Job Description

The Operational Risk Advisor is a regional second-line role responsible for supporting the Chief Risk Officer in strengthening operational risk management and operational resilience across the Middle East and Africa. The role will have primary responsibility for coordinating the implementation and embedding of UAE operational risk and operational resilience regulatory requirements, while supporting consistent and proportionate risk practices across other MEA entities. 

The role will translate regulatory obligations and enterprise standards into practical governance, frameworks, tools, controls, reporting, and evidence. It will partner with business and functional leaders across Operations, Technology, Cybersecurity, Business Continuity, Compliance, Legal, Finance, Procurement and Third-Party Management, while preserving clear first-line ownership and providing effective second-line oversight and constructive challenge. 

Key Responsibilities 

Framework & Governance 

  • Support the design, maintenance, and embedding of a consistent MEA Operational Risk Management Framework, aligned with enterprise standards and adapted to local regulatory requirements. 
  • Lead coordination of the UAE implementation roadmap for applicable CBUAE operational risk and operational resilience requirements, including milestones, dependencies, deliverables, evidence and remediation actions. 
  • Maintain the UAE operational risk regulatory obligations register and evidence matrix, while supporting proportionate regulatory mapping across other MEA jurisdictions. 
  • Promote clear governance, reporting lines, delegated authority and Three Lines of Defence accountability across MEA entities. 

Risk Identification & Management 

  • Facilitate risk and control self-assessments, process risk reviews and thematic assessments, providing independent second-line review and challenge. 
  • Oversee the quality and completeness of operational risk registers, ensuring that risks, controls, ratings, owners, actions and target dates are accurate, current, and evidence based. 
  • Monitor regional and local operational risk profiles against approved risk appetite and tolerance, identifying emerging risks and escalating material exposures, breaches and overdue remediation. 
  • Support business owners in identifying, assessing, managing and evidencing operational risks and controls, without displacing first-line accountability. 

Controls, Incidents, KRIs & Reporting 

  • Develop and maintain minimum control standards and support business owners in documenting, assessing and improving key controls. 
  • Coordinate operational incident, loss event and near-miss reporting, including classification, root-cause analysis, remediation, lessons learned and trend analysis. 
  • Develop and monitor Key Risk Indicators, thresholds and early-warning measures, with clear escalation and action tracking. 
  • Prepare concise dashboards, committee papers and regulatory reporting covering risk profile changes, control effectiveness, incidents, losses, resilience, third-party exposures and implementation progress. 

Business Continuity & Operational Resilience 

  • Support identification of critical operations and services, end-to-end dependency mapping, impact tolerance setting, scenario testing and remediation planning, with implementation priority given to the UAE. 
  • Partner with Business Continuity, Technology and Cybersecurity teams to align business continuity, disaster recovery, incident response and resilience testing with applicable local requirements and enterprise standards. 
  • Monitor material resilience vulnerabilities and testing outcomes, ensuring that remediation is clearly owned, appropriately prioritized and tracked to sustainable closure. 

Third-Party Risk Management 

  • Provide second-line oversight of material outsourcing and third-party risks across due diligence, onboarding, ongoing monitoring, concentration risk, continuity, contingency and exit planning. 
  • Partner with Procurement, Legal, Technology, Cybersecurity and business owners to promote consistent third-party risk and control standards across MEA. 
  • Ensure material third-party exposures, incidents and control weaknesses are reflected in risk registers, governance reporting and remediation plans. 

Stakeholder Engagement & Risk Culture 

  • Build strong working relationships across MEA business, control and enterprise functions, with particular focus on delivery of the UAE regulatory programme. 
  • Facilitate risk workshops, training and awareness activities that strengthen first-line ownership and consistent application of the ORM framework. 
  • Act as a trusted advisor to the CRO and senior stakeholders across MEA, translating complex regulatory requirements into proportionate and practical actions. 
  • Support regulatory reviews, internal audit and independent assurance activities, coordinating responses and maintaining a complete audit trail. 

Qualifications 

  • Bachelor's degree in risk management, finance, business, law, technology or a related discipline; an advanced degree is advantageous. 
  • Professional certification such as CRISC, CISA, CISM, CBCP, IRM, FRM, PMP or equivalent is preferred. 

Experience & Knowledge 

  • Minimum 7 years of relevant experience in operational risk, enterprise risk, internal controls, operational resilience, business continuity, regulatory change or assurance within insurance or financial services. 
  • Experience operating across multiple jurisdictions or within a regional, matrixed organization. 
  • Demonstrable experience implementing operational risk frameworks and translating regulatory requirements into governance, controls, reporting and evidence. 
  • Practical experience with risk assessments, risk registers, control design or assurance, incidents and loss events, KRIs, action tracking and senior-management reporting. 
  • Working knowledge of outsourcing and third-party risk, ICT and cyber dependencies, business continuity and operational resilience. 
  • Proficiency in Microsoft 365 and risk management or governance platforms; experience with SharePoint, Power BI, Jira, Visio or comparable tools is advantageous. 

Key Competencies 

  • Strong regulatory judgement and the ability to convert regulatory intent into proportionate implementation actions. 
  • Credible constructive challenge, while supporting the first line to retain ownership and deliver sustainable solutions. 
  • Strong execution discipline, including management of plans, dependencies, evidence, actions and deadlines. 
  • Regional perspective, balancing consistency across MEA with local regulatory and business requirements. 
  • Excellent stakeholder management, influencing, communication and presentation skills. 
  • Analytical, pragmatic, resilient and solutions focused, with the confidence to engage senior leaders, auditors and regulators. 

Measures of Success 

  • A consistent MEA operational risk framework that is demonstrably effective, locally proportionate and supported by complete, current evidence. 
  • Full and sustainable implementation of applicable UAE operational risk and operational resilience requirements. 
  • Clear first-line ownership, effective second-line oversight and timely escalation through established UAE and MEA governance forums. 
  • Accurate risk registers, meaningful KRIs, disciplined incident reporting and timely closure of material remediation actions. 
  • High-quality regional and regulatory reporting that supports informed decisions and withstands supervisory or assurance review. 

About Cigna Healthcare

Cigna Healthcare, a division of The Cigna Group, is an advocate for better health through every stage of life. We guide our customers through the health care system, empowering them with the information and insight they need to make the best choices for improving their health and vitality. Join us in driving growth and improving lives.

Qualified applicants will be considered without regard to race, color, age, disability, sex, childbirth (including pregnancy) or related medical conditions including but not limited to lactation, sexual orientation, gender identity or expression, veteran or military status, religion, national origin, ancestry, marital or familial status, genetic information, status with regard to public assistance, citizenship status or any other characteristic protected by applicable equal employment opportunity laws.

If you require reasonable accommodation in completing the online application process, please email: SeeYourselfEMEA@cigna.com for support. Do not email SeeYourselfEMEA@cigna.com for an update on your application or to provide your resume as you will not receive a response.


Job Details

Role Level: Mid-Level Work Type: Full-Time
Country: United Arab Emirates City: Dubai
Company Website: http://www.cigna.com Job Function: Security & Risk Management
Company Industry/
Sector:
Hospitals and Health Care

What We Offer


About the Company

Searching, interviewing and hiring are all part of the professional life. The TALENTMATE Portal idea is to fill and help professionals doing one of them by bringing together the requisites under One Roof. Whether you're hunting for your Next Job Opportunity or Looking for Potential Employers, we're here to lend you a Helping Hand.

Report

Disclaimer: talentmate.com is only a platform to bring jobseekers & employers together. Applicants are advised to research the bonafides of the prospective employer independently. We do NOT endorse any requests for money payments and strictly advice against sharing personal or bank related information. We also recommend you visit Security Advice for more information. If you suspect any fraud or malpractice, email us at abuse@talentmate.com.


ad 1
Talentmate Instagram Talentmate Facebook Talentmate YouTube Talentmate LinkedIn