Enterprise Risk Manager
Full TimeJob Overview
As we continue to scale our operations globally, we are seeking a strategic and hands-on Enterprise Risk Manager to architect and lead our internal Enterprise Risk Management (ERM) function.
Reporting directly to the Chief Legal Officer, you will move beyond simple compliance to engineer a robust risk framework that supports our growth. You will collaborate with senior leadership to identify, assess, and mitigate risks, ensuring our risk posture satisfies not only our internal standards but also the rigorous third-party risk requirements of our banking and financial services clientele.
What Will You Be Involved With?
1. ERM Strategy & Framework Design
- Engineer the Function: Design, implement, and maintain a right-sized Enterprise Risk Management framework (aligned with ISO 31000 or COSO) tailored to a midsized global software company.
- Risk Governance: Establish risk policies, tolerance levels, and standard operating procedures that align with corporate strategy and legal requirements.
- Culture of Risk: Champion a proactive risk culture across global offices, training department heads on how to own and manage risk within their verticals.
2. Risk Identification & Reporting
- The Risk Register: Build and maintain a comprehensive, living Enterprise Risk Register. Facilitate quarterly risk assessments with senior management to identify emerging threats (Including Cyber, Operational, Geopolitical, Regulatory, and Strategic).
- Reporting: Create executive-level dashboards and reports for the CLO, Executive Committee, and the Board of Directors, providing clear visibility into the company’s risk profile and mitigation progress.
- Global Scope: Monitor geopolitical and operational risks associated with our global footprint, ensuring continuity of operations across international time zones.
3. Commercial & Client Assurance Support
- Vendor Due Diligence: Act as a subject matter expert during the sales cycle. Assist the Sales and Security teams in navigating complex vendor risk assessments and due diligence questionnaires required by our Tier-1 financial services customers.
- Compliance Alignment: Work closely with Legal and InfoSec to ensure our risk controls map to key standards (SOC 2, ISO 27001, GDPR, and incoming regulations like EU DORA) that matter to our clients.
4. Business Continuity & Incident Management
- Oversee the Business Continuity Planning (BCP) and Disaster Recovery (DR) governance, ensuring plans are tested annually.
- Partner with Legal to manage the risk aspects of insurance renewals and coverage adequacy.
What Will You Bring to the Table?
- Experience: 5–8+ years of experience in Risk Management, Internal Audit, or GRC (Governance, Risk, and Compliance).
- Industry Background: Must have experience working within the Technology/SaaS sector OR within Financial Services. You must understand the unique pressure points of selling software to regulated banks.
- Education: Bachelor’s degree in Business, Finance, Legal Studies, or a related field.
- Builder Mindset: Proven ability to build a function from scratch ("engineer the operations") rather than just maintaining an existing legacy process.
- Communication: Exceptional ability to translate complex risk concepts into business language for the C-Suite and Legal teams.
Preferred Qualifications ("Nice to Haves")
- Certifications such as CRISC, ARM, CISA, or CISSP.
- Experience with GRC software platforms (e.g., LogicGate, ServiceNow, Vanta).
- Familiarity with financial regulations (GLBA, NYDFS 500) or international frameworks (GDPR, DORA).
Make Your Resume Now