Enterprise Risk Officer
Group AMANA · Dubai, United Arab Emirates
قدّم وتابع مع أبلاي إيدجRole Purpose Amana is implementing a group-wide Enterprise Risk Management framework in partnership with a top global consulting firm. This role is the internal owner of that framework — working alongside the external team through design and rollout, then carrying it forward as a permanent in-house capability once the consultants demobilize. Beyond maintaining the framework, the role is expected to advance it: expanding the Key Risk Indicator library and moving the group from periodic manual reporting toward near real-time risk monitoring built on connected internal data. Success is not that a risk register exists. Success is that risk data measurably changes decisions at bid stage, project stage, and Board level. Key Responsibilities Framework & Governance Act as the internal counterpart to the external consulting partner throughout implementation; own documentation, knowledge transfer and formal handover. Maintain the group risk policy, taxonomy, scoring criteria and risk appetite statements; run the annual refresh cycle. Administer the risk register across three levels: corporate, business unit, and major project. Risk Identification & Assessment Facilitate risk workshops and one-to-one interviews with business unit leadership, project directors and functional heads across the UAE, KSA and Qatar. Challenge ratings rather than transcribe them — push back on optimistic likelihood and impact scoring. Maintain Key Risk Indicators, monitor tolerance breaches, and escalate against defined triggers. Project & Commercial Risk Embed risk review into the tender/bid gate process: contract terms, client creditworthiness, liquidated damages exposure, design and scope risk, supply chain and price escalation. Support project teams in establishing and maintaining live risk registers on major awards. Track realized risk events and losses; feed lessons learned back into tender assumptions. KRI Development, Data & Real-Time Monitoring Expand the Key Risk Indicator library well beyond the baseline set delivered at framework design. Indicators must be measurable from data the group already holds, not aspirational metrics nobody can populate. Connect risk data across internal systems — ERP, project controls, procurement, finance, HR and HSE — into a single monitoring layer, replacing manual data collection wherever possible. Build and own the risk dashboard, moving reporting from a quarterly compilation exercise toward continuous, near real-time visibility with automated threshold alerts. Apply AI and automation practically where it removes manual effort or surfaces signal earlier: extracting and classifying data from unstructured sources such as contracts, incident reports and correspondence; anomaly and early-warning detection across project and financial data; and drafting narrative risk commentary from underlying figures. Prototype and iterate directly rather than routing every change through a development backlog. This is a hands-on build role, not a requirements-writing one. Business Continuity & Crisis Management Maintain and periodically test business continuity and crisis management plans. Reporting Produce quarterly risk reporting to the Executive Committee and the Audit & Risk Committee, progressively reducing the manual effort required to produce it. Maintain live risk dashboards for executive and business unit audiences (Power BI or equivalent). Culture & Training Deliver risk awareness training and act as the first point of contact for the business on risk matters. Required Qualifications & Experience Bachelor’s degree in engineering, Finance, Business Administration or a related discipline. An engineering background is an advantage given the construction context. 3–5 years in enterprise risk management, including at least two years in a dedicated ERM role — not general internal audit, QHSE, or compliance. Preferred background: risk advisory at a Big 4 firm (Deloitte, EY, KPMG, PwC), a specialist risk consultancy (Marsh, Aon, WTW, Gallagher, Protiviti), or the in-house risk function of a large GCC contractor, developer, industrial group or government-related entity. Demonstrable GCC experience — UAE and/or KSA — with a working understanding of the regional client, contracting and payment environment. Hands-on experience building or operating a risk register, facilitating risk workshops, and producing board-level risk reporting. Preferred Certifications ISO 31000 practitioner / lead risk manager IRM (Institute of Risk Management) Certificate or Diploma PMI-RMP (project risk) CRMA (Certification in Risk Management Assurance) Certification is not a substitute for operating experience. Candidates working toward one of the above will be considered. Skills & Attributes Genuinely technical. This is not a role for someone whose toolkit ends at Excel and PowerPoint. Required: advanced Excel and Power Query, and demonstrable capability in Power BI or an equivalent BI platform — building data models, not just consuming reports. Practical fluency with AI tools. Able to use large language models and automation to extract, classify and summarise risk data, and to prototype working solutions independently. Candidates should be prepared to describe something they have actually built. Working understanding of how systems exchange data — APIs, integrations, structured versus unstructured sources — sufficient to hold a credible conversation with IT and specify what is needed. SQL or Python literacy is an advantage, though not a hard requirement at this level. Familiarity with GRC or risk management software. Strong facilitation and stakeholder management. The role requires holding a room with business unit MDs and project directors who outrank the incumbent and are skeptical of head-office process. This is the most common failure point in the position. Concise written English; able to compress complexity into a one-page executive view. Arabic is an advantage given KSA operations. Comfortable operating as a single-person function with direct senior sponsorship rather than within a layered team. Success Measures — First 12 Months ERM framework fully transitioned from the external consulting partner with no residual consultancy dependency. Group risk register live, populated across all business units, and refreshed on cycle. Risk review embedded as a mandatory gate in the tender approval process. KRI library materially expanded beyond the framework baseline, with the majority of indicators fed automatically rather than manually compiled. Live risk dashboard in production, drawing from core internal systems, with defined threshold alerts operating. Four quarterly risk reports delivered to the Audit & Risk Committee. Risk appetite statements approved and KRIs monitored on a continuous basis.