Head of Risk and Controls
- Hiring from
- Malta
- Work type
- Hybrid
- Posted
- Oct 2, 2026
Head of Risk and Controls
Job Profile
The Head of Risk & Controls is accountable for the day-to-day design, operation, and continuous improvement of Vista Global's enterprise risk management (ERM) and internal control framework. The role acts as the operational lead within the Risk & Control function, translating the Director of Risk & Control's strategic direction into an executable risk and controls programme across all business units and geographies.
Vista is the world’s leading global business aviation company, providing worldwide business flight services through its network of subsidiaries and a team of over 4,000 experts. A global group headquartered in Dubai, Vista integrates a unique portfolio of companies to offer asset-free services that cover all key aspects of business aviation, including guaranteed and on-demand global flight coverage, subscription and membership solutions, and trading and management services.
A career at Vista means stepping into an environment where you’re trusted with real autonomy and responsibility from day one. Whether you're keeping our aircraft airworthy, flying our clients across the globe, or working in one of our corporate teams, you’ll move fast, deliver impact quickly, and grow through hands‑on learning and close collaboration within a supportive global community.
Your Responsibilities
Enterprise Risk Management
- Own and maintain the enterprise risk register and departmental risk registers, ensuring risks are identified, assessed, owned, and managed across financial, operational, regulatory, and technology domains.
- Facilitate risk and control discussions with business unit and function heads; challenge risk ratings and mitigation plans.
- Support the Director of Risk & Control in setting and monitoring the Board-approved risk appetite framework and key risk indicators (KRIs).
- Prepare risk MI and reporting packs for senior management.
Internal Control Framework
- Design, document, and test the internal control framework across key financial and operational processes, aligned to a recognised model (e.g. COSO Internal Control – Integrated Framework).
- Lead control testing cycles, track deficiencies, and manage remediation plans to closure with clear ownership and deadlines.
- Act as the primary control-function liaison for the reporting accountant and external auditors on control matters, coordinating information requests and walkthroughs.
Team & Stakeholder Leadership
- Line-manage the Risk & Control Manager, setting objectives, reviewing output quality, and building technical capability within the team.
- Act as a trusted second-line partner to Finance, Legal, and Commercial leadership, providing pragmatic, risk-based advice rather than pure gatekeeping.
- Maintain a clear and cooperative interface with the Head of Internal Audit (third line), respecting the independence of the audit function while ensuring management actions on audit findings are tracked through the risk and control framework.
Required Skills, Qualifications, and Experience
- 10+ years in risk management, internal controls, or internal audit.
- Demonstrable experience designing or operating an internal control framework.
- People management experience, with a track record of developing risk and control professionals.
- Professional qualification in a recognised audit/risk/control framework, or equivalent certification.
- Working understanding of GDPR and UK/EU data protection obligations.
- Awareness of the EU AI Act's risk-based obligations.
- Degree-level education in a relevant discipline (Risk, Finance, Law, Business, or equivalent).