| Title | VP of Enterprise Risk Management |
|---|---|
| Department | Enterprise Risk Management |
| Reports to | [Chief Risk Officer / Chief Financial Officer / Board Risk Committee] |
| Location | [Remote / Hybrid / On-site] |
| Employment type | Full-time |
| Salary | [Salary range. Postings with a range perform significantly better, and several states require one.] |
Position overview
The VP of Enterprise Risk Management leads [Company]'s enterprise risk program, providing the framework, methods, and reporting that help the organization identify, assess, and manage risk across all categories.
The VP partners closely with executive leadership, business units, finance, compliance, internal audit, and technology to set risk appetite, run enterprise risk assessments, monitor key risks, and support risk-informed decision making.
As organizations face a broader and faster-moving risk landscape, the VP of Enterprise Risk Management serves as a senior authority on ERM and the integration of risk into strategy and operations.
Key responsibilities
ERM framework and strategy
- Own and evolve the enterprise risk management framework.
- Align the ERM program with COSO ERM and ISO 31000.
- Establish risk appetite, tolerance, and limits with leadership.
- Integrate risk into strategy, planning, and decision making.
- Present enterprise risk updates to leadership and the Board.
Risk assessment
Lead enterprise risk assessments across risk categories, including:
- Strategic, financial, and operational risk
- Compliance, legal, and regulatory risk
- Technology, cyber, and third-party risk
- Emerging and reputational risk
Risk monitoring and KRIs
- Define and track Key Risk Indicators (KRIs).
- Maintain the enterprise risk register.
- Monitor changes in the risk profile and environment.
- Escalate emerging and threshold breaches to leadership.
Reporting and dashboards
Develop enterprise risk reporting for executive leadership and the Board, including risk dashboards, heat maps, top risk summaries, and trend analysis that support informed oversight.
Risk culture and training
Advance a strong risk culture across the organization through training, risk champions, and embedding risk practices into business processes and the first line of defense.
Business continuity and resilience
- Coordinate business continuity and resilience planning.
- Assess concentration and third-party risk.
- Support crisis management and scenario planning.
- Align risk with insurance and mitigation strategies.
Program leadership
Lead the enterprise risk team, manage risk governance committees, and coordinate the three lines of defense across risk, compliance, and internal audit.
Required qualifications
- Bachelor's degree in Risk Management, Finance, Business, Economics, or a related discipline. Master's degree preferred.
- 10 to 15+ years of progressive experience in enterprise risk, financial risk, or operational risk.
- 5+ years leading risk teams or ERM programs.
- Experience briefing executive leadership and Board committees.
- Strong knowledge of COSO ERM and ISO 31000.
- Track record of building or maturing ERM programs in complex organizations.
Preferred certifications
One or more of: FRM, PRM, CRISC, or CRMA.
Technical knowledge
Enterprise risk management, COSO ERM, ISO 31000, risk appetite and tolerance, risk assessment methodologies, Key Risk Indicators, risk quantification, business continuity, third-party risk, scenario analysis, GRC platforms, and risk reporting.
Essential competencies
Strategic leadership, executive communication, Board presentation skills, risk-based decision making, analytical rigor, program management, change leadership, and negotiation and influence.
Success measures: first 12 months
- Assess and refresh the ERM framework.
- Establish or update enterprise risk appetite and tolerance.
- Complete enterprise risk assessments across categories.
- Define and operationalize Key Risk Indicators.
- Refresh the enterprise risk register.
- Build executive and Board risk reporting.
- Strengthen risk culture and first-line engagement.
- Advance the maturity of the ERM program.
About [Company]
[Two or three sentences about your organization, the maturity of your program, and what the first year looks like. Candidates in this field respond to honesty about whether they are joining a build or an established function.]
Post this role on GRC Careers
Reach professionals who specialize in enterprise risk management rather than hoping they find you in a general feed. Hand reviewed, live within one business day.
See how others are hiring
Review live GRC leadership jobs postings to benchmark scope, level, and posted salary before you publish yours.
Stay close to the market
Job alerts
Get new GRC leadership jobs roles sent to you as they post.
Newsletter
Hiring trends, salary signals, and new templates from GRC Careers.
Frequently asked questions
What does a VP of Enterprise Risk Management do?
The VP of Enterprise Risk Management leads the enterprise risk program. They own the ERM framework, set risk appetite with leadership, run enterprise risk assessments, track Key Risk Indicators, and report the enterprise risk profile to leadership and the Board.
What qualifications and certifications does a VP of Enterprise Risk Management need?
Most bring 10 to 15 or more years in enterprise, financial, or operational risk, including at least 5 years leading risk programs. Common certifications include FRM, PRM, CRISC, and CRMA.
Who does a VP of Enterprise Risk Management report to?
The VP of ERM typically reports to the Chief Risk Officer, the Chief Financial Officer, or the Board Risk Committee, and coordinates the three lines of defense across risk, compliance, and internal audit.
What frameworks does a VP of Enterprise Risk Management use?
The role works primarily from COSO ERM and ISO 31000 for enterprise risk, supported by the NIST Cybersecurity Framework and, in financial services, Basel standards.