Key Responsibilities
Framework amp Governance
- Support the design maintenance and embedding of a consistent MEA Operational Risk Management Framework aligned with enterprise standards and adapted to local regulatory requirements
- Lead coordination of the UAE implementation roadmap for applicable CBUAE operational risk and operational resilience requirements including milestones dependencies deliverables evidence and remediation actions
- Maintain the UAE operational risk regulatory obligations register and evidence matrix while supporting proportionate regulatory mapping across other MEA jurisdictions
- Promote clear governance reporting lines delegated authority and Three Lines of Defence accountability across MEA entities
Risk Identification amp Management
- Facilitate risk and control self-assessments process risk reviews and thematic assessments providing independent second-line review and challenge
- Oversee the quality and completeness of operational risk registers ensuring that risks controls ratings owners actions and target dates are accurate current and evidence based
- Monitor regional and local operational risk profiles against approved risk appetite and tolerance identifying emerging risks and escalating material exposures breaches and overdue remediation
- Support business owners in identifying assessing managing and evidencing operational risks and controls without displacing first-line accountability
Controls Incidents KRIs amp Reporting
- Develop and maintain minimum control standards and support business owners in documenting assessing and improving key controls
- Coordinate operational incident loss event and near-miss reporting including classification root-cause analysis remediation lessons learned and trend analysis
- Develop and monitor Key Risk Indicators thresholds and early-warning measures with clear escalation and action tracking
- Prepare concise dashboards committee papers and regulatory reporting covering risk profile changes control effectiveness incidents losses resilience third-party exposures and implementation progress
Business Continuity amp Operational Resilience
- Support identification of critical operations and services end-to-end dependency mapping impact tolerance setting scenario testing and remediation planning with implementation priority given to the UAE
- Partner with Business Continuity Technology and Cybersecurity teams to align business continuity disaster recovery incident response and resilience testing with applicable local requirements and enterprise standards
- Monitor material resilience vulnerabilities and testing outcomes ensuring that remediation is clearly owned appropriately prioritized and tracked to sustainable closure
Third-Party Risk Management
- Provide second-line oversight of material outsourcing and third-party risks across due diligence onboarding ongoing monitoring concentration risk continuity contingency and exit planning
- Partner with Procurement Legal Technology Cybersecurity and business owners to promote consistent third-party risk and control standards across MEA
- Ensure material third-party exposures incidents and control weaknesses are reflected in risk registers governance reporting and remediation plans
Stakeholder Engagement amp Risk Culture
- Build strong working relationships across MEA business control and enterprise functions with particular focus on delivery of the UAE regulatory programme
- Facilitate risk workshops training and awareness activities that strengthen first-line ownership and consistent application of the ORM framework
- Act as a trusted advisor to the CRO and senior stakeholders across MEA translating complex regulatory requirements into proportionate and practical actions
- Support regulatory reviews internal audit and independent assurance activities coordinating responses and maintaining a complete audit trail
Qualifications
Bachelor's degree in risk management, finance, business, law, technology or a related discipline; an advanced degree is advantageous. Professional certification such as CRISC, CISA, CISM, CBCP, IRM, FRM, PMP or equivalent is preferred.
Experience & Knowledge
Minimum 7 years of relevant experience in operational risk, enterprise risk, internal controls, operational resilience, business continuity, regulatory change or assurance within insurance or financial services. Experience operating across multiple jurisdictions or within a regional, matrixed organization. Demonstrable experience implementing operational risk frameworks and translating regulatory requirements into governance, controls, reporting and evidence. Practical experience with risk assessments, risk registers, control design or assurance, incidents and loss events, KRIs, action tracking and senior-management reporting. Working knowledge of outsourcing and third-party risk, ICT and cyber dependencies, business continuity and operational resilience. Proficiency in Microsoft 365 and risk management or governance platforms; experience with SharePoint, Power BI, Jira, Visio or comparable tools is advantageous.
#J-18808-Ljbffr