- Experience
- 3–5 yrs
- Salary
- —
- Openings
- 1
- Posted
- 4 weeks ago
- Work mode
- In office
- Education
- Bachelor’s degree
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Role Overview
Group AMANA is implementing an enterprise-wide risk management system in partnership with a leading global consultancy. The Enterprise Risk Officer will serve as the in-house custodian of this framework, collaborating closely with the external consultants through the development and deployment phases, then autonomously managing and enhancing the system post-consultancy. The focus is on ensuring that risk data actively influences key decisions across bidding, project execution, and governance levels.
Key Duties and Responsibilities
- Act as the internal liaison and owner of documentation, knowledge transfer, and formal handover processes with external consultants.
- Maintain and update the group’s risk policy, classification system, scoring methods, and risk appetite, including overseeing the annual update cycle.
- Manage the risk register at corporate, business unit, and project levels.
- Conduct risk identification sessions including workshops and interviews with leadership across UAE, KSA, and Qatar.
- Critically evaluate risk ratings to ensure realistic assessment of likelihood and impact.
- Develop and monitor Key Risk Indicators (KRIs), escalating issues when defined thresholds are breached.
- Integrate risk assessments into tender and bid processes, reviewing contract terms, client credit risk, potential liabilities, design risks, supply chain vulnerabilities, and price escalation concerns.
- Support project teams to maintain dynamic risk registers on major contracts.
- Track actual risk events and losses and ensure lessons are incorporated into future tender assumptions.
- Expand the KRI library with measurable indicators from existing internal data sources.
- Develop a continuous risk monitoring dashboard by linking data from internal systems such as ERP, project controls, procurement, finance, HR, and health & safety, minimizing manual data collection.
- Leverage AI and automation tools practically for early detection and reporting, including analyzing unstructured data and generating narrative explanations.
- Directly prototype and implement improvements and solutions without relying solely on formal development requests.
- Maintain and periodically test business continuity and crisis management plans.
- Produce comprehensive quarterly risk reports for the Executive and Audit & Risk Committees, progressively automating reporting processes.
- Operate live risk dashboards for executives and business units, using platforms such as Power BI.
- Deliver risk awareness training and serve as the primary point of contact for all risk-related inquiries within the business.
Required Qualifications & Experience
- Bachelor’s degree in Engineering, Finance, Business Administration, or a related field; engineering background preferred considering construction context.
- Three to five years of enterprise risk management experience, including at least two years dedicated solely to ERM roles (excluding internal audit, QHSE, or compliance).
- Preferred experience includes working at leading risk advisory firms, specialist consultancies, or in-house risk teams of large GCC contractors, developers, industrial groups, or government entities.
- Proven track record of experience within the GCC region, specifically UAE and/or KSA, with an understanding of local client and contracting environments.
- Hands-on experience with risk registers, facilitating risk workshops, and preparing reports suitable for board-level review.
Preferred Certifications
- ISO 31000 Practitioner or Lead Risk Manager
- Institute of Risk Management (IRM) Certificate or Diploma
- Project Management Institute Risk Management Professional (PMI-RMP)
- Certification in Risk Management Assurance (CRMA)
Note: Certifications are advantageous but not a replacement for operational experience. Candidates actively pursuing these qualifications will be considered.
Skills & Competencies
- Advanced technical proficiency beyond basic Excel and PowerPoint, including expert-level Excel, Power Query, and demonstrable competence in Power BI or other business intelligence platforms with data modeling capabilities.
- Practical understanding and application of AI tools, including large language models and automation for data extraction, classification, summarization, and prototype development.
- Knowledge of data integration, APIs, and handling structured/unstructured data sufficient to collaborate with IT teams; SQL or Python skills are beneficial but not mandatory.
- Experience with governance, risk, and compliance (GRC) or risk management software.
- Strong facilitation skills and stakeholder management to influence senior leaders and skeptical stakeholders effectively.
- Excellent written communication skills with the ability to distill complex information into concise, one-page executive summaries.
- Arabic language skills are an asset, particularly for operations in KSA.
- Ability to operate as a solo function with direct senior leadership support, rather than as part of a large team.
Success Criteria for First Year
- Complete transition and independent management of the ERM framework with no further reliance on consultants.
- Fully operational group risk register encompassing all business units with regular updates.
- Mandatory integration of risk assessments within the tender approval procedures.
- Significant expansion of the KRI library, with most indicators automated rather than manually maintained.
- Deployment of a live risk dashboard integrating core internal systems and delivering automated threshold alerts.
- Completion of four quarterly risk reports submitted to the Audit & Risk Committee.
- Formal approval and ongoing monitoring of risk appetite statements and KRIs.
Minimum education
Bachelor's Degree