Internal Audit & Risk Management Manager
Al Jomaih Energy and Water • Saudi Arabia
Full Description
The Role
The global energy company develops, invests in, owns and operates conventional power generation, renewable power and water desalination assets in Saudi Arabia and the wider region, primarily through project-specific special purpose vehicles (SPVs) and joint ventures with domestic and international partners.
The Internal Audit & Risk Management function reports functionally to the Board Audit Committee and administratively to the Chief Executive Officer. The Manager in this function supports the Head of Internal Audit & Risk Management across corporate functions, project companies and joint venture entities. The role requires credible engagement with senior management, external auditors, regulators, lenders and shareholder representatives.
The position is based in Riyadh, Saudi Arabia.
Key Responsibilities
Internal Audit
- Support the Head of Internal Audit & Risk Management in developing the annual risk-based internal audit plan.
- Independently manage and execute internal audit engagements within the assigned area of responsibility.
- Conduct audits of business functions, processes and controls, evaluating their effectiveness and identifying areas for improvement.
- Assess compliance with relevant laws, regulations and company policies.
- Prepare audit reports communicating findings, recommendations and remediation plans to senior management and the Board Audit Committee.
- Monitor and track implementation of agreed audit recommendations, ensuring timely resolution of identified issues.
- Assist in the review and improvement of company-wide policies, procedures and management practices.
Project, Contract and Capital Expenditure Audits
- Audit the project development lifecycle from origination and bid through to financial close, construction, commissioning and handover to operations.
- Review compliance with EPC, O&M, PPA/WPA, shareholder and financing agreements, including obligations, milestones, liquidated damages, warranties, insurance and reporting covenants.
- Verify progress payments, variation orders, claims, change management and contingency utilization against contractual entitlement and approved budgets.
- Assess governance, delegation of authority and control arrangements at project companies and joint ventures, including access rights available under shareholder agreements.
Risk Management
- Support the Head of Internal Audit & Risk Management in developing the annual risk management plan and executing engagements within the assigned area of responsibility.
- Collaborate with the Head of Internal Audit & Risk Management and senior management to develop, implement and maintain the ERM framework, covering risk identification, assessment, mitigation and monitoring.
- Conduct regular risk assessments to identify and evaluate potential risks, considering likelihood, impact and cascading effects.
- Develop and implement risk mitigation plans aligned with the ERM strategy and internal controls framework.
- Maintain an updated risk register and ensure consistent communication of risks to relevant stakeholders.
- Integrate risk management activities with internal audit processes.
- Analyze emerging risks and trends and adapt the ERM framework and annual plans accordingly.
Advisory and Ad Hoc Engagements
- Execute ad hoc and advisory engagements within expected turnaround times and quality standards.
Skills & Experience
Education
- Bachelor's degree in Accounting, Finance, Business Administration, Engineering or a related discipline.
- Master's degree or MBA preferred.
Experience
- Eight to ten years of relevant professional experience, of which a minimum of four to five years in internal audit, risk management or external audit.
- Experience with a Big Four firm, leading professional services firm or similar industry is preferred.
- Exposure to IPP/IWP structures, project SPVs, joint ventures, EPC and O&M contracts and project finance is strongly preferred.
- Track record of reporting to or presenting at an Audit Committee or equivalent governance forum.
Certifications
- Certified Internal Auditor (CIA) required, or actively pursuing with completion within an agreed timeframe.
- One or more of the following preferred: SOCPA, CPA, ACCA, CRMA, CFE, CISA or PMP.
- ISO 31000 risk management training is an advantage.
Technical Knowledge
- Working knowledge of COSO Internal Control – Integrated Framework (2013) and COSO Enterprise Risk Management – Integrating with Strategy and Performance (2017).
- Understanding of NCA Essential Cybersecurity Controls, Saudi Companies Law, applicable corporate governance regulations, ZATCA requirements and IFRS as endorsed in Saudi Arabia.
About MENA Careers
MENA Careers is a finance community built for professionals who want better access to recruiters, opportunities, and market insight. It helps members discover relevant private equity roles, find recruiters, and navigate the search with sharper direction across London, Europe, and Dubai. MENA Careers is designed to make the private equity search more focused, more informed, and more effective. For more information, visit joinsenna.com.