Governance, Risk & Compliance Director
Listed on 2026-01-19
-
Management
Risk Manager/Analyst, Corporate Strategy, Regulatory Compliance Specialist
Summary of Position
The Governance, Risk & Compliance (GRC) Director is responsible for establishing, supervising, and managing the Company’s Governance, Enterprise Risk Management (ERM), and Compliance functions. The Director ensures that the Company complies with applicable laws, regulations, and internal policies, and that risks are properly identified, assessed, and managed. The Director provides oversight of the Information Security function through the CISO, who maintains full operational responsibility for cybersecurity.
The Director also serves as Secretary to the Boards Committees, ensuring proper documentation, recordkeeping and coordination of all governance-related materials. The Director reports administratively to the CEO and functionally to the Board Audit & Compliance Committee (BACC).
- Establish and maintain a governance framework that supports accountability and alignment with Company objectives.
- Serve as Secretary to the Boards Committees, including responsibility for circulating materials, documenting Minutes of Meetings (MoM), maintaining official records, and ensuring timely distribution of all Board and Committee documentation.
- Oversee the staff responsible for preparing MoM, circulating materials, and coordinating governance documentation.
- Coordinate with Management to ensure timely submission of presentations, reports, and supporting materials for Boards Committee meetings.
- Maintain accurate, secure, and complete documentation of all governance activities, Board and Committee resolutions, and decisions.
- Oversee the development, review, and communication of governance, risk, and compliance-related policies and procedures.
- Promote awareness of governance requirements and support adherence to approved governance processes.
- Ensure adherence to Board and Committee charters, governance requirements, and regulatory obligations related to meetings, documentation, and reporting.
- Serve as custodian of governance documents, including Board and Committee charters and governance policies ensuring they remain current and properly maintained.
- Provide regular governance updates to the CEO.
- Lead and manage the Company’s ERM Framework and risk assessment process.
- Facilitate the identification and assessment of risks in coordination with Management and risk owners.
- Advise the CEO on major risks and the resources and actions required for their management.
- Maintain the Top Corporate Risks (TCRs) and provide periodic reports to the CEO and Board Audit & Compliance Committee.
- Support risk owners in defining and monitoring mitigation actions and ensure alignment with the ERM Framework.
- Ensure ERM is integrated into strategic planning, decision‑making, and key business processes.
- Establish and oversee the Company’s Compliance Program to ensure adherence to applicable laws, regulations, shareholder requirements, and internal policies.
- Develop and maintain compliance‑related policies and ensure they are communicated appropriately.
- Monitor compliance activities across the Company, assess their effectiveness, and report the results to the CEO and Board Audit & Compliance Committee.
- Investigate potential violations of laws, regulations, or Company policies while maintaining confidentiality and objectivity.
- Report to the CEO and Board Audit & Compliance Committee on compliance matters, including investigations, monitoring results, corrective actions, and compliance updates.
- Coordinate with Human Resources regarding disciplinary actions related to compliance violations.
- Oversee compliance with the Company’s Code of Conduct and investigate reported breaches.
- Develop the annual Compliance Plan and conduct compliance risk assessments in coordination with relevant departments.
- Maintain oversight of Information Security through review of reports and updates submitted by the CISO.
- Report high‑level Information Security matters to the CEO based on information provided by the CISO.
Note:
CISO retains full operational and technical responsibility for Information Security and cybersecurity activities.
- Bachelor’s or Master’s degree in Accounting, Finance, Law, Business Administration, Compliance, Risk Management or a related field.
- Professional certifications such as CCEP, CFE, CIA, or risk management credentials are highly preferred.
- Minimum 15 years of experience in governance, compliance, risk management, internal audit or related fields.
- Experience in the petroleum or industrial sectors is preferred.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).