Skip to content
AGJ, the AI governance job board
Menu

Job description template

Risk Manager

The Risk Manager owns the operating risk program, from risk appetite and assessment methodology to monitoring, reporting, and the team that runs it. This template reflects how the role is scoped at organizations maturing their enterprise risk function, including the risks introduced by AI and automated systems. Replace the [highlighted fields] with your specifics, trim what does not apply, and post.

Download PDF Download reference sheet

TitleRisk Manager
DepartmentEnterprise Risk Management / Risk & Compliance
Reports to[Director of Risk / Chief Risk Officer / Chief Financial Officer]
Location[Remote / Hybrid / On-site]
Employment typeFull-time
Salary[Salary range. Postings with a range perform significantly better, and several states require one.]

Position overview

The Risk Manager leads the operating enterprise risk program at [Company], setting methodology, maintaining the risk appetite framework, and driving assessment, monitoring, and reporting across the business. The role owns program execution and manages the analysts who support it.

The Risk Manager partners with business, technology, security, finance, and compliance leaders to identify significant risks, oversee mitigation, and give leadership a clear, credible view of the risk profile. As AI and automated systems enter operations, this role brings those risks into the same enterprise discipline.

This is a people-leading role for a seasoned risk professional who can pair analytical rigor with practical business judgment and clear executive communication.

Key responsibilities

Risk program ownership

Risk appetite and strategy

Define and operationalize how much risk the organization is willing to take:

Assessment and monitoring

Team leadership

Lead, coach, and develop risk analysts, set clear standards and priorities, and manage workload across assessment, monitoring, and reporting.

Reporting and governance

Third-party and emerging risk

Oversee third-party and vendor risk, and lead assessment and monitoring of emerging risks including those from AI, automated decisions, and new technology.

Resilience and response

Support business continuity, incident escalation, and response coordination so that significant risk events are identified, escalated, and addressed.

Required qualifications

Preferred certifications

One or more of: FRM, PRM, CRISC, CRM, CISA, depending on the risk domain.

Technical knowledge

Enterprise risk management, risk appetite and methodology, risk assessment and monitoring, key risk indicators, risk quantification and scenario analysis, third-party risk, resilience, risk reporting, GRC platforms, and AI and automated-system risk integration.

Essential competencies

People leadership, risk-based decision making, executive communication, stakeholder influence, sound business judgment, program management, and analytical rigor.

Success measures: first 12 months

About [Company]

[Two or three sentences about your organization, the maturity of your program, and what the first year looks like. Candidates in this field respond to honesty about whether they are joining a build or an established function.]

Post this role on GRC Careers

Reach professionals who specialize in enterprise risk management rather than hoping they find you in a general feed. Hand reviewed, live within one business day.

Post this role

See how others are hiring

Review live GRC jobs postings to benchmark scope, level, and posted salary before you publish yours.

Browse GRC jobs

Stay close to the market

Frequently asked questions

What does a Risk Manager do?

A Risk Manager owns the operating enterprise risk program. They set risk methodology and appetite, drive risk assessments and monitoring, report the risk profile to leadership, and lead the risk analysts who support the work.

What qualifications and certifications does a Risk Manager need?

Most Risk Managers have a bachelor's degree, sometimes an advanced degree, and 6 to 9 or more years in risk or audit, including leadership. Common certifications include FRM, PRM, CRISC, and CRM.

Who does a Risk Manager report to?

A Risk Manager typically reports to a Director of Risk, the Chief Risk Officer, or, in some organizations, the Chief Financial Officer, and often supports enterprise risk committees.

How is AI changing the Risk Manager role?

AI and automated decision systems introduce new operational, model, and third-party risks. Risk Managers increasingly bring these into the enterprise risk framework, using references such as the NIST AI Risk Management Framework alongside ISO 31000 and COSO ERM.