Develop and periodically review / update the risk governance and management framework, policies & procedures.
Facilitate preparation of the organization's risk appetite statements through transparent and appropriate review / challenge to business assumptions and oversee amendment of appetite measures in budgeting process / monitoring by Finance and other stakeholders.
Introduce and manage formal risk assessment of major change initiatives by relevant and mandatory stakeholders through an appropriate governance framework - utilizing Risk Champions as primary 2nd line reviewers.
Introduce manage formal risk assessment of key EITC policy, procedures and associated MIS utilizing Risk Champions as primary 2nd line reviewers.
Maintain central repository of all open risk and control issues for effective tracking and closure by stakeholders.
Ensure appropriate monitoring and mitigation of risk exposures by 1st line of defense through surprise QA checks.
Day to day management, oversight and administrative ownership of EITC Risk & Control frameworks, policies, procedures, MIS.
Lead the EITC Risk & Control engagement model vis a vis Risk Champions set KPIs, monitor performance.
SPOC for RCF engagement model within RCF Division.
Oversee the EITC enterprise risk management position, including holistic consolidation of all risk types across the group into reporting formats suitable for all governance levels within EITC.
Preparation of packs / reports / ad hoc data and MIS for Board, management level committees etc.
Ensure EITC alignment to global good practice in relation to GRC standards.
Act as RCF administrator / owner for RSA Archer system, architecture, design and change management.
Report performance against targeted KPI's within RCF engagement model.
Ensure alignment of RCF to EITC corporate governance standards, governance committee structures, charter alignment, DoA alignment etc.
Act as the SPOC for RCF and external regulators, government entities and 3rd parties.
Qualifications:
Degree in Engineering / technology or similar.
CISA/CRISC/CISM
Experience:
Minimum 6-8 years in relevant area
4 years in Telecommunication Industry
Skills:
Deep knowledge of risk & control governance.
Deep knowledge of risk management systems / enterprise GRC systems, preferably RSA Archer.
Communication skills that include ability to communicate effectively at all levels.
Excellent interpersonal, written and verbal communication skills.