Enterprise Risk Manager
About Nscale
Nscale is the GPU cloud engineered for AI. We provide cost-effective, high-performance infrastructure for AI start-ups and large enterprise customers. Nscale enables AI-focused companies to achieve superior results by reducing the complexity of AI development. Our GPU cloud bolsters technical capabilities and directly supports strategic business outcomes, including cost management, rapid innovation, and environmental responsibility.
We thrive on a culture of relentless innovation, ownership, and accountability, where every team member takes pride in their work and drives it with excellence and urgency. As an Nscaler, you’ll build trust through openness and transparency, where everyone is inspired to do their best work. If you join our team, you’ll be contributing to building the technology that powers the future.
About the Role
We’re hiring an Enterprise Risk Manager to develop and embed Nscale’s Enterprise Risk Management Framework and strengthen risk management, internal audit, and controls as the business scales.
Reporting to the Senior Manager, Audit, Risk & Controls within Finance, you’ll work across infrastructure, operations, product, technology, and corporate functions. You’ll provide oversight, guidance, and constructive challenge to ensure risks are identified, assessed, managed, and reported in line with Nscale’s strategic objectives.
You’ll also deliver risk-based internal audits and support internal controls and SOX compliance, providing independent assurance and practical advice to management and the Audit & Risk Committee. This is a UK-based, full-time opportunity to own the enterprise risk agenda in a fast-growing, technology-led business and help build a robust, forward-looking risk culture.
What you'll be doing
Enterprise Risk Management
- Develop, maintain, and enhance the Enterprise Risk Management Framework, including policies, standards, taxonomy, and guidance.
- Lead enterprise-wide risk assessments, workshops, and horizon scanning across strategic, operational, financial, technology, and emerging risks.
- Maintain the enterprise risk register, ensuring risks, controls, mitigating actions, and ownership remain current and well evidenced.
- Support risk appetite statements and Key Risk Indicators, monitoring performance against agreed thresholds.
- Provide independent oversight and constructive challenge on first-line risk assessments, control design, and mitigation plans.
Risk Governance and Culture
- Produce clear risk reports, dashboards, and papers for senior management, the Executive Committee, and the Board or Audit & Risk Committee.
- Analyse risk trends and emerging themes to provide insight that supports strategic decision-making.
- Support risk committees and governance forums, documenting discussions and tracking actions through to closure.
- Partner with teams across the business to strengthen risk awareness, ownership, and capability.
- Translate complex risk analysis into clear, practical recommendations for stakeholders at all levels.
Internal Audit and Assurance
- Plan and deliver risk-based internal audit engagements across financial, operational, compliance, and IT domains, from scoping through follow-up.
- Lead audit fieldwork, including walkthroughs, documentation reviews, and testing of control design and operating effectiveness.
- Contribute to the annual risk-based internal audit plan and ensure coverage of key business risks.
- Identify root causes of control weaknesses and develop practical, value-adding recommendations.
- Prepare evidence-based audit reports, track management actions, and coordinate with external auditors.
Internal Controls and SOX Compliance
- Support the design, implementation, and enhancement of the internal controls framework across financial reporting and operational processes.
- Perform control walkthroughs and effectiveness testing, identifying deficiencies and tracking remediation to closure.
- Support the SOX compliance programme, including control narratives, risk and control matrices, process documentation, and testing cycles.
- Advise first-line teams on embedding practical, well-documented controls into processes, systems, and change initiatives.
- Coordinate with external auditors on controls- and SOX-related matters.
Incidents, Emerging Risks, and Special Projects
- Support incident management and root cause analysis, working with business areas on practical and sustainable remediation.
- Coordinate across the second and third lines of defence to align risk assessment, response, assurance, and feedback.
- Maintain the emerging risks agenda, including AI, technology, market, regulatory, and best-practice developments.
- Provide risk input into major business, technology, and transformation projects, including new products, markets, systems, and operating models.
- Support ad hoc reviews and deliverables for the Audit, Risk & Controls function.
About You
- You have 6–10 years of experience in enterprise, operational, or strategic risk management, with increasing levels of responsibility.
- You hold a bachelor’s degree in Business, Finance, Risk Management, or a related field.
- You have worked within a risk function, providing effective oversight while collaborating constructively with the business.
- You have demonstrable experience planning and delivering risk-based internal audits and independently testing control design and operating effectiveness.
- You have generalist experience across internal controls and SOX compliance, including documentation, testing, and remediation.
- You have strong working knowledge of ISO 31000, COSO ERM, the COSO Internal Control Framework, the three lines of defence model, and IIA standards.
- You have experience developing risk appetite statements, Key Risk Indicators, enterprise risk registers, and executive- or Board-level reporting.
- You can use data analytics and risk management or GRC tools to support reporting, assurance, and insight.
- You communicate clearly, exercise sound judgement, and build trusted relationships while constructively influencing stakeholders at all levels.
- A professional qualification such as IRM, CIA/IIA, CIMA, CFA, PRM, or equivalent is preferred, or you are actively working towards one.
Experience in a high-growth technology environment, AI infrastructure, cloud platforms, international risk, or emerging technology risk would be advantageous. Familiarity with platforms such as Workiva or Vanta and experience supervising junior team members or outsourced resources would also be valuable.
Equal Opportunities Statement
We strongly encourage applications from people of colour, the LGBTQ+ community, people with disabilities, neurodivergent people, parents, carers, and people from lower socio-economic backgrounds.
If there’s anything we can do to accommodate your specific situation, please let us know.
The responsibilities outlined in this job description are not exhaustive and are intended to provide a general overview of the position. The employee may be required to perform additional duties, tasks, and responsibilities as assigned by management, consistent with the skills and qualifications required for the role.
For information on how Nscale handles candidate personal data, please see our Employee & Candidate Privacy Notice: Here.
Apply for this job
*
indicates a required field
