| Title | Operational Risk Manager |
|---|---|
| Department | Operational Risk / Enterprise Risk Management |
| Reports to | [Head of Operational Risk / Chief Risk Officer / VP of Risk] |
| Location | [Remote / Hybrid / On-site] |
| Employment type | Full-time |
| Salary | [Salary range. Postings with a range perform significantly better, and several states require one.] |
Position overview
The Operational Risk Manager runs [Company]'s operational risk program, applying the framework and methods that help the organization identify, assess, and manage risks arising from people, processes, systems, and external events.
The role partners with business units, compliance, technology, and internal audit to run risk and control self-assessments, track loss events, monitor Key Risk Indicators, and drive control improvements.
As operational and third-party dependencies grow more complex, the Operational Risk Manager helps the organization understand and reduce operational risk in line with Basel and COSO expectations.
Key responsibilities
Operational risk framework
- Apply and maintain the operational risk framework.
- Support risk appetite and tolerance for operational risk.
- Align practices with Basel and COSO expectations.
- Maintain operational risk policies and procedures.
Risk and control self-assessment
Facilitate risk and control self-assessments (RCSA) across business units, including:
- Identification of key processes and risks
- Assessment of control design and effectiveness
- Rating of residual risk and gaps
- Agreement of remediation actions and owners
Loss events and incidents
- Capture and analyze operational loss events.
- Investigate root causes and control failures.
- Track remediation and lessons learned.
- Report loss trends to risk leadership.
Key Risk Indicators
Define, monitor, and report Key Risk Indicators (KRIs) for operational risk, escalating threshold breaches and emerging concerns to leadership.
Controls and remediation
Assess control effectiveness, identify gaps, and work with business owners to design and implement control improvements and corrective actions.
Third-party and resilience
- Support third-party and outsourcing risk assessment.
- Contribute to business continuity and resilience.
- Assess process and technology dependencies.
- Support scenario analysis for operational risk.
Reporting and analytics
Prepare operational risk reporting and analytics for leadership and risk committees, including dashboards, heat maps, and trend analysis.
Required qualifications
- Bachelor's degree in Risk Management, Finance, Business, or a related discipline.
- 5 to 8+ years of experience in operational risk, internal control, audit, or a related field.
- Experience facilitating RCSA and analyzing loss events.
- Working knowledge of operational risk frameworks and control concepts.
- Strong analytical and documentation skills.
- Experience with GRC tools and risk reporting preferred.
Preferred certifications
One or more of: FRM, PRM, or an operational risk management (ORM) certification.
Technical knowledge
Operational risk management, risk and control self-assessment, loss event analysis, Key Risk Indicators, control assessment, root cause analysis, third-party risk, business continuity, scenario analysis, and GRC platforms, aligned to Basel and COSO expectations.
Essential competencies
Analytical rigor, attention to detail, stakeholder engagement, clear communication, problem solving, and the ability to influence control owners.
About [Company]
[Two or three sentences about your organization, the maturity of your program, and what the first year looks like. Candidates in this field respond to honesty about whether they are joining a build or an established function.]
Post this role on GRC Careers
Reach professionals who specialize in operational risk management rather than hoping they find you in a general feed. Hand reviewed, live within one business day.
See how others are hiring
Review live GRC jobs postings to benchmark scope, level, and posted salary before you publish yours.
Stay close to the market
Job alerts
Get new GRC jobs roles sent to you as they post.
Newsletter
Hiring trends, salary signals, and new templates from GRC Careers.
Frequently asked questions
What does an Operational Risk Manager do?
The Operational Risk Manager runs the day-to-day operational risk program. They facilitate risk and control self-assessments, analyze loss events, monitor Key Risk Indicators, and work with the business to close control gaps.
What qualifications and certifications does an Operational Risk Manager need?
Most bring 5 to 8 or more years in operational risk, internal control, or audit. Helpful certifications include FRM, PRM, and operational risk management credentials, along with a degree in risk, finance, or business.
Who does an Operational Risk Manager report to?
The role typically reports to the Head of Operational Risk, the Chief Risk Officer, or a VP of Risk, and partners with business units, compliance, technology, and internal audit.
What frameworks does an Operational Risk Manager use?
Common reference points include Basel operational risk expectations, COSO for internal control and enterprise risk, and ISO 31000, supported by the NIST Cybersecurity Framework for technology-related risk.