system, infrastructure, process, or data changes impacting regulatory or operational control environments.

  • Support the operation and continuous enhancement of governance processes relating to:

    • IT general controls;

    • technology change management;

    • operational resilience;

    • implementation readiness;

    • testing and validation;

    • and post-implementation oversight.

  • Assist in the development and maintenance of policies, procedures, workflows, standards, and governance documentation supporting operational risk management and technology governance activities.

  • Support the maintenance and refinement of critical systems inventories, regulatory-critical datasets, data dependencies, and associated governance artefacts.

  • Review and analyse the effectiveness of IT general controls, testing standards, implementation readiness controls, and post-implementation validation processes across operational and regulatory control environments.

  • Support the execution and review of post-implementation validation activities and assist in the investigation, escalation, and remediation of identified control issues, operational incidents, or reconciliation variances.

  • Assist in the development and operationalisation of workflow tooling, data governance controls, and technology-enabled oversight processes designed to support scalable governance and operational risk management.

  • Help develop and implement performance metrics supporting the monitoring, reporting, escalation, and management of technology and operational risks.

  • Work with second line of defence teams to support the development and maintenance of a consistent framework for identifying, measuring, mitigating, monitoring, and managing technology and operational risks.

  • Support the embedding of a strong risk culture across operational and technology functions, where effective risk management forms part of day-to-day decision making and operational processes.

  • Work with Internal Audit, Compliance, Risk, Finance, Engineering, Data, and external assurance providers to support periodic reviews of operational processes and IT general controls, including testing, validation, evidence gathering, and reporting activities.

  • Assist in the preparation of governance reporting, management information, committee materials, audit evidence, and regulatory submissions relating to technology governance and operational control frameworks.

  • Support liaison and co-ordination between Kraken’s regulated entities and Group functions in relation to technology change, operational dependencies, governance processes, audit activities, and remediation initiatives.

  • Support adherence to enterprise risk management frameworks and IT-related policies, standards, and procedures.

Third Party Management

  • Proactively partner with business stakeholders and suppliers throughout contract negotiations, developing negotiation strategies, fallback positions, and acceptable commercial terms while establishing key performance benchmarks to measure contractual success.

  • Lead and coordinate the contract review process across internal stakeholders, engaging legal and subject matter experts as needed to ensure timely execution and compliance.

  • Support supplier rationalization initiatives to optimize the vendor portfolio, driving cost savings, supply continuity, quality improvements, innovation, and increased vendor value.

  • Analyze business requirements and develop vendor management guidelines, policies, and standardized contracting protocols.

  • Establish and manage the vendor lifecycle strategy, including vendor planning, sourcing, selection, performance management, and offboarding/transition activities.

  • Identify and mitigate risks associated with strategic suppliers while monitoring vendor performance against negotiated Service Level Agreements (SLAs) and Master Service Agreements (MSAs).

  • Perform spend analysis and financial modeling to support commercial negotiations, vendor performance reviews, and executive reporting through data-driven dashboards and metrics.

  • Create and manage purchase requisitions (PRs) and purchase orders (POs) for a wide range of goods and services, ensuring accuracy of accounting classifications and coding.

  • Partner with Accounts Payable, FP&A, IT, and business stakeholders to drive digital transformation initiatives across the Procure-to-Pay (P2P) process.

  • Champion continuous improvement efforts by identifying process enhancement opportunities, implementing automation solutions, testing new workflows, and driving operational efficiencies.

  • Manage the full purchase order lifecycle, ensuring timely processing, approvals, receipt validation, and issue resolution.

  • Analyze purchasing and procurement data to ensure compliance with policies and procedures, validate data integrity, and identify discrepancies, trends, and improvement opportunities.

What you bring

  • 5+ years of experience in IT risk management, operational risk, IT audit, technology governance, operational resilience, procurement, or a related discipline, ideally within a financial services, fintech, or crypto organisation, or a consulting/audit environment.

  • Strong understanding of IT general controls, change management processes, testing and validation standards, and operational risk management frameworks.

  • Experience supporting or assessing operational control environments relating to technology governance, regulatory compliance, or operational resilience.

  • Strong analytical and problem-solving skills, with the ability to assess complex operational or technology risks and translate findings into practical recommendations.

  • Excellent written and verbal communication skills, including the ability to prepare clear governance reporting and engage effectively with senior stakeholders across business, technology, and control functions.

  • Experience working cross-functionally with Engineering, Product, Risk, Compliance, Finance, Data, and operational teams.

  • Comfortable operating in a fast-moving environment with evolving priorities and regulatory requirements.

  • Systems thinker with an interest in leveraging technology, workflow tooling, automation, and data-driven approaches to support scalable governance and oversight processes.

  • Strong organisational and coordination skills, with the ability to manage multiple workstreams, stakeholders, and governance activities simultaneously.

Nice to haves

  • Familiarity with governance frameworks and regulatory expectations relating to operational resilience, outsourcing, technology risk, or digital asset regulation (e.g. MiCAR, DORA, PSD2, E-Money Regulations).

Unless a specific application deadline is stated in the job posting, applications are accepted on an ongoing basis.

Please note, applicants are permitted to redact or remove information on their resume that identifies age, date of birth, or dates of attendance at or graduation from an educational institution.

We consider qualified applicants with criminal histories for employment on our team, assessing candidates in a manner consistent with the requirements of the San Francisco Fair Chance Ordinance.

Payward is powered by people from around the world and we celebrate the diverse talents, backgrounds, contributions, and unique perspectives that everyone brings to the table. We hire based on merit, seeking out people with the right abilities, knowledge, and skills for the job. We encourage you to apply for roles where you don't fully meet the listed requirements, especially if you're passionate or knowledgeable about crypto.

We may ask candidates to complete job-related skills or work-style assessments as part of our hiring process. These assessments evaluate competencies relevant to the role and are applied consistently across candidates for similar positions. Results are considered alongside experience and interviews, and are not the sole basis for any employment decision.

As an equal opportunity employer, we don't tolerate discrimination or harassment of any kind, whether based on race, ethnicity, age, gender identity, citizenship, religion, sexual orientation, disability, pregnancy, veteran status, or any other protected characteristic as outlined by federal, state, or local laws.

Stay in the know

Follow us on Twitter

Learn on the Kraken Blog

Connect on LinkedIn


Candidate Privacy Notice