Consultant – Manager| Cyber Operate | Cybersecurity Risk Specialist | KSA
Deloitte Middle East · Riyadh, Saudi Arabia · 1d ago
About Deloitte: When you work for us, you commit to a career at one of the largest and most prestigious professional services firms in the world. We have received numerous awards over the last few years, including Best Employer in the Middle East, and Best Consulting Firm, and the Middle East Training & Development Excellence Award.
Our Purpose
Deloitte makes an impact that matters. Every day we challenge ourselves to do what matters most—for clients, for our people, and for society. We serve clients distinctively, bringing innovative insights, solving complex challenges and unlocking sustainable growth. We inspire our talented professionals to deliver outstanding value to clients, providing an exceptional career experience and an inclusive and collaborative culture. We contribute to society, building confidence and trust in the markets, upholding the integrity of organizations and supporting our communities.
Our shared values guide the way we behave to make a positive, enduring impact:
During your tenure as a Consultant – Manager, you will demonstrate and develop your capabilities in the following areas.
Define the risk framework
·Design the cybersecurity risk management framework and methodology: risk taxonomy, asset and impact criteria, likelihood scales, risk matrix and scoring rules
·Define risk appetite and tolerance statements for cyber risk with leadership, aligned with the enterprise risk management (ERM) framework and ISO 31000
·Write the risk management policy, procedures and templates, including risk acceptance, exceptions and escalation thresholds
·Align the framework with NCA ECC risk management requirements, ISO/IEC 27005 and NIST SP 800-30
Assess cyber risk
·Enterprise level: identify and assess the organisation's top cyber risks and scenarios (e.g. ransomware, data breach, payment fraud, service outage, OT disruption) with business and technology leaders
·Systems and projects: run risk assessments for critical systems, new projects and major changes before go-live, and agree treatment with owners
·New technology: assess the risk of adopting new technologies such as cloud services, AI and IoT platforms, and recommend conditions for safe use
·Specialist inputs: bring together findings from vulnerability management, penetration testing, OT security, third-party risk and threat intelligence into a single, joined-up risk view
·Run risk workshops that get honest input from business owners, and challenge optimistic or vague risk ratings
Treat and monitor risk
·Maintain the cyber risk register: owners, ratings, treatment plans, due dates and status
·Track treatment plans to completion, re-assess residual risk, and escalate overdue or rising risks
·Manage the risk acceptance and exception process, making sure acceptances are justified, approved at the right level and time-limited
·Define key risk indicators (KRIs) and thresholds, and monitor them with the Performance Management team
Report and advise
·Produce clear risk reports and heat maps for management and the risk committee, explaining what changed, why it matters and what decisions are needed
·Senior: introduce quantitative risk analysis (e.g. FAIR) for top risks to express exposure in financial terms
·Configure and run risk workflows in the GRC platform (e.g. Archer, ServiceNow IRM, MetricStream)
Leadership Capabilities:
- Builds own understanding of our purpose and values; explores opportunities for impact.
- Demonstrates strong commitment to personal learning and development; acts as a brand ambassador to help attract top talent.
- Understands expectations and demonstrates personal accountability for keeping performance on track.
- Actively focuses on developing effective communication and relationship-building skills.
- Understands how their daily work contributes to the priorities of the team and the business.
Qualifications:
- Years of experience: 4-8 total years
- Bachelor's in cybersecurity, IT, risk management or a related field
- Has designed or substantially improved a cyber or IT risk methodology (Senior), or run risk assessments end to end (Mid)
- Strong understanding of cybersecurity threats and controls, enough to judge technical risk credibly
- Working knowledge of ISO/IEC 27005, NIST SP 800-30, ISO 31000 and NCA ECC
- Clear written English for management and committee reporting
- Experience with a GRC platform (Archer, ServiceNow IRM, MetricStream or similar) is preferred.
- Quantitative risk analysis experience (FAIR) is preferred.
- Experience linking cyber risk to enterprise risk management in a large organisation is preferred.
- Background in large-scale development, hospitality, financial services or critical infrastructure is preferred.
- Arabic Language is preferred.
- At least one preferred: CRISC, ISO/IEC 27005 Risk Manager, CISM. Also valued: Open FAIR, CISSP, ISO 31000 Risk Manager.
- Frameworks & Standards: NCA ECC-2:2024 · ISO/IEC 27005:2022 · ISO 31000:2018 · NIST SP 800-30 Rev 1 · NIST SP 800-37 Rev 2 · NIST CSF 2.0 (Govern – Risk Management) · FAIR