Senior Consultant/ Manager| Cyber Operate | Governance & PMO Specialist |KSA
Deloitte Middle East · Riyadh, Saudi Arabia · 1d ago
Senior Consultant/ Manager| Cyber Operate | Governance & PMO Specialist |KSA
About Deloitte: When you work for us, you commit to a career at one of the largest and most prestigious professional services firms in the world. We have received numerous awards over the last few years, including Best Employer in the Middle East, and Best Consulting Firm, and the Middle East Training & Development Excellence Award.
Our Purpose
Deloitte makes an impact that matters. Every day we challenge ourselves to do what matters most—for clients, for our people, and for society. We serve clients distinctively, bringing innovative insights, solving complex challenges and unlocking sustainable growth. We inspire our talented professionals to deliver outstanding value to clients, providing an exceptional career experience and an inclusive and collaborative culture. We contribute to society, building confidence and trust in the markets, upholding the integrity of organizations and supporting our communities.
Our shared values guide the way we behave to make a positive, enduring impact:
During your tenure as a Senior Consultant/ Manager, you will demonstrate and develop your capabilities in the following areas
Design and maintain the governance framework
·Design the cybersecurity governance framework: governance structure, decision rights, roles and RACI across the CISO office, IT, OT, risk, legal, procurement and business units
·Write and maintain the cybersecurity policy framework: top-level policy, domain policies, standards, processes, procedures and SOPs, mapped to NCA ECC-2:2024 and other applicable NCA controls
·Run the document lifecycle: drafting, stakeholder review, approval, publication, communication, periodic review and version control
·Maintain the ISMS governance components (scope, context, roles, management review) toward ISO/IEC 27001:2022
·Define the cybersecurity roles and responsibilities matrix required by NCA ECC, and keep it current as the organisation grows
Run governance bodies
·Set up and run the cybersecurity steering committee and working groups: charters, membership, meeting calendar, agendas, decision packs, minutes and action tracking
·Prepare clear, decision-focused papers for executives, and follow up on decisions and actions until they are closed
Run the programme management office
·Build and maintain the integrated programme plan across all domains, with milestones, dependencies and critical path (e.g. MS Project, Primavera, Smartsheet)
·Run the RAID log (risks, assumptions, issues, dependencies), and escalate blockers early with options, not just problems
·Manage change control for scope, schedule and resources
·Track resourcing, onboarding, timesheets and budget against plan for the programme team
·Run the programme's weekly and monthly status reporting, and produce dashboards and executive summaries for leadership
·Coordinate with the service management office (SMO), centre of excellence (CoE) and domain leads so work flows smoothly across the programme
Assure quality and delivery
·Set programme standards for deliverables: templates, quality review steps and acceptance criteria
·Run quality reviews and manage deliverable submission and formal acceptance
·Maintain the programme document repository and records so evidence is easy to find for audits and regulators
Leadership Capabilities:
- Builds own understanding of our purpose and values; explores opportunities for impact.
- Demonstrates strong commitment to personal learning and development; acts as a brand ambassador to help attract top talent.
- Understands expectations and demonstrates personal accountability for keeping performance on track.
- Actively focuses on developing effective communication and relationship-building skills.
- Understands how their daily work contributes to the priorities of the team and the business.
Qualifications:
·Years of experience: 5-10 total years
·Bachelor's in cybersecurity, IT, business or a related field
·Has designed or substantially updated a cybersecurity governance framework or policy suite (Senior); has written policies, procedures or SOPs (Mid)
·Proven PMO or programme management experience on large, multi-workstream programmes: planning, RAID, change control and status reporting
·Working knowledge of NCA ECC, ISO/IEC 27001 and NIST CSF 2.0
·Strong stakeholder management and executive reporting
·Clear, concise written English
·Experience setting up and running steering committees in Saudi government or large private entities
·Experience with planning tools (MS Project, Primavera, Smartsheet) and Power BI dashboards
·Experience coordinating with service management (ITIL) functions
·Consulting background
·Arabic language is a plus.
·At least one preferred: PMP, CISM, CGEIT. Also valued: PgMP, PRINCE2 / MSP, ISO/IEC 27001 Lead Implementer, COBIT.
·NCA ECC-2:2024 · ISO/IEC 27001:2022 · ISO/IEC 27014 · NIST CSF 2.0 (Govern) · COBIT 2019 · PMI PMBOK · PRINCE2 / MSP