About the job
About HuruHuru is a regulated fintech company licensed by the Central Bank of the UAE, building financial solutions that make banking and payments simpler, faster, and more accessible. We are on a mission to serve the underbanked workforce through innovative payment products, payroll solutions, remittances, and embedded financial services.
About the role:As we continue to scale, we're looking for a Risk Manager to establish and strengthen Huru's Enterprise Risk Management framework while providing independent oversight across operational, technology, resilience, third-party, and strategic risks. This role will play a critical part in ensuring the business grows safely, remains resilient, and continues to meet the regulatory expectations of the Central Bank of the UAE.
- Key ResponsibilitiesEstablish and maintain the Enterprise Risk Management (ERM) Framework, including risk taxonomy, risk appetite, risk registers, risk ownership, control assessments, KRIs, and remediation tracking.
- Lead the annual Enterprise-Wide Risk Assessment (EWRA) and ensure material risks are identified, assessed, monitored, and reported.
- Provide independent second-line oversight and challenge to business functions on risk assessments, control effectiveness, and remediation plans.
- Develop and maintain Operational Risk Management frameworks, including RCSAs, operational risk assessments, incident management, and loss event reporting.
- Coordinate the Operational Resilience Framework, including identification of critical business functions, impact tolerances, dependency mapping, resilience testing, and self-assessments.
- Oversee risk assessments relating to technology, ICT, cybersecurity, cloud services, third-party vendors, outsourcing arrangements, and operational resilience.
- Establish governance for new products, material business changes, outsourcing arrangements, and major technology initiatives, ensuring appropriate cross-functional risk assessments are completed before implementation.
- Monitor operational incidents, near misses, customer-impacting events, technology failures, fraud events, and regulatory issues to ensure timely root cause analysis, corrective actions, and closure.
- Develop enterprise-wide risk dashboards and prepare regular risk reporting for Senior Management, Executive Management, and the Board.
- Monitor Key Risk Indicators (KRIs), emerging risks, risk appetite breaches, and overdue remediation actions.
- Support Board Risk Committee and Governance Committee meetings through risk reporting, documentation, and action tracking.
- Partner closely with Compliance, Product, Technology, Operations, Finance, Information Security, and Internal Audit to embed effective risk management across the organization.
- Support regulatory inspections, internal audits, external audits, and CBUAE examinations relating to Enterprise Risk Management and Operational Resilience.
- Promote a strong risk culture across the organization through awareness, governance, and continuous improvement initiatives.
- Ensure risk frameworks remain aligned with applicable CBUAE regulations, industry best practices, and the Company's evolving business model.
- Preferred QualificationsBachelor's degree in Risk Management, Finance, Business, Accounting, Engineering, Information Systems, or a related discipline. A Master's degree is an advantage.
- 6–10+ years of experience in Enterprise Risk Management, Operational Risk, Operational Resilience, or Risk Governance within banking, fintech, payments, or other regulated financial institutions.
- Demonstrated experience designing and implementing Enterprise Risk Management frameworks, rather than only maintaining existing processes.
- Strong understanding of Enterprise-Wide Risk Assessments (EWRA), Risk Appetite Frameworks, Risk Registers, KRIs, RCSAs, and Board reporting.
- Experience with Operational Resilience, Business Continuity, Incident Management, Third-Party Risk, and Technology Risk.
- Strong understanding of the Three Lines of Defence model and second-line risk responsibilities.
- Ability to independently challenge senior stakeholders while maintaining strong business partnerships.
- Experience working within CBUAE-regulated entities or similar financial regulatory environments is highly preferred.
- Knowledge of technology, cyber, cloud, outsourcing, and operational resilience risks is highly desirable.
- Professional certifications such as FRM, CRISC, CISA, CRMA, ISO 31000, ISO 22301, ISO 27001, or equivalent are advantageous.
- What We're Looking ForWe are not simply looking for someone who maintains risk registers and prepares reports. We're looking for someone who continually asks:Where are our biggest risks before they become incidents?
- How do we strengthen our controls while enabling business growth?
- How do we build a resilient organization that can continue serving customers during disruption?
The ideal candidate is someone who can balance effective governance with business agility, while building scalable risk frameworks that support a fast-growing fintech.
If you've successfully built Enterprise Risk Management frameworks, challenged business decisions constructively, and helped organizations scale safely within a regulated environment, we'd love to speak with you.