Apply Edge Start your job search

Manager-Internal Audit & Risk Management- Saudi Nationals

Aljomaih Energy and Water Company · Riyadh, Riyadh, Saudi Arabia

Apply & track with Apply Edge
Aljomaih Energy and Water Company (AEW) develops, invests in, owns and operates conventional power generation, renewable power and water desalination assets in the Kingdom of Saudi Arabia and the wider region largely through project-specific special purpose vehicles (SPVs) and joint ventures with domestic and international partners.The Internal Audit & Risk Management function provides independent and objective assurance and advisory services designed to add value and improve AEW's operations. The function reports functionally to the Board Audit Committee and administratively to the Chief Executive Officer.This role supports the Head of Internal Audit & Risk Management across corporate functions, project companies and joint venture entities and is expected to operate credibly with senior management, external auditors, regulators, lenders and shareholder representatives.OverviewThe Manager, Internal Audit & Risk Management plays a critical role in upholding AEW's ethical, governance and operational integrity. The role plans and executes risk-based internal audits, supports the design and operation of the Enterprise Risk Management (ERM) framework, and advises management on effective risk mitigation and control improvement.The role requires a proactive mindset, strong analytical and report-writing skills, sound judgement in sensitive situations and a working understanding of the utilities development industry - in particular conventional power, renewable power and water projects and the contractual and financing structures through which they are delivered.Your Job Functions (Duties & Responsibilities) Internal Audit Plan & Execute: Support the Head of Internal Audit & Risk Management in developing the annual risk-based internal audit plan and independently manage and execute internal audits engagement within your assigned area of responsibility.Evaluate & Improve: Conduct comprehensive audits of various business functions, processes and controls, evaluating their effectiveness and identifying areas for improvement.Compliance & Reporting: Assess compliance with relevant laws, regulations and company policies, and prepare clear and concise audit reports that communicate findings, recommendations and remediation plans to senior management and the Board Audit Committee.Follow-up & Monitoring: Monitor and track the implementation of agreed-upon audit recommendations, ensuring timely and effective resolution of identified issues. Policies and Procedures Review: Assist in the review and improvement of company-wide policies, procedures, and management practices. Project, Contract and Capital Expenditure Audits Audit the project development lifecycle from origination and bid through to financial close, construction, commissioning and handover to operations. Contract Assurance: Review compliance with EPC, O&M, PPA/WPA, shareholder and financing agreements, including obligations, milestones, liquidated damages, warranties, insurance and reporting covenants.Capex & Claims: Verify progress payments, variation orders, claims, change management and contingency utilization against contractual entitlement and approved budgets.SPV & JV Governance: Assess governance, delegation of authority and control arrangements at project companies and joint ventures, including access rights available to AEW under shareholder agreements.Risk Management Plan & Execute: Support the Head of Internal Audit & Risk Management in developing the annual plan to support, manage and execute risk management engagements within your assigned area of responsibilityERM Framework: Collaborate with the Head of Internal Audit & Risk Management and senior management to develop, implement & maintain the company's ERM framework, encompassing risk identification, assessment, mitigation and monitoring processes.Risk Assessment & Mitigation: Conduct regular risk assessments to identify and evaluate potential risks facing the company, considering likelihood, impact and cascading effects. Develop and implement effective risk mitigation plans aligned with the overall ERM strategy and internal controls framework.Risk Communication & Monitoring: Maintain an updated risk register and ensure consistent communication of risks to relevant stakeholders. Integrate risk management activities with internal audit processes.Emerging Risks: Analyze emerging risks and trends, proactively adapt the ERM framework and annual plans to address them.Advisory and Ad hoc EngagementEnsure the smooth and effective execution of all Ad hoc or advisory engagements once assigned within expected turnaround time and quality of deliverables.Qualifications and RequirementsBachelor's degree in accounting, Finance, Business Administration, Engineering or a related discipline.Master's degree or MBA preferred.Eight to ten years of relevant professional experience, of which a minimum of four to five years in internal audit, risk management or external audit.Experience with a Big Four firm, leading professional services firm or similar industry is preferred.Demonstrated exposure to IPP/IWP structures, project SPVs, joint ventures, EPC and O&M contracts and project finance is strongly preferred.Track record of reporting to, or presenting at, an Audit Committee or equivalent governance forum.CertificationsCertified Internal Auditor (CIA) required or actively pursuing with completion within an agreed timeframe.One or more of the following is preferred: SOCPA, CPA, ACCA, CRMA, CFE, CISA or PMP.ISO 31000 risk management training is an advantage.COSO Internal Control - Integrated Framework (2013) and COSO Enterprise Risk Management - Integrating with Strategy and Performance (2017).Understanding of NCA Essential Cybersecurity Controls, Saudi Companies Law, applicable corporate governance regulations, ZATCA requirements and IFRS as endorsed in Saudi Arabia.