| Title | Risk Manager |
|---|---|
| Department | Enterprise Risk Management / Risk & Compliance |
| Reports to | [Director of Risk / Chief Risk Officer / Chief Financial Officer] |
| Location | [Remote / Hybrid / On-site] |
| Employment type | Full-time |
| Salary | [Salary range. Postings with a range perform significantly better, and several states require one.] |
Position overview
The Risk Manager leads the operating enterprise risk program at [Company], setting methodology, maintaining the risk appetite framework, and driving assessment, monitoring, and reporting across the business. The role owns program execution and manages the analysts who support it.
The Risk Manager partners with business, technology, security, finance, and compliance leaders to identify significant risks, oversee mitigation, and give leadership a clear, credible view of the risk profile. As AI and automated systems enter operations, this role brings those risks into the same enterprise discipline.
This is a people-leading role for a seasoned risk professional who can pair analytical rigor with practical business judgment and clear executive communication.
Key responsibilities
Risk program ownership
- Own the enterprise risk management framework and methodology.
- Maintain the risk assessment cycle and risk register.
- Set program priorities aligned to the business.
- Report the risk profile to leadership and committees.
Risk appetite and strategy
Define and operationalize how much risk the organization is willing to take:
- Maintain the risk appetite and tolerance framework.
- Align risk taking with strategy and objectives.
- Advise leaders on the risk implications of major decisions.
- Integrate AI and automated-system risk into enterprise risk.
Assessment and monitoring
- Oversee risk assessments across the enterprise.
- Maintain key risk indicators and thresholds.
- Monitor mitigation and escalate significant exposures.
- Strengthen the environment based on trends and events.
Team leadership
Lead, coach, and develop risk analysts, set clear standards and priorities, and manage workload across assessment, monitoring, and reporting.
Reporting and governance
- Produce risk reports, heat maps, and dashboards for leadership.
- Support risk committees and governance forums.
- Maintain risk methodology and documentation.
- Ensure consistent risk data and quality across the program.
Third-party and emerging risk
Oversee third-party and vendor risk, and lead assessment and monitoring of emerging risks including those from AI, automated decisions, and new technology.
Resilience and response
Support business continuity, incident escalation, and response coordination so that significant risk events are identified, escalated, and addressed.
Required qualifications
- Bachelor's degree in Finance, Business, Economics, Information Systems, or a related field. Advanced degree a plus.
- 6 to 9+ years of risk management, audit, or related experience, including program or people leadership.
- Strong knowledge of frameworks such as ISO 31000 and COSO ERM.
- Experience owning risk assessment, appetite, and monitoring programs.
- Track record presenting risk to senior leadership and committees.
- Strong leadership, analytical, and communication skills.
Preferred certifications
One or more of: FRM, PRM, CRISC, CRM, CISA, depending on the risk domain.
Technical knowledge
Enterprise risk management, risk appetite and methodology, risk assessment and monitoring, key risk indicators, risk quantification and scenario analysis, third-party risk, resilience, risk reporting, GRC platforms, and AI and automated-system risk integration.
Essential competencies
People leadership, risk-based decision making, executive communication, stakeholder influence, sound business judgment, program management, and analytical rigor.
Success measures: first 12 months
- Refresh the enterprise risk assessment and program plan.
- Strengthen the risk appetite and tolerance framework.
- Implement or improve key risk indicators and monitoring.
- Stand up clear risk reporting and dashboards for leadership.
- Integrate AI and automated-system risk into enterprise risk.
- Reduce overdue or unmitigated high risks.
- Develop the risk team's skills and coverage.
- Improve the credibility and consistency of risk data.
About [Company]
[Two or three sentences about your organization, the maturity of your program, and what the first year looks like. Candidates in this field respond to honesty about whether they are joining a build or an established function.]
Post this role on GRC Careers
Reach professionals who specialize in enterprise risk management rather than hoping they find you in a general feed. Hand reviewed, live within one business day.
See how others are hiring
Review live GRC jobs postings to benchmark scope, level, and posted salary before you publish yours.
Stay close to the market
Job alerts
Get new GRC jobs roles sent to you as they post.
Newsletter
Hiring trends, salary signals, and new templates from GRC Careers.
Frequently asked questions
What does a Risk Manager do?
A Risk Manager owns the operating enterprise risk program. They set risk methodology and appetite, drive risk assessments and monitoring, report the risk profile to leadership, and lead the risk analysts who support the work.
What qualifications and certifications does a Risk Manager need?
Most Risk Managers have a bachelor's degree, sometimes an advanced degree, and 6 to 9 or more years in risk or audit, including leadership. Common certifications include FRM, PRM, CRISC, and CRM.
Who does a Risk Manager report to?
A Risk Manager typically reports to a Director of Risk, the Chief Risk Officer, or, in some organizations, the Chief Financial Officer, and often supports enterprise risk committees.
How is AI changing the Risk Manager role?
AI and automated decision systems introduce new operational, model, and third-party risks. Risk Managers increasingly bring these into the enterprise risk framework, using references such as the NIST AI Risk Management Framework alongside ISO 31000 and COSO ERM.