←  Back to all vacancies

VP & Head of Operational Risk Advisory & Oversight - Group Technology & Transformation

First Abu Dhabi Bank

Banking & Financial Services

πŸ“ Abu Dhabi, United Arab Emirates
πŸ’Ό Full-time
πŸ•’ Posted 2 weeks ago

Job description

Role Overview

VP & Head of Operational Risk Advisory & Oversight β€” Group Technology & Transformation at First Abu Dhabi Bank. The role operates as a Second Line of Defence function within the Operational Risk Advisory & Oversight (ORA) function, reporting to the SVP, Head of Operational Risk Advisory & Oversight.

Role Purpose

Lead portfolio-specific ORA coverage for the Group Technology & Transformation (GT&T) portfolio, ensuring that operational risks relating to technology services, platforms, infrastructure, data analytics, AI-enabled capabilities, information risk, change and transformation are effectively identified, assessed, challenged, escalated and governed in line with the Group Operational Risk Framework, risk appetite and regulatory expectations. The role executes the ORA coverage model and priorities defined at Group level, providing independent challenge and subject matter expertise to senior GT&T stakeholders while maintaining clear separation from first-line ownership, technology delivery, control operation, remediation and independent assurance.

Key Responsibilities

Portfolio Leadership & Oversight

  • Lead second-line Operational Risk Advisory & Oversight coverage for the GT&T portfolio, aligned to Group-wide operational risk priorities, minimum standards and the ORA coverage model.
  • Act as the primary ORA point of engagement for senior GT&T leadership across business-as-usual technology operations, platforms, infrastructure, data analytics, AI-enabled capabilities and change initiatives.
  • Maintain a risk-based portfolio coverage plan reflecting technology service criticality, transformation activity, data and analytics priorities, AI-related operational risk considerations, third-party dependencies, resilience matters, incidents, open issues and regulatory developments.
  • Act as the designated Line 2 subject matter expert within ORA for GT&T-related technology risk, information risk, technology resilience, data analytics risk and AI-related operational risk considerations.

Independent Challenge & Risk Assessment

  • Provide independent second-line challenge over technology, information, data and transformation-related operational risks, including risk identification, assessment, control design, control effectiveness, risk acceptance, issue remediation and tolerance breaches.
  • Challenge material risk acceptance decisions, control weaknesses, remediation plans and closure evidence, escalating to the SVP where risks are material, systemic or cross-cutting.
  • Ensure challenge activity is evidence-based, proportionate, clearly documented and aligned to the Group Operational Risk Framework and applicable operational risk policies.
  • Challenge technology and information risk assessments.
  • Challenge RCSA outputs and control assessments for GT&T.
  • Challenge technology change, transformation and digital initiative assessments.
  • Challenge data management, analytics and AI-related operational risk assessments.
  • Challenge operational resilience assessments for technology services.
  • Challenge third-party and outsourcing risk matters relating to technology dependencies.
  • Challenge material incidents, root cause analysis and remediation plans.
  • Challenge KRI breaches, tolerance exceptions and policy exceptions.

Subject Matter Expertise

  • Provide SME input covering information confidentiality, integrity and availability, data protection, information security risk, technology control alignment, data management controls, analytics risks and operational risks associated with AI-enabled processes or technology capabilities.
  • Provide SME input to enterprise thematic reviews, regulatory responses, supervisory engagements and material incident assessments led by the SVP or relevant governance owner.
  • Support consistent second-line interpretation and challenge across technology platforms, change programmes, data and analytics capabilities and strategic transformation initiatives.

Advisory & Transformation Oversight

  • Provide operational risk advisory and independent challenge over major technology programmes, digital initiatives, platform changes, data and analytics initiatives and AI-enabled transformation activities.
  • Support second-line oversight of operational resilience within technology estates, including technology service mapping, dependency analysis, control embedding and scenario challenge, without assuming first-line ownership.
  • Challenge whether material technology changes and transformation programmes appropriately consider operational resilience, information risk, data risk, third-party dependencies, control design and sustainable remediation.
  • Identify systemic control weaknesses or recurring operational risk themes arising from technology change, transformation and resilience activity.
  • Provide practical second-line guidance to GT&T stakeholders on the application of operational risk requirements without assuming first-line ownership or execution responsibility.

Issue Management & Escalation

  • Ensure timely identification, escalation and tracking of material GT&T operational risk issues, including technology, information, data, transformation, resilience and third-party dependency matters.
  • Challenge issue ownership, target dates, remediation quality, closure evidence and sustainability of corrective actions.
  • Escalate matters requiring enterprise-level consistency, interpretation, risk acceptance, committee positioning or senior management judgement to the SVP.

Reporting & Governance

  • Provide portfolio insight and recommendations to the SVP where matters are material, systemic, cross-portfolio, regulatory-sensitive or require enterprise-level governance alignment.
  • Support preparation of portfolio-level reporting, committee materials, risk insight papers and escalation notes for relevant governance forums.

Stakeholder Engagement & Assurance Support

  • Engage with senior GT&T management, technology leadership teams, risk committees, Internal Audit, assurance functions, Compliance and other relevant control partners.
  • Support regulatory inspections, supervisory reviews and internal assurance activity within the GT&T, technology risk, information risk, operational resilience, data and analytics or AI-related operational risk scope, under the direction of the SVP.
  • Maintain effective working relationships across Operational Risk, Framework & Governance, Data & Analytics, Technology, Cyber / Security, Strategic Vendor Management and other relevant functions.

Team Leadership & Development

  • Provide leadership, direction and technical guidance to assigned AVP and Specialist resources supporting the GT&T portfolio.
  • Support capability development, coaching, performance management, succession planning and knowledge sharing within the portfolio team.
  • Review the quality of challenge outputs, thematic reviews, issue assessments and portfolio reporting prepared by team members.

Governance & Culture

  • Act as a senior leader within Group Risk, modelling ethical behaviour, sound judgement, strong governance discipline and an effective risk culture.
  • Ensure compliance with all applicable Group health, safety and wellbeing policies.
  • Promote a safe, respectful and inclusive working environment within the function.

Qualifications & Experience

  • Bachelor's degree in Computer Science, Information Technology, Engineering, Risk Management, Data Analytics, Information Systems or a related discipline.
  • 12–15+ years' relevant experience in financial services, technology risk, operational risk or complex regulated organisations.
  • Significant experience in technology risk, information risk, operational risk, operational resilience, third-party technology risk, data management, data analytics risk or second-line risk advisory roles.
  • Proven experience engaging with senior technology stakeholders, technology governance forums, risk committees, Internal Audit, assurance functions and regulators.
  • Exposure to large-scale technology change, digital transformation, technology platforms, infrastructure, cloud or third-party technology dependency risk.

Skills & Competencies

  • Strong technology risk judgement and advisory capability.
  • Strong understanding of information risk, data risk, technology resilience and technology control environments.
  • Ability to challenge senior stakeholders effectively while preserving constructive business engagement.
  • Clear written and verbal communication, including executive-level reporting and governance papers.
  • Collaborative leadership, stakeholder management and coaching capability.
  • Strong understanding of second-line risk responsibilities, operational resilience expectations and regulatory expectations.
  • Ability to identify systemic risk themes, root causes and emerging risks across technology, data, analytics and transformation environments.

Additional Information

Preferred Qualifications & Experience

  • Professional certifications preferred, including CRISC, CISM, CISA, CISSP, FRM or equivalent technology, cyber, data, resilience or risk qualifications.
  • Experience providing challenge over data and analytics capabilities, AI-enabled technology initiatives or emerging technology risks is desirable.

Role Operating Principles

  • The role operates within the Group Operational Risk Framework, approved policies, governance standards, Delegation of Authority and the ORA strategy and coverage model defined by the SVP, Head of Operational Risk Advisory & Oversight.
  • The role is a Second Line of Defence function and provides independent advisory, oversight, challenge and escalation. It does not perform first-line execution, technology delivery, control operation, remediation ownership or independent assurance activities.
  • Enterprise Operational Risk Framework, taxonomy, risk appetite methodology and framework governance ownership remain with the relevant framework and governance function. This role consumes those standards for portfolio advisory and challenge purposes.
  • First Line of Defence retains accountability for technology delivery, risk ownership, control design, control operation, service resilience, data and analytics control operation and remediation.
  • Independent validation or assurance activities remain with the relevant independent validation, audit or assurance functions. This role may use their output to inform second-line challenge but does not perform independent assurance.
  • The role is authorised to make decisions and escalate matters in line with approved delegated authorities and second-line escalation protocols. Material, systemic, cross-portfolio or regulatory-sensitive issues are escalated to the SVP for enterprise-level governance and committee consideration.

People looking at this role also searched

Report this job

⚑ Quick Apply

Create your account and upload your CV to apply for β€” takes less than a minute.

✨ Get a free AI ATS Score Report for your CV the moment you sign up.