1 hour ago

Manager Enterprise Risk Management (ERM) & Internal Controls Oversight

43 views
Full Time 2026-09-28 Male/Female
Job Overview
Location
Kabul
Nationality
Afghan
Category
Information Technology
Employment Type
Full Time
Salary
As per company salary scale
Vacancy Number
E-0326
No. of Jobs
1
City
Kabul
Organization
e& Afghanistan
Experience
7 Years
Contract Duration
2 Years and Extendable
Gender
Male/Female
Education
Bachelor's Degree
Closing Date
2026-09-28

About e& Afghanistan

e& Afghanistan is a wholly owned subsidiary of e& UAE. e& is one of the world's largest telecommunications companies and a leading operator across the Middle East and Africa, with its headquarters in the UAE.

e& Afghanistan is committed to developing the Afghan national workforce as a key organizational priority. As an equal opportunity employer, the company is dedicated to empowering Afghan nationals through capacity building, professional development, and access to training opportunities, ensuring the growth of local talent and expertise.

Job Description

To lead the establishment, maintenance, and continuous enhancement of the Enterprise Risk Management (ERM) Framework across e& Afghanistan by providing independent risk oversight, challenge, monitoring, reporting, and advisory support to promote effective management of risks within the approved risk appetite. The role serves as a second-line risk oversight function, promoting a strong risk culture and informed decision-making. In addition, the role provides independent oversight of the Internal Controls Framework and coordinates and monitors risk-based control review, testing, and remediation activities in alignment with e& Group requirements.

Duties and Responsibilities

• Lead and coordinate enterprise-wide risk identification, assessment, evaluation, monitoring, and reporting activities covering strategic, operational, financial, regulatory, compliance, fraud, cybersecurity, technology, business continuity, and reputational risks.
• Facilitate periodic risk assessments and Risk C Control Self-Assessments (RCSA) across business functions to identify emerging risks, assess control effectiveness, and evaluate residual risk exposure.
• Maintain the Enterprise Risk Register, ensuring significant risks are appropriately documented, assessed, assigned to risk owners, and supported by mitigation plans.
• Develop, maintain, and monitor risk appetite statements, risk tolerance thresholds, Key Risk Indicators (KRIs), and Key Control Indicators (KCIs), and escalate significant breaches and exposures to management.
• Facilitate and oversee the documentation and periodic review of risks, controls, control ownership, testing procedures, and remediation plans for critical business processes.
• Coordinate and oversee the annual Internal Controls Review and Testing Program to assess the design adequacy and operating effectiveness of key controls.
• Identify control deficiencies, process weaknesses, and governance gaps through risk and control assessments, and provide independent recommendations to management to strengthen the effectiveness of the control environment.
• Monitor and report the implementation status of risk mitigation actions, control remediation plans, and risk-related recommendations arising from Internal Audit, External Audit, regulatory reviews, and management assessments.
• Prepare and present periodic risk and internal control reports to the VP Risk C Assurance, Executive Risk Management Committee (ERMC), and the Audit C Risk Management Committee (ARMC), highlighting key risk exposures, emerging risks, control weaknesses, trends, and mitigation progress.
• Collaborate with Internal Audit, Compliance, Legal, Regulatory Affairs, Information Security, Finance, Technology, Human Resources, and business functions to enhance enterprise-wide risk and control management practices.
• Act as Secretary to the Executive Risk Management Committee (ERMC) chaired by the CEO by coordinating meetings, preparing agendas and risk reports, recording minutes, tracking action items, and facilitating timely closure of agreed actions.
• Assess and monitor regulatory and compliance risks and coordinate with relevant stakeholders to support adherence to telecommunications regulations, license obligations, corporate policies, and applicable laws.
• Provide independent oversight of Business Continuity Management (BCM) and Disaster Recovery (DR) testing exercises and monitor implementation of agreed improvement actions.
• Evaluate cybersecurity, information security, data privacy, technology, and network resilience risks in collaboration with relevant stakeholders and ensure such risks are appropriately reflected in the Enterprise Risk Register.
• Provide risk advisory support for strategic initiatives, major projects, investments, new products, digital transformation programs, outsourcing arrangements, and other significant business decisions.
• Promote a strong risk-aware and control-conscious culture through communication, training, awareness initiatives, and stakeholder engagement activities.
• Monitor industry trends, emerging risks, geopolitical developments, regulatory changes, and market conditions that may impact eC Afghanistan's objectives and operations.

Job Requirements

Educational Qualifications:
• Bachelor's Degree in Risk Management, Finance, Accounting, Business Administration, Telecommunications and Information Technology, or a related discipline.

Preferred:
• Master’s degree in risk management
• Certified Risk Management Professional (CRMP)
• Certification in Risk Management Assurance (CRMA)
• Certified Internal Auditor (CIA)
• Certified Information Systems Auditor (CISA)
• Financial Risk Manager (FRM)
• ISO 31000 Risk Management Certification

Experience Requirements:
• Minimum 7 years of progressive experience in Enterprise Risk Management, Internal Controls, Compliance, Governance, Risk Advisory, or related disciplines.
• Substantial hands-on experience in Enterprise Risk Management is essential. Experience in Internal Controls, Internal Audit, Compliance, Governance, or Assurance may be considered as complementary experience.
• Minimum 3 to 5 years of experience in a managerial or leadership role - preferred.
• Experience within telecommunications, technology, financial services, or other highly regulated industries is preferred.
• Demonstrated experience in implementing and maintaining Enterprise Risk Management and Internal Control Frameworks.
• Experience in facilitating senior management and Board-level committees and preparing executive and Board reports.
• Strong understanding of risk management frameworks, internal controls, governance, regulatory compliance, business continuity, and operational resilience.

Technical Competencies:
• Enterprise Risk Management (ERM)
• Internal Control Frameworks (COSO)
• ISO 31000 Risk Management
• Governance, Risk C Compliance (GRC)
• Risk Assessment and Analysis
• Risk & Control Self-Assessments (RCSA)
• Internal Controls Testing and Evaluation
• Regulatory Compliance Management
• Operational Risk Management
• Cybersecurity and Technology Risk Management
• Data Analytics and Risk Reporting
• KRI and KCI Development

Behavioral Competencies:
• Strategic Thinking
• Leadership and Stakeholder Management
• Analytical and Critical Thinking
• Decision Making and Problem Solving
• Communication and Presentation Skills
• Influencing and Negotiation Skills
• Planning and Organizing
• Collaboration and Teamwork
• Change Management
• Business Acumen
• Integrity and Professional Ethics
• Results Orientation
• Resilience and Adaptability

Submission Guidelines

To apply for this vacancy, please use the following link: https://careers.eand.af 

Kindly use the Google Chrome Browser for smooth access.

For further information, please contact us via WhatsApp at +93 (0) 788 887 363.

Submission Email
https://careers.eand.af

Similar Jobs

21 hours ago
NOC Officer NOC Officer
Hindukush Bridge ICT-Services company Kabul