Senior Consultant – Senior Manager| Cyber Operate | Security Architecture | KSA
Deloitte Middle East · Riyadh, Saudi Arabia · 1d ago
SeniorOn-siteTechnology & Digital Consulting
About Deloitte: When you work for us, you commit to a career at one of the largest and most prestigious professional services firms in the world. We have received numerous awards over the last few years, including Best Employer in the Middle East, and Best Consulting Firm, and the Middle East Training & Development Excellence Award.
Our Purpose
Deloitte makes an impact that matters. Every day we challenge ourselves to do what matters most—for clients, for our people, and for society. We serve clients distinctively, bringing innovative insights, solving complex challenges and unlocking sustainable growth. We inspire our talented professionals to deliver outstanding value to clients, providing an exceptional career experience and an inclusive and collaborative culture. We contribute to society, building confidence and trust in the markets, upholding the integrity of organizations and supporting our communities.
Our shared values guide the way we behave to make a positive, enduring impact:
• Lead the way• Serve with integrity• Take care of each other• Foster inclusion• Collaborate for measurable impact
During your tenure as a Senior Consultant – Senior Manager, you will demonstrate and develop your capabilities in the following areas.
Set the architecture and standards
• Define and maintain the cybersecurity reference architecture, design principles and reusable security patterns, and publish them as the standard projects must follow• Write technical security standards for identity, network, cloud, endpoint, data protection and application security, mapped to NCA ECC, CCC, DCC and NIST SP 800-53• Design the zero trust target architecture and a phased path to reach it
Assure new solutions
• Run security architecture reviews and design approvals for new projects, platforms and vendor solutions, and issue clear review reports with conditions• Lead threat modelling for critical and guest-facing systems, focusing on the threats that matter rather than long generic lists• Explain design trade-offs in plain terms to engineers, project managers and executives, and hold the line on risks that can't be accepted
Design key security capabilities
• Design controls for identity and privileged access, network segmentation, secure remote access, encryption and key management, and cloud security posture• Embed security into the SDLC and DevSecOps pipelines with engineering and AppSec teams• Evaluate and select security technologies with practical proof-of-concept testing, and maintain the security technology roadmap
Work across the programme
• Work with the Strategy team so the architecture supports the roadmap, and with OT Security on IT/OT boundaries• Keep an up-to-date view of architecture risks and exceptions, and report them to governance
Leadership Capabilities:
• Builds own understanding of our purpose and values; explores opportunities for impact.• Demonstrates strong commitment to personal learning and development; acts as a brand ambassador to help attract top talent.• Understands expectations and demonstrates personal accountability for keeping performance on track.• Actively focuses on developing effective communication and relationship-building skills.• Understands how their daily work contributes to the priorities of the team and the business.
Qualifications:
• Years of experience: 6-10 total years• Bachelor's in computer science, engineering or a related field• Hands-on depth in at least two of: identity and access, network security, cloud security (Azure, AWS or GCP), application security• Has produced security architectures or design reviews for real systems in production• Working knowledge of NCA ECC, CCC and DCC, and NIST SP 800-53• Clear written and verbal English• SABSA or TOGAF training or practice• Zero trust design and implementation experience (NIST SP 800-207)• Experience with large digital, hospitality, smart-city or critical-infrastructure environments• Arabic Language is a bonus• At least one preferred: CISSP (ISSAP a plus), SABSA, CCSP. Also valued: TOGAF, AZ-500 / SC-100, AWS Certified Security – Specialty, CCSK.• Frameworks Knowledge: NCA ECC-2:2024 · NCA CCC · NCA DCC · NIST SP 800-53 Rev 5 · NIST SP 800-207 · ISO/IEC 27001/27002:2022 · SABSA · TOGAF