As a Senior Associate - Audit, Compliance & Operational Risk, you will help build and operationalize governance, risk, and compliance within the Legal and Compliance organization, reporting directly to the Operational Risk and Audit Manager. Distinct from the firm's Information and Technology GRC function, this role will focus on strengthening the audit, risk, and compliance program through control assessments, risk assessments, policy development, remediation, and practical improvements to processes and controls.
Sitting at the intersection of operational risk, compliance, and audit, you will partner closely with business, operational, and compliance stakeholders and help translate governance, risk, and controls into clear business language for leadership, auditors, and investors. This is not a checkbox compliance role; it requires genuine audit, risk, or compliance expertise and the ability to understand how systems and processes actually work.
You will also help strengthen the Legal and Compliance organization's three-lines-of-defense model, serving as a key interface across Compliance, Operational Risk, Internal Audit, and Legal.
As part of the Compliance department, you will have broad exposure to the firm's trading, operations, and research groups, navigate issues related to the firm's investment products in a fast-paced, evolving regulatory environment, and help develop policies and procedures to manage and mitigate regulatory requirements.
This role is hybrid, with an expectation of working in our Berkeley office at least three days per week.
ResponsibilitiesRisk- Contribute to the risk universe, program and plan;
- Contribute to foundation of governance, risk and controls by completing risk reviews, documenting process, and key controls for selected areas;
- Assisting with raising and tracking of gaps and enhancements, identifying owners, developing actions plans, tracking remediation and closure.
- Document risk processes, procedures, and operational workflows - build the institutional knowledge base
Audit- Contribute to the internal audit charter, audit universe, and multi-year risk-based plan;
- Plan and execute scoped audits with oversight: scoping, walkthroughs, control design assessment, testing, reporting, and remediation follow-up.
- Assisting with raising and tracking of gaps and enhancements, identifying owners, developing actions plans, tracking remediation and closure.
- Independently managing the SOC project including: coordination with audit teams, document requests facilitation, review and preparation of audit materials to support SOC efforts, own the SOC check-ins and updates
- Document audit processes, procedures, and operational workflows - build the institutional knowledge base
Compliance- Assisting with developing compliance policy lifecycle: creation, review, updates, and enforcement across the organization
- Assist with compliance tasks and ad hoc projects as needed such as day-to-day adminstration of the Compliance Program, compliance training, ad hoc compliance requests and reviews
- Assist with compliance follow up remediation efforts and tracking
- Document compliance processes, procedures, and operational workflows - build the institutional knowledge base
Requirements- 2-5+ years of experience in audit, risk, or compliance with meaningful GRC depth - not pure audit/compliance
- Demonstrated ability to write policies grounded in technical reality - you understand how process, risk and controls work, not just what controls should exist on paper
- Experience working with or maturing a governance, risk and compliance program: risk registers, risk assessments, control mapping, remediation tracking
- Familiarity with risk assessment methodologies (COSO, or equivalent)
- Experience interfacing with operational risk, internal audit, legal, and compliance functions - comfortable navigating multi-stakeholder governance relationships
- Strong understanding of compliance and operational processes and controls
- Experience creating investor-facing or board-level security materials is a plus -
- Excellent written and verbal communication - policies, risk narratives, and executive summaries are primary deliverables
- Experience with vendor risk management and third-party due diligence questionnaires
- Self-directed and autonomous - this is a individual contributor role to start; you will prioritize and execute without a team
Preferred Qualifications- Experience with compliance frameworks (SOC 1, COSO and/or Rule 206 (4) - 7 or equivalent) and the practical work of achieving or maintaining compliance
- Background in financial services, hedge funds, or regulated environments with investor due diligence requirements
- Familiarity with automated compliance platforms
- Experience with operational risk
- Experience working in a quasi-academic, engineering-heavy culture where credibility is earned through demonstrated expertise, not authority
"Friends of Voleon" Candidate Referral Program If you have a great candidate in mind for this role and would like to have the potential to earn $7,500 if your referred candidate is successfully hired and employed by The Voleon Group, please use this form to submit your referral. For more details regarding eligibility, terms and conditions please make sure to review the Voleon Referral Bonus Program.