On-site Full Time
--
Oman Investment Authority

Job Details

ROLE OBJECTIVE Lead and manage the Enterprise Governance, Risk & Compliance function by establishing and embedding risk, governance, and compliance frameworks across the organization. The role ensures independent second-line oversight, enabling leadership to make informed decisions, while maintaining clear separation from operational execution and accountability.

RESPONSIBILITIES

Enterprise Risk Management (COSO ERM)

  • Establish and continuously enhance the Enterprise Risk Management framework aligned with COSO ERM
  • Define risk taxonomy, scoring methodology, and reporting standards
  • Embed risk appetite and tolerance into business decision-making
  • Maintain enterprise-wide risk registers covering all business units
  • Lead risk identification workshops and risk assessments
  • Ensure proper classification of strategic, operational, IT, compliance, and HSE risks
  • Oversee mitigation planning and track execution progress
  • Monitor high-risk and critical risk exposures
  • Escalate Risks exceeding appetite, Delayed mitigation actions and Emerging systemic risks

Governance & Policy Management

  • Design and maintain enterprise governance structures and frameworks
  • Develop policies covering: Risk management, Compliance, Internal controls and Governance standards
  • Ensure structured policy lifecycle: Drafting, Review, Approval, Periodic updates
  • Ensure alignment with Regulatory requirements, Industry best standards and Organizational strategy
  • Promote governance awareness across all business units
  • Ensure accountability and ownership at first-line level

Compliance Oversight

  • Establish compliance framework and obligation register
  • Map regulatory and contractual requirements across functions
  • Monitor compliance adherence across organization
  • Track compliance breaches, policy violations, control failures
  • Ensure timely escalation and resolution
  • Collaborate with Legal (support function) for Regulatory interpretation, and Legal risk insights
  • Ensure legal risks are reflected in enterprise risk reporting

Risk Reporting, Analytics & Decision Support

  • Develop Risk dashboards, Risk heatmaps and Compliance reports
  • Provide consolidated enterprise risk view to leadership
  • Prepare risk reports for executive management and Board / Committee
  • Identify emerging and forward-looking risks
  • Provide scenario-based insights for decision-making

Integration with QA & HSE

  • Work closely with QA & HSE to integrate quality and safety risks into ERM and align reporting and escalations
  • Ensure systemic issues are identified and cross-functional risks are addressed
  • Support integrated enterprise assurance approach

Leadership & Team Development

  • Lead and manage GRC team
  • Define team structure and capabilities (e.g., risk specialists)
  • Set KPIs, performance standards, and accountability
  • Define competency matrices, certification roadmaps, and continuous learning plans.
  • Champion best practices in solutioning, storytelling, and commercial awareness.

Desired Candidate Profile

ROLE SPECIFICATIONS

Qualification

Bachelor s / Master s in Risk Management, Business Administration, Finance / Accounting, Law or relevant

Certification

Certified Risk Manager (CRM / CRMP)
Certified Internal Auditor (CIA)
ISO 31000 / 9001 Lead Auditor
Compliance certification (CCEP)

Experience

10+ years in Enterprise Risk Management, Governance / Compliance and Internal Audit / Assurance
Experience in ICT / infrastructure / telecom strongly preferred

Skills

Enterprise Risk Management (COSO ERM)
Governance frameworks & policy design
Compliance program management
Data analysis & reporting
Stakeholder management
Decision-making & risk advisory

Competency Type

Competency
Leadership Impactful Decisions
Leadership Leading team and performance
Leadership Strategic Mindset
Behavioural Collaboration
Behavioural Planning & coordination
Behavioural Negotiation
Behavioural Achievement orientation
Behavioural Personal effectiveness
Core Integrity & Ethical behaviour
Core Operational excellence
Core Effective communication
Core Stakeholder management
Core Creativity & innovation

Technical

COSO ERM
Internal control frameworks
Compliance frameworks
Risk analytics & reporting

Similar Jobs