Skip to content
AGJ, the AI governance job board
Menu

Executive job description template

VP of Enterprise Risk Management

The VP of Enterprise Risk Management leads the enterprise risk program, owning the ERM framework, risk appetite, and the reporting that gives leadership a clear view of risk. This template reflects how the role is scoped at organizations maturing their ERM function today. Replace the [highlighted fields] with your specifics, trim what does not apply, and post.

Download PDF Download reference sheet

TitleVP of Enterprise Risk Management
DepartmentEnterprise Risk Management
Reports to[Chief Risk Officer / Chief Financial Officer / Board Risk Committee]
Location[Remote / Hybrid / On-site]
Employment typeFull-time
Salary[Salary range. Postings with a range perform significantly better, and several states require one.]

Position overview

The VP of Enterprise Risk Management leads [Company]'s enterprise risk program, providing the framework, methods, and reporting that help the organization identify, assess, and manage risk across all categories.

The VP partners closely with executive leadership, business units, finance, compliance, internal audit, and technology to set risk appetite, run enterprise risk assessments, monitor key risks, and support risk-informed decision making.

As organizations face a broader and faster-moving risk landscape, the VP of Enterprise Risk Management serves as a senior authority on ERM and the integration of risk into strategy and operations.

Key responsibilities

ERM framework and strategy

Risk assessment

Lead enterprise risk assessments across risk categories, including:

Risk monitoring and KRIs

Reporting and dashboards

Develop enterprise risk reporting for executive leadership and the Board, including risk dashboards, heat maps, top risk summaries, and trend analysis that support informed oversight.

Risk culture and training

Advance a strong risk culture across the organization through training, risk champions, and embedding risk practices into business processes and the first line of defense.

Business continuity and resilience

Program leadership

Lead the enterprise risk team, manage risk governance committees, and coordinate the three lines of defense across risk, compliance, and internal audit.

Required qualifications

Preferred certifications

One or more of: FRM, PRM, CRISC, or CRMA.

Technical knowledge

Enterprise risk management, COSO ERM, ISO 31000, risk appetite and tolerance, risk assessment methodologies, Key Risk Indicators, risk quantification, business continuity, third-party risk, scenario analysis, GRC platforms, and risk reporting.

Essential competencies

Strategic leadership, executive communication, Board presentation skills, risk-based decision making, analytical rigor, program management, change leadership, and negotiation and influence.

Success measures: first 12 months

About [Company]

[Two or three sentences about your organization, the maturity of your program, and what the first year looks like. Candidates in this field respond to honesty about whether they are joining a build or an established function.]

Post this role on GRC Careers

Reach professionals who specialize in enterprise risk management rather than hoping they find you in a general feed. Hand reviewed, live within one business day.

Post this role

See how others are hiring

Review live GRC leadership jobs postings to benchmark scope, level, and posted salary before you publish yours.

Browse GRC leadership jobs

Stay close to the market

Frequently asked questions

What does a VP of Enterprise Risk Management do?

The VP of Enterprise Risk Management leads the enterprise risk program. They own the ERM framework, set risk appetite with leadership, run enterprise risk assessments, track Key Risk Indicators, and report the enterprise risk profile to leadership and the Board.

What qualifications and certifications does a VP of Enterprise Risk Management need?

Most bring 10 to 15 or more years in enterprise, financial, or operational risk, including at least 5 years leading risk programs. Common certifications include FRM, PRM, CRISC, and CRMA.

Who does a VP of Enterprise Risk Management report to?

The VP of ERM typically reports to the Chief Risk Officer, the Chief Financial Officer, or the Board Risk Committee, and coordinates the three lines of defense across risk, compliance, and internal audit.

What frameworks does a VP of Enterprise Risk Management use?

The role works primarily from COSO ERM and ISO 31000 for enterprise risk, supported by the NIST Cybersecurity Framework and, in financial services, Basel standards.