Job DescriptionThe OpportunityThe
Director of Enterprise Risk Management and Compliance leads two connected programs within the Office of Audit, Risk, and Compliance (OARC): the University's enterprise risk management program and its institutional compliance program. The Director advances an established ERM architecture and compliance management framework, strengthens how both inform decision-making by senior leadership and the Board of Trustees, and works across a highly decentralized institution to keep risk and compliance practices effective, current, and proportionate to the University's exposure.
OARC integrates internal audit, enterprise risk management, and institutional compliance under a shared framework. The Director serves as a collaborative partner to units across the University, helping them own and manage their risks and compliance obligations, while OARC provides coordination, methodology, monitoring, and reporting. The position reports to the Chief Audit Executive.
Enterprise Risk Management Responsibilities- Lead and continue to mature the University's ERM program, including the enterprise risk register, risk theme structure, and the methods used to identify, assess, and monitor strategic and operational risks
- Facilitate the ERM Steering Committee and prepare risk reporting for senior leadership and the Board of Trustees
- Partner with units to translate departmental risks into enterprise-level risk views that support strategic planning and resource decisions
- Advance risk analysis methods over time, including scenario-based and quantitative approaches where they add decision value
- Coordinate with internal audit so that risk information informs the audit plan and audit results inform the risk picture, while preserving the independence of the audit function
Institutional Compliance Responsibilities- Coordinate compliance activities across a highly decentralized environment, working with designated compliance owners in each area
- Maintain and operate the University's compliance management framework and system, including regulatory requirements, controls, owner assessments, and status reporting
- Monitor the regulatory environment (for example Title IX, Clery Act, FERPA, GLBA, Title IV, export controls, and aviation regulations), assess impact, and communicate relevant changes and recommended actions to the responsible owners
- Prioritize compliance efforts based on risk exposure and monitor the effectiveness of compliance activities on an ongoing basis
- Coordinate and escalate potential compliance concerns to the appropriate channels for review and resolution
- Support development of compliance training and communications for employees and managers
- Report regularly to senior leadership and the Board of Trustees on the state of compliance
- Generous Time Off: Enjoy up to 18 days of paid leave in your first year, including 3 days granted upon hire and 15 days accrued throughout the year. You'll also receive 9+ paid holidays, including the day after Thanksgiving and the week between Christmas Eve and New Year's Day.
- Tuition Coverage: Get 100% tuition coverage for yourself for one undergraduate and one graduate degree, and discounted rates for your spouse and dependent children up to age 26.
- Retirement Contributions: ERAU contributes 6% of your base salary to your retirement plan and offers a 4% matching contribution - with no vesting period.
- Personal Leave: Relax with 15 days of personal leave for non-exempt employees or 18 days for exempt full-time employees in your first year.
QualificationsRequired Education:- Bachelor's Degree in Business Administration, Law, Risk Management or a related field
Required Licenses, Certificates, and/or Security Clearances:- Relevant certifications such as CCEP, CRMA, CRISC, or an ERM credential
Required Skills, Knowledge, and Abilities:- Demonstrated experience building or running a risk register, a compliance program, or a comparable management-owned framework, and facilitating risk and compliance discussions with senior leaders
- Demonstrated skill in assessing and communicating risk to senior leaders and governing bodies
- Working knowledge of higher education operations, regulations, and accreditation, or the ability to build that depth quickly
- Experience leading and coordinating work through influence in a large, complex, decentralized organization
- Strong written and verbal communication skills
- Sound judgment and discretion with confidential and sensitive matters
Preferred Skills, Knowledge, and Abilities:- Master's degree
- Internal audit, controls, or assurance experience that complements second-line risk and compliance work
- Familiarity with recognized frameworks such as COSO ERM or ISO 31000
- Experience with governance, risk, and compliance technology
- Experience with quantitative risk analysis or data analytics
- Comfort using emerging tools, including AI-assisted approaches, to improve monitoring and analysis
Experience:- Seven to ten years of progressively responsible experience leading or operating enterprise risk management, compliance, or both, preferably within higher education or a similarly complex organization
To submit your application for this opportunity, please visit the Embry-Riddle Career Site and search for requisition number
R312270. Please attach all relevant materials to your application when you apply online. Complete submissions include:
- Cover letter
- Resume
- Contact information for at least three professional references (please note that references may be contacted as part of the interview/screening process)
Current Embry-Riddle employees: Please apply directly through the ERAU Employee Hub Central application within Workday.