GRC Careers: Governance, Risk and Compliance JobsGovernance · Risk · Compliance Careers

Jobs › California › New York City › Senior Operational Risk Manager

Senior Operational Risk Manager

Mercury
RiskRemoteFull-timeSan Francisco, CA, New York · Remote

Mercury is hiring for the job of Senior Operational Risk Manager, San Francisco, CA, New York · Remote. This is a Risk job in the governance, risk, and compliance field. Review the full details below and apply directly with Mercury.

Organization: MercuryLocation: San Francisco, CA, New York · RemoteWorkplace: RemoteFocus: RiskPosted: Oct 9, 2026
Mercury is hiring for this Risk job in San Francisco, one of the metros GRC Careers tracks for governance, risk, and compliance hiring. See other GRC jobs in San Francisco →

Mercury is revolutionizing finance for startups by building a complete, user-friendly banking* stack. We prioritize creating a secure and seamless experience for entrepreneurs while upholding the highest standards of compliance and safety.

In this role, you will own the day-to-day operation of Mercury s Operational Risk program. You will report to the Head of Operational Risk, within the Risk organization under the Chief Risk Officer, and partner closely with first-line risk teams, Compliance, Third-Party Risk, Information Security, and Internal Audit.

You will run the centralized issues and events program, coordinate risk and control assessments with first line teams, and drive reporting that give leadership and the Board a clear view of operational risk. This is a builder role. Much of the program is being stood up now, and you will have the autonomy to shape how it operates as Mercury prepares to operate as a bank.

em *Mercury is a fintech company, not an FDIC-insured bank. Banking services provided through Choice Financial Group and Column N.A., Members FDIC.

As part of the journey, we would expect you to:

Set the risk and control assessment standard. Review and challenge first-line RCMs; independently test design and operating effectiveness on critical processes and issue findings.
Oversee the operational event program: challenge first-line root cause, ratings and fixes; trend events across the enterprise.
Own the centralized issues management program across operational events, incidents, testing and regulatory findings, from intake and triage through remediation tracking, validation, and closure
Define enterprise KRIs and thresholds for each L2, tied to risk appetite, and aggregate first-line metrics into Board reporting.
Partner with 1LOD teams, InfoSec, Compliance and model risk owners to collect inputs, challenge assessments and make sure risks are raised early.
Provide second-line review and concurrence on high-risk new activities.
Write and maintain the ORM standards, procedures and templates that first-line teams execute against.
Support regulatory examinations, audits, and charter readiness reviews

There are lots of paths that could lead you to be successful in a role like this; we think the strongest candidates will have some of this experience:

8+ years in operational risk, compliance, or internal audit at a bank or a fintech partnered with a bank
Hands-on ownership of an issues management or operational event program, including severity rating, escalation, and validation of remediation
Experience administering a GRC platform (LogicGate, Archer, or similar), including workflow configuration and reporting
Strong data skills: you turn raw issue and event data into trends leadership can act on
Familiarity with interagency and OCC expectations for operational risk management
You challenge constructively, with evidence, and keep strong relationships with the teams you oversee
You find, prioritize, and execute key projects independently, balancing program build with daily operations

Mercury values diversity and belonging and is proud to be an Equal Employment Opportunity employer. All individuals seeking employment at Mercury are considered without regard to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, sexual orientation, or any other legally protected characteristic. We are committed to providing reasonable accommodations throughout the recruitment process for applicants with disabilities or special needs. If you need assistance, or an accommodation, please let your recruiter know once you are contacted about a role.

# -AR1

Total Rewards
The total rewards package at Mercury includes base salary, equity (stock options/RSUs), and benefits.

Our salary and equity ranges are highly competitive within the SaaS and fintech industry and are updated regularly using the most reliable compensation survey data for our industry. New hire offers are made based on a candidate’s experience, expertise, geographic location, and internal pay equity relative to peers.

Our target new hire base salary ranges for this role are the following strong:

US employees in New York City, Los Angeles, Seattle, or the San Francisco Bay Area:

span $199,900 span span $249,900 USD

US employees outside of New York City, Los Angeles, Seattle, or the San Francisco Bay Area:

span $179,900 span span $224,900 USD

Canadian employees (any location):

span $189,000 span span $236,200 CAD

Location and market context

This is a remote risk management job, so it draws from a national talent pool rather than a single metro. Remote governance and compliance jobs reward candidates who can show they work effectively across time zones and distributed legal, security, and product teams. Confirm any residency, travel, or occasional-onsite expectations directly with Mercury.

About risk management jobs

Risk jobs own the methodology for identifying, assessing, and escalating enterprise, operational, and technology risk. Second-line teams set risk appetite and challenge the first line. Jobs like this one are typically evaluated against frameworks such as enterprise and operational risk frameworks, NIST AI RMF, and risk-appetite and escalation practices.

How to position yourself for this risk management job

Strong candidates emphasize risk assessment methodology, appetite and escalation, cross-functional partnership, and clear reporting to senior leadership and the board. In your resume and outreach, tie your experience to how Mercury would apply enterprise and operational risk frameworks, NIST AI RMF, and risk-appetite and escalation practices, and lead with concrete outcomes rather than duties.

Similar GRC jobs

More jobs at Mercury

More GRC jobs in San Francisco

Hiring for Risk?

Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.

Post a job  Pricing from $99 · About GRC Careers · Hiring toolkit

Want to be next in a job like this?

Jobs like Senior Operational Risk Manager (remote) open regularly. Be first to know, privately. No current employer ever sees you looking.

New Risk jobs, the moment they post.

One click unsubscribe.
Know your GRC? Take the 2-minute AI Governance Challenge. No signup needed.
Play now →

Employer, or see something wrong with this posting? Report this posting and we will review it promptly.