Operations & Finance

Risk Manager Job Description

A Risk Manager builds and runs the framework an organisation uses to see, measure, and decide what to do about the things that could go wrong. The remit spans operational, financial, technology, people, and strategic exposures, not just regulated ones: maintaining a risk register that reflects reality, setting and testing appetite with leadership, tracking indicators that move before an incident does, making sure every significant exposure has a named owner, and running the scenario and resilience work that shows whether a plan survives contact with a bad day. The role does not remove risk. Its value is that decisions get made with the exposure quantified and consciously accepted, rather than discovered afterwards.

Key skills

Risk framework design, taxonomy, and register maintenanceRisk appetite setting, cascading, and breach escalationLikelihood and impact assessment, including quantification where data allowsKey risk indicator design and threshold calibrationScenario analysis, stress testing, and business continuity planningIncident and loss event capture, root cause review, and trend analysisFacilitating risk conversations with executives and control ownersBoard and committee reporting that prompts a decision rather than a nod

Responsibilities

  • Maintain a risk register that reflects the organisation as it is now, not as it was at the last review
  • Facilitate risk assessments with business owners and challenge optimistic ratings
  • Propose risk appetite statements and track exposures against them
  • Design and monitor key risk indicators, and escalate when thresholds are crossed
  • Ensure every significant risk has a named owner, an agreed treatment, and a review date
  • Run scenario, stress, and continuity exercises and turn the findings into actions
  • Capture incidents and near misses, analyse root cause, and track themes over time
  • Report the risk profile and appetite breaches to leadership and the board or its committee

Requirements

  • Experience building or running a risk framework rather than only populating someone else's register
  • Ability to facilitate a risk workshop with senior people and challenge a rating without antagonising the room
  • Comfort quantifying exposure where data exists and being honest where it does not
  • Experience designing indicators that move before an event, not after it
  • Clear reporting that prompts a decision rather than restating a heat map
  • Understanding that risk governance expectations differ by sector, size, and jurisdiction, and that any regulatory requirement must be confirmed locally

Nice to have

  • Sector-specific risk experience relevant to your operations
  • Business continuity, operational resilience, or crisis management experience
  • Exposure to third-party or supply chain risk assessment
  • Technology and information security risk literacy
  • Experience embedding risk ownership in a business that previously treated it as a finance exercise

What to look for in a great Risk Manager

The failure mode of this role is a beautiful register that nobody uses, so hire for influence as much as method. Look for a candidate who can describe a decision that changed because of their analysis, and who talks about business owners accepting risks rather than about the register being complete. Test whether they can quantify: many candidates are comfortable with high, medium, and low but cannot express an exposure in terms leadership can weigh against a commercial upside. Facilitation skill matters enormously, since the honest version of a risk assessment only emerges if people feel able to say the uncomfortable thing in front of their peers.

Where to source Risk Manager candidates

Internal audit produces candidates with strong control understanding, though some need to shift from assurance after the event to influence before it. Operational leaders who have run a complex function often make excellent risk managers because they know where things actually break. In regulated sectors, second-line risk teams are the natural pool. Business continuity, resilience, and security backgrounds are worth considering where your major exposures are operational rather than financial. Professional risk associations run active local networks that reach passive candidates.

Interview questions to ask a Risk Manager

Ask 'Tell me about a risk the business was underrating. How did you change their view?' Then test method: 'How would you set appetite for a risk that has never materialised here and has no loss data?' Probe indicators with 'Give me a key risk indicator you designed that gave real early warning, and one that turned out to be useless.' Finally, test the reporting instinct: 'Show me how you would summarise the risk profile for a board that has fifteen minutes and no appetite for a heat map.'

Red flags when hiring a Risk Manager

Be wary of candidates whose entire answer is a framework diagram, since the method is the easy part and the adoption is the hard part. Someone who cannot name a risk they were wrong about, in either direction, has probably not been close enough to real decisions. Watch for people who treat every exposure as unacceptable, because a function that never signs off on accepted risk becomes an obstacle and gets bypassed. Registers described as complete and stable are usually stale. Finally, treat confident claims about regulatory expectations in an unfamiliar sector or jurisdiction with caution, since those expectations differ and should be verified.

How an ATS speeds up hiring a Risk Manager

This appointment usually needs sign-off from an executive team and often a board committee, which means several stakeholders with different definitions of a good candidate. Pitch N Hire's ATS holds one structured scorecard covering framework design, quantification, facilitation, and reporting clarity, so the panel debates the same evidence instead of comparing impressions from separate conversations. A practical exercise, such as summarising a risk profile for a board, can be attached to a pipeline stage and reviewed side by side across the shortlist. Keeping the full record in one place also makes the eventual recommendation to the committee straightforward to justify.

Hiring a Risk Manager? See Pitch N Hire on your roles.

FAQ

Hiring a Risk Manager — FAQs

What does a Risk Manager do? +
A Risk Manager designs and runs the framework used to identify, assess, own, and monitor an organisation's exposures across operations, finance, technology, people, and strategy. The work includes maintaining the risk register, facilitating assessments with business owners, proposing and tracking risk appetite, designing early warning indicators, running scenario and continuity exercises, analysing incidents for root cause, and reporting the risk profile and any appetite breaches to leadership and the board.
What is the difference between a Risk Manager and a Compliance Officer? +
A Compliance Officer is accountable for adherence to rules that already exist and for the evidence that the organisation followed them. A Risk Manager deals with uncertainty more broadly, including exposures that no rule addresses, and helps leadership decide how much of it to accept. Regulatory risk is one entry on a risk register but is the entirety of the compliance remit. The two functions work closely together and are usually kept separate once an organisation is large enough.
Does a Risk Manager need a specific qualification? +
Professional risk credentials exist and are valued in some sectors, but requirements differ by industry, size, and jurisdiction, and regulated sectors may impose expectations on the function or the individual. Confirm the local position rather than assuming one. In practice, evidence of building a framework people actually use, facilitating honest assessments, and reporting in a way that changed a decision predicts performance more reliably than a certificate.
Should risk management sit inside finance? +
It often starts there because finance already reports to the board and holds the controls agenda, but the remit covers far more than financial exposure. What matters more than the reporting line is independence from the people whose targets depend on a risk being rated low, and direct access to leadership or a board committee when an appetite breach needs escalating. As organisations grow, the function commonly moves out of finance to reflect that broader scope.
How do you measure whether risk management is working? +
Useful signals include whether the register genuinely changes between reviews, whether risks have active owners with dated treatments rather than passive ratings, whether indicators trigger before incidents rather than after, and whether incidents cluster in areas that were already flagged. The strongest signal is behavioural: leadership consulting the risk view while a decision is still open, and being willing to record a risk as consciously accepted rather than quietly hoping it does not happen.
Pitch N Hire ATS

Post this job description and track every applicant in one place

Pitch N Hire is an applicant tracking system. Publish this role to your careers page and job boards, then follow every applicant through screening, interviews, and offer without a spreadsheet.

  • Publish to your careers page and job boards from one job record
  • Screen and shortlist applicants against the criteria in this description
  • Move candidates through stages with the whole panel seeing the same view

Free for 1 user · No credit card · Talk to a real hiring expert

Built for recruiters & hiring teams

Ready to hire a Risk Manager?

Post this role to multiple job boards and screen, interview and decide — all in one AI-native platform.

Prefer to talk? Book a demo · Talk to sales · View pricing

Free 1-user plan · No credit card · Talk to a real hiring expert

One Hiring Infrastructure.
Zero Tool Chaos.

Demos are consultative. We respect privacy and enterprise
governance. No lock-ins.

Start free Book demo