Khazna was founded in 2012 and has grown rapidly into becoming the leading and trusted wholesale Data Center provider in the Middle East and North Africa region. Through our Data Centers, we provide industry benchmark levels of power supply and cooling services to better serve the growing need for data center operations in the UAE and wider region.
We are seeking a Risk Management Specialist who will play a pivotal role in safeguarding the reputation, safety, security, and financial stability of the data center. This role will be responsible for identifying, assessing, and managing risk mitigation plans for potential threats that could impact operational integrity and strategic objectives. The specialist will drive the Risk Management program by partnering with process owners to embed risk awareness across operations, maintaining risk registers, coordinating risk assessments, and delivering clear, actionable risk reporting to leadership and governance forums.
Key Accountabilities:
- Maintain ERM policy, methodology, scoring criteria, and risk appetite/tolerance aligned to ISO 31000 and COSO ERM.
- Run the risk assessment calendar (cycles, risk reports and dashboards).
- Facilitate risk assessments with Operations, Engineering, QHSE, Projects, Security, IT and Business teams. Identify and assess operational risks.
- Maintain enterprise/functional/site risk registers current; inherent/residual ratings; treatment plans & owners).
- Perform scenario analyses for data-center specific risks (CRAH/Chiller/UPS/STS failures, thermal run-ups, supply chain, capacity, EHS, cyber, physical, ESG).
- Support project risk assessments (capacity builds, retrofits, energizations); track handover risks to Operations.
- Support third-party/vendor risks assessments/ management, monitor remediation.
- Support mapping risks to preventive/detective/corrective controls (e.g., change/CAB gates, LOTO, EOPs, PM/PPM compliance, BMS/ alarms, thresholds).
- Plan and execute control testing; log issues, concessions, and CAPA; verify closures with evidence.
- Implement mitigation strategies to reduce potential risks and improve operational reliability.
- Define and monitor Key Risk Indicators.
- Produce monthly/quarterly dashboards and reports with trends, breaches, and recommendations.
- Support BIA, recovery strategies, tabletop & live exercises (e.g., OT, power, cooling, security, cyber etc).
- Assist in the development of business continuity and disaster recovery plans. Develop and update standard operating procedures (SOPs) to reflect best practices.
- Collaborate with cross-functional teams to integrate risk management into resilience plans.
- Apply the RAID (Risks, Assumptions, Issues, Dependencies) framework to ensure structured identification and tracking of critical elements affecting business continuity and resilience outcomes.
- Ensure resilience strategies uphold the principles of the CIA triad (Confidentiality, Integrity, and Availability) to protect critical assets and maintain trust in operational systems.
- Align risk program with ISO 9001/27001/22301/14001/45001 and internal policies.
- Maintain auditable documentation of assessments, controls, and mitigation actions.
- Collaborate with quality and compliance teams to embed risk controls and track corrective actions.
- Facilitate risk awareness sessions and workshops, coach process owners on risk methods and practices.
- Operating within a 24/7 mission-critical, multi-site wholesale data centre environment, this role supports live customer operations activities. The specialist ensures governance, risk, and compliance (GRC) principles are embedded across all operational layers, balancing strategic oversight with real-time risk mitigation in a dynamic setting.
- This role operates within a complex, 24/7 mission-critical, multi-site wholesale data center environment, supporting live customer operations. The Operational Risk Management Specialist plays a key role in ensuring that governance, risk, and compliance (GRC) frameworks are consistently applied across all operational domains, supporting both business continuity and strategic resilience.
- The position involves cross-functional collaboration across multiple sites and departments, requiring a strong understanding of operational processes and risk landscapes. The specialist engages with stakeholders at all levels to embed risk awareness, ensure compliance with internal controls, and maintain alignment with enterprise risk objectives. Occasional travel between sites and flexible working hours may be required to support risk assessments, control testing, and leadership reporting. The environment demands a proactive and structured approach to managing risk in a fast-paced, high-stakes operational setting.
- Authority to recommend changes to workflows, systems integration, and performance management tools.
- Recommend acceptance/deferral of residual risk against appetite; escalate breaches.
- Gatekeeper input for ORL changes; power to recommend stop-work where critical risk is uncontrolled.
Minimum Qualifications:
- Bachelor's degree in Risk Management /Engineering, Information Systems, Business or a related field.
- 4–7 years in Risk/GRC/Assurance, including 2+ years in data center, critical infrastructure, or industrial operations.
- ISO 31000, COSO ERM; working knowledge of ISO 9001/14001/45001/27001/22301/ 27701; familiarity with NIST CSF/ISO 27005, PCI DSS is beneficial.
- Hands-on with risk registers, RCSAs, control testing, KRIs, and remediation tracking.
- Knowledge of industry regulations and compliance standards.
- Certifications (preferred): CRISC/CRMA/IRM, CISA/CIA, ISO Lead Implementer/Auditor (any of 9001/27001/22301/45001).
Job-Specific Skills (Generic / Technical):
- Excellent written and verbal communication skills, strong attention to detail, and the ability to effectively communicate and present to senior executives.
- High integrity, ability to multi-task and handle competing priorities working with different levels of colleagues/stakeholders across Khazna.
- Experience working with various cross-functional teams and cultures.
- Proficiency in working with risk dashboards and automated reporting systems.
Additional Qualifications:
- Demonstrated ability to develop and implement effective risk management frameworks.
- Ability to translate risk into concise, executive-ready messages; adapts style for juniors vs. executives.
- Strong understanding of risk assessment and mitigation techniques.
- Ability to connect asset, process, and human factors to anticipates knock-on effects.
- Strong communication and interpersonal skills, with the ability to work effectively in an agile and collaborative environment.
- Ability to manage multiple tasks and prioritize effectively.
- Attention to Detail and Compliance Focus
- Proactive Risk Identification and Mitigation
- Strong interpersonal skills to facilitate collaboration with cross-functional teams.
- Excellent problem-solving, organizational, and project management skills.