About the Role
The Manager – GRC Services (Risk Management) is responsible for the day-to-day delivery of risk management advisory engagements. This role leads engagement teams to design, implement, and enhance enterprise and operational risk frameworks for clients. Reporting to the Director – GRC Services, the position combines hands-on technical delivery with team leadership, client relationship management, and support for business development. The Manager ensures that engagements are delivered to a high standard, on time, and within budget.
Ready to apply for roles like this?
Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.
Unlock employer & apply directly
Responsibilities
- Lead the assessment, design, and implementation of operational, strategic, financial, and emerging-risk frameworks aligned to ISO 31000, COSO ERM, and relevant regulatory expectations.
- Plan, manage, and deliver risk management engagements, including enterprise risk management (ERM) framework design, risk appetite and tolerance setting, risk and control self-assessments, key risk indicators, and risk reporting.
- Develop risk registers, heat maps, risk appetite statements, policies, procedures, and governance structures tailored to client needs.
- Manage engagement scope, timelines, budgets, deliverables, and quality, escalating issues to the Director as needed.
- Act as a primary day-to-day client contact, building strong working relationships with risk, audit, and operational stakeholders.
- Present findings, recommendations, and deliverables clearly to management and, where appropriate, board and committee audiences.
- Lead, coach, and review the work of consultants and analysts, providing direction, feedback, and on-the-job development.
- Manage resourcing and workload allocation across concurrent engagements.
- Support proposal development, scoping, and pricing for risk management opportunities.
- Identify follow-on and cross-service opportunities within existing accounts.
Skills
- Strong risk-management technical skills across ERM, operational, and emerging risk.
- Project and engagement management, including scope, budget, and quality control.
- Client relationship management and clear written and verbal communication.
- Team leadership and coaching skills.
Tools Experience
- GRC and risk management platforms (e.g. ServiceNow GRC, RSA Archer, or equivalent).
- Reporting and BI tools (e.g. Power BI, Tableau) and advanced Excel for risk analytics and dashboards.
- Risk register, heat-map, and KRI/KPI tooling.
- Microsoft 365 or equivalent productivity and collaboration suites.
Qualifications
- Minimum 7 years of relevant risk-management experience, including experience in a consulting or advisory environment.
- Minimum 2 years managing engagement and teams end-to-end.
- Demonstrated experience designing or implementing ERM frameworks, risk appetite, and control assessments.
- Experience supporting national/sector-wide cyber risk and maturity programmes—such as the National Cybersecurity Index Program—including cyber risk scoring, maturity assessment, and KRI/KPI design, is strongly preferred.
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- Master’s degree preferred.