Head of Risk Management
Reporting to the Group General Counsel, who oversees Legal, Compliance, Data Protection and Risk Management, the role ensures that strategic, operational, financial, legal, regulatory, and reputational risks are identified, assessed, and monitored across the organization.
This position focuses on risk assessment, monitoring, and mitigation coordination . The Group Risk Manager works closely with business units, Compliance, Legal, and Data Protection teams to promote a strong risk culture.
Reporting to the Group General Counsel, who oversees Legal, Compliance, Data Protection and Risk Management, the role ensures that strategic, operational, financial, legal, regulatory, and reputational risks are identified, assessed, and monitored across the organization.
This position focuses on risk assessment, monitoring, and mitigation coordination . The Group Risk Manager works closely with business units, Compliance, Legal, and Data Protection teams to promote a strong risk culture.
Key Responsibilities
Enterprise Risk Management
- Maintain and update the Group risk sheet register and risk assessment methodologies together with the relevant Risk owner.
- Monitor the grouper risk methodology and update according to group directive.
- Lead periodic risk identification and assessment exercises across subsidiaries and business units.
- Support with the identification of emerging and strategic risks affecting the Group's objectives.
- Support development of risk mitigation plans and monitor their implementation (without performing control testing).
Risk Governance
- Assist with risk reporting to Executive Management and the Management and Supervisory Board.
- Facilitate risk committees and cross-functional risk reviews.
- Support definition of risk appetite and tolerance levels with senior management.
Regulatory & Legal Risk
- Collaborate with Legal and Compliance teams to assess regulatory, litigation, and compliance risks.
- Monitor relevant regulatory developments and advise on potential impacts.
- Participate in crisis management from a risk perspective where required.
Data Protection & Information Risk
- Coordinate with the Data Protection Officer on privacy and cybersecurity risk assessments.
- Contribute to information risk mapping and mitigation plans.
Business Continuity & Crisis Management
- Support the development and maintenance of Business Continuity plans.
- Participate in crisis preparedness exercises and risk scenario analysis.
Risk Culture & Awareness
- Promote awareness of risk management principles across the organization.
- Deliver training and guidance for risk owners and business managers.
- Embed risk-based thinking into decision-making processes.
Qualifications & Experience
- Master's degree in Law, Risk Management, Finance, Business Administration, or related field.
- Minimum 7 years of relevant experience in Enterprise Risk Management, Compliance, Legal, or Internal Audit ideally including an experience in a highly regulated business environment.
- Experience in a multi-entity or international environment preferred.
- Professional certifications (FRM, CRMA, ISO 31000, or equivalent) are a plus.
Skills & Competencies
- Strong knowledge of Enterprise Risk Management frameworks (e.g., COSO ERM, ISO 31000).
- Clear understanding of the distinction between risk management and internal control/audit.
- Ability to work across functions and influence stakeholders at all levels within the business.
- Analytical and problem-solving skills.
- Excellent communication and reporting abilities.
- High ethical standards and sound professional judgment.
Key Interfaces
- Risk owner/Operational Director
- Internal Audit Director
- Finance and Business Unit Management
- Management Board