A complete application in a minute — tailored resume and cover letter, ready to send.
Idemitsu Malaysia seeks an experienced Risk Manager to lead the enterprise risk framework in line with ISO 31000 and COSO ERM. You will coordinate risk assessments across functions and facilitate workshops with stakeholders to ensure comprehensive risk visibility.
You will maintain risk registers, monitor indicators, and produce dashboards for senior management while supporting regulatory and contractual risk reviews, business continuity planning, and policy governance.
Jora Malaysia will close on 9th September 2026. Thank you for being with us, we are cheering you on as you continue your career journey.
Support the implementation and continuous improvement of the company’s enterprise risk management framework, aligned with group requirements and recognised practices such as ISO 31000 and COSO ERM.
Coordinate periodic enterprise, departmental and operational risk assessments.
Facilitate risk workshops with business and functional stakeholders.
Assist risk owners in identifying and assessing strategic, operational, financial, compliance, technology, environmental and emerging risks.
Maintain the corporate and departmental risk registers, including:
Provide independent challenge on risk assessments and the adequacy of mitigation plans.
Monitor changes in the internal and external business environment and identify emerging risks that may affect the company.
Support the review and periodic refresh of the company’s risk appetite, risk criteria and escalation thresholds.
Develop and monitor key risk indicators, risk limits and risk mitigation milestones.
Track the implementation of agreed risk treatment plans and escalated overdue or ineffective actions.
Prepare risk dashboards, trend analyses and management reports for the HOD, senior management and relevant governance committees.
Highlight significant changes in risk exposure, control failures, recurring issues and emerging risks.
Maintain accurate and current risk management records and supporting documentation.
Coordinate periodic reporting required by regional or group management.
Support the development of data-driven risk reporting using available business and operational information.
Conduct risk and control assessments of key business processes, projects and operational changes.
Facilitate risk and control self-assessments with process owners.
Review the design and adequacy of controls in areas such as:
Identify control gaps, process inefficiencies, concentration risks and potential single points of failure.
Recommend proportionate risk treatment measures that balance control effectiveness, operational efficiency and cost.
Monitor risk events, control failures, near misses and operational losses, where applicable.
Analyse recurring incidents and support process owners in conducting root-cause analysis.
Review policies, SOPs and process documentation from a risk and internal-control perspective.
Advise process owners on appropriate controls, including:
Support process owners in identifying gaps, duplication, bottlenecks and unclear accountability.
Ensure risk-related policies and procedures are aligned with company objectives, group requirements and applicable regulatory obligations.
Monitor whether key policies and SOPs are periodically reviewed and updated.
Maintain advisory independence by ensuring business process owners remain accountable for developing, approving and operating their SOPs.
Monitor regulatory and compliance risks relevant to the company’s operations.
Support compliance risk assessments and the maintenance of a compliance obligations register, where applicable.
Coordinate with Legal, Human Resources, Information Technology and other functions on matters involving:
Support privacy risk assessments under Malaysia’s Personal Data Protection Act 2010 and applicable amendments.
Review whether appropriate controls are established over the collection, use, access, storage, disclosure, retention and disposal of personal data.
Escalate significant compliance exposures to the appropriate function and management.
The role should support compliance oversight but should not be described as providing legal advice unless the candidate is appropriately qualified and formally authorised to do so.
Review proposed commercial and operational arrangements from a business, operational, compliance and control-risk perspective.
Identify risks associated with contractual obligations, service continuity, data handling, confidentiality, insurance, performance standards and third-party dependencies.
Coordinate with Procurement, Legal Counsel and relevant process owners to ensure material risks are appropriately addressed.
Support risk assessments and due diligence for significant vendors, service providers and business partners.
Monitor significant third-party risks and agreed mitigation actions.
Refer legal interpretation, contract drafting and legal approval to qualified Legal Counsel.
Support the development, review and testing of business continuity plans.
Coordinate business impact analyses and identify critical business processes, resources and dependencies.
Monitor business continuity and disaster recovery actions with relevant process owners.
Support scenario exercises, crisis simulations and post-exercise improvement plans.
Report material business continuity gaps to the HOD and relevant management.
This section should be retained only if business continuity falls under the Risk Management Department.
Act as a coordination point for risk information requested by Internal Audit, external auditors or group assurance functions.
Provide Internal Audit with relevant risk registers, risk assessments and management reports.
Coordinate with process owners on the submission of responses and corrective action plans.
Maintain a central tracker of agreed audit actions and monitor implementation progress.
Escalate overdue or repeatedly deferred audit actions to the HOD and relevant management.
Support management in understanding audit findings without changing, suppressing or influencing Internal Audit’s independent conclusions.
Avoid performing activities that would impair the independence of the Internal Audit function.