Consultant – Senior Manager| Cyber Operate | Cybersecurity Compliance Specialist | KSA
Deloitte Middle East · Riyadh, Saudi Arabia · 1d ago
Our Purpose
Deloitte makes an impact that matters. Every day we challenge ourselves to do what matters most—for clients, for our people, and for society. We serve clients distinctively, bringing innovative insights, solving complex challenges and unlocking sustainable growth. We inspire our talented professionals to deliver outstanding value to clients, providing an exceptional career experience and an inclusive and collaborative culture. We contribute to society, building confidence and trust in the markets, upholding the integrity of organizations and supporting our communities.
Our shared values guide the way we behave to make a positive, enduring impact:
During your tenure as a Consultant – Senior Manager, you will demonstrate and develop your capabilities in the following areas.
Assess compliance
·Run compliance assessments against NCA ECC-2:2024 and other applicable NCA controls: CSCC (critical systems), CCC (cloud), DCC (data), OTCC (OT), TCC (telework) and OSMACC (social media accounts)
·Assess compliance with ISO/IEC 27001:2022, PDPL data protection requirements and other obligations that apply to the organisation
·Assess new systems, projects and major changes for compliance before go-live
·Interview control owners, review policies and procedures, and judge whether each control is fully, partially or not implemented
Test that controls work
·Test control effectiveness through evidence sampling and technical checks: user access reviews, privileged account listings, firewall rules, logging and monitoring configuration, backup and restore records, patch status and hardening baselines
·Validate technical configurations against required baselines, using automated compliance scans where available
·Challenge weak or outdated evidence, and record clear, defensible findings
Prepare for regulators and audits
·Prepare NCA compliance self-assessments, evidence packs and submissions, and support NCA assessments and other regulatory reviews
·Support ISO/IEC 27001 certification and surveillance audits, and internal audit reviews
·Coordinate responses to auditor requests and track audit findings to closure
Track and report
·Maintain the compliance obligations register and the control-to-evidence mapping across NCA, ISO and NIST
·Agree remediation plans with control owners, follow them through to closure, and verify fixes
·Report compliance status, trends and overdue actions to management and governance committees
·Monitor new and updated regulations (NCA, SDAIA/PDPL, NDMO) and assess their impact on the organization
Leadership Capabilities:
- Builds own understanding of our purpose and values; explores opportunities for impact.
- Demonstrates strong commitment to personal learning and development; acts as a brand ambassador to help attract top talent.
- Understands expectations and demonstrates personal accountability for keeping performance on track.
- Actively focuses on developing effective communication and relationship-building skills.
- Understands how their daily work contributes to the priorities of the team and the business.
Qualifications:
- Years of experience: 2-8 total years
- Bachelor's in cybersecurity, IT or a related field
- Hands-on NCA ECC compliance assessment experience in Saudi Arabia (Mid and Senior)
- Practical control testing and evidence review skills, with enough technical understanding to assess access, network, logging and configuration controls
- Working knowledge of ISO/IEC 27001 and NIST CSF 2.0
- Clear, precise written English
- Experience with other NCA frameworks (CSCC, CCC, DCC, OTCC) is preferred.
- Experience supporting NCA assessments or ISO/IEC 27001 certification audits is preferred.
- Knowledge of PDPL and NDMO data management requirements is preferred.
- Experience with a GRC platform (Archer, ServiceNow GRC, MetricStream or similar) is preferred.
- Arabic language is preferred.
- At least one preferred: CISA, ISO/IEC 27001 Lead Auditor, CISM. Also valued: CRISC, CISSP, CDPSE.
- Frameworks & Standards: NCA ECC-2:2024 · NCA CSCC / CCC / DCC / OTCC / TCC / OSMACC · ISO/IEC 27001:2022 · NIST CSF 2.0 · PDPL · NDMO Data Management Standards