06 Sep
|
Arminus
|
Kolkata
Role Summary The ERM & BCM Manager is responsible for embedding a disciplined, organisation-wide approach to enterprise risk management and business continuity management. This role designs, implements, and continuously improves the risk governance framework — coordinating risk identification, assessment, and reporting across business units — while building the organisation's capability to anticipate, withstand, and recover from operational disruptions. The role acts as the principal subject-matter expert and facilitator for risk profiling and business continuity planning, working closely with senior leadership, functional heads, and site or business-unit leaders to ensure risks are identified early, controls are effective, and continuity plans are tested and ready when needed.
Key Responsibilities
1. Enterprise Risk Management (ERM)
- Lead the end-to-end risk management cycle — risk identification, assessment, profiling, and reporting — across business units, functions, and sites, using a consistent enterprise risk framework (e.g., COSO ERM, ISO 31000)
- Facilitate and coordinate periodic Risk Control Self-Assessments (RCSA) with business and functional leaders, ensuring risk registers and risk profiles remain current, comprehensive, and actionable.
- Maintain the enterprise risk register and risk taxonomy; track key risk indicators (KRIs) and risk appetite/tolerance thresholds, escalating breaches or emerging risks to senior management.
- Consolidate and synthesise risk data into clear, decision-ready reports and presentations for senior leadership, risk committees, and the Board (or equivalent governance bodies).
- Review the quality of risk assessments submitted by business units to ensure risks are properly characterised, owners are assigned, and mitigation/control plans are realistic and effective — providing independent challenge where needed.
- Act as the subject-matter expert and primary trainer on risk management methodology, coaching risk owners and business partners on risk identification, scoring, and control design.
- Administer and champion the organisation's risk management software/GRC platform (e.g., Archer, Intelex, LogicManager, Riskonnect, or similar), including user support, training, and data quality oversight.
- Support third-party and customer risk assessment requests (e.g., vendor due diligence, customer ERM/BCM questionnaires) in coordination with relevant functions.
- Monitor the external risk environment (regulatory, geopolitical, market, climate, cyber)
and translate emerging themes into updates to the risk framework or risk profiles.
2. Business Continuity Management (BCM)
- Develop, maintain, and continuously improve Business Continuity Plans (BCPs) for critical business functions, in alignment with recognised standards (e.g., ISO 22301) and any applicable regulatory requirements.
- Conduct Business Impact Analyses (BIA) to identify critical processes, recovery time objectives (RTOs), resource dependencies and recovery strategies.
- Design and facilitate business continuity exercises, simulations, and tabletop drills to test plan effectiveness and identify gaps in organisational readiness.
- Coordinate crisis and incident response activities during disruption events, working with crisis management teams, site leadership, and relevant functions to support effective response and recovery.
3. Governance, Stakeholder Management & Continuous Improvement
- Support the operation of risk governance forums (e.g., Risk Management Committee, Crisis Management Team) including agenda preparation, materials, minutes, and follow-up on action items.
- Build and maintain effective working relationships with finance business partners, operations leaders, site/plant management, legal, compliance, EHS, IT/cybersecurity, and external partners (insurers, auditors, consultants) to ensure a cohesive approach to risk and resilience.
- Identify and recommend improvements to ERM and BCM processes, tools, governance structures, and reporting formats to increase efficiency and risk maturity over time.
- Stay current on industry leading practices, regulatory developments, and relevant certifications/standards, bringing external benchmarking into internal framework design.
Qualifications & Experience
Education
- Bachelor's degree in Finance, Risk Management, Economics, Business Administration, Engineering, or a related field is required.
- Master's degree (MBA or related) is an asset but not required.
Experience
- 5–8+ years of progressive experience in enterprise risk management, business continuity management, internal audit, compliance, or operational risk, ideally in a manufacturing, industrial, or multi-site environment.
- Demonstrated experience facilitating risk assessments (RCSA) and developing/testing business continuity or crisis management plans.
- Experience administering a GRC or risk management software platform is strongly preferred.
- Experience presenting to and engaging senior leadership, risk committees, or board-level audiences.
Certifications (Preferred, Not Mandatory)
- Risk: FRM (Financial Risk Manager), PRM (Professional Risk Manager), CRMA (Certification in Risk Management Assurance), CERA (Chartered Enterprise Risk Analyst).
- Business Continuity: ABCP/CBCP/MBCP (Certified/Master Business Continuity Professional — DRI International), CBCI/MBCI (Business Continuity Institute), ISO 22301 Lead Implementer/Auditor.
Knowledge & Technical Skills
- Strong business acumen skills.
- Working knowledge of recognised risk and continuity frameworks (COSO ERM, ISO 31000, ISO 22301, the Three Lines Model).
- Strong analytical skills with the ability to synthesise complex, cross-functional risk information into clear narratives and executive-ready materials
- Proficiency with GRC/risk software platforms and standard productivity tools (advanced PowerPoint and Excel skills expected).
- Familiarity with crisis management protocols, incident command structures, and business impact analysis methodology.
- Understanding of relevant regulatory and industry-standard requirements applicable to the organisation's sector and geographies.
Behavioural & Leadership Competencies
- Strong stakeholder management and influencing skills, with the ability to drive accountability without formal authority over business unit leaders.
- Valuable written and verbal communication skills, including the ability to present confidently to senior and board-level audiences.
- Structured, detail-oriented, and comfortable managing multiple concurrent workstreams under time pressure, particularly during live incidents.
- Calm, decisive, and solutions-focused under pressure, with sound judgement in ambiguous or fast-moving situations.
- A continuous-improvement mindset, proactively identifying gaps and opportunities to strengthen organisational resilience.
Working Conditions
- Hybrid - Primarily office-based with periodic travel to business unit sites/plants for risk workshops, BCM exercises, and assurance programs.
- May require availability outside standard business hours during live crisis or incident activations.
- Cross-functional and cross-regional collaboration; involve working across time zones in global organisations.
📌 Enterprise Risk Management (ERM) & Business Continuity Management (BCM) Manager
🏢 Arminus
📍 Kolkata