وظيفة مهندس ذكاء اصطناعي وتعلم آلي لأمن السيبراني (استشاري/مدير) لدى Deloitte في الرياض
تفاصيل الوظيفة
انضم إلى شركة Deloitte، إحدى أكبر وأعرق شركات الخدمات المهنية في العالم، والحاصلة على جوائز عديدة منها أفضل جهة عمل في الشرق الأوسط وأفضل شركة استشارات. نبحث حاليًا عن Senior Consultant/Manager في مجال Cyber Operate بتخصص AI/ML Engineer (Cyber Automation) للعمل في الرياض، المملكة العربية السعودية.
المهام والمسؤوليات
- تحديد وترتيب أولويات الفرص من خلال العمل مع قادة المجالات لرسم خريطة للمهام اليدوية والمتكررة وذات الحجم الكبير في مجالات الاستراتيجية والتقييم التقني والمخاطر والامتثال وإدارة المخاطر والجهات الخارجية (TPRM) والحوكمة وإدارة الأداء.
- بناء قائمة متراكبة من حالات الاستخدام للذكاء الاصطناعي والأتمتة مع تقدير الوقت الموفّر والمخاطر والجهد لكل حالة.
- تتبع التطورات والممارسات الجيدة في الذكاء الاصطناعي ومشاركتها مع فريق التوجيه الابتكاري والبرنامج الأوسع.
- تصميم وبناء ونشر حلول متنوعة، مثل: تحليل الأدلة والوثائق (مراجعة السياسات والعقود وتقارير SOC 2 وأدلة الامتثال)، أتمتة TPRM (تعبئة ومراجعة استبيانات الموردين وتحديد الثغرات)، تحليلات الثغرات (إثراء وتحديد أولويات النتائج باستخدام بيانات الأصول والتهديدات والاستغلال)، أتمتة التقارير (توليد تقارير التقييم الأولية ولوحات المعلومات والملخصات التنفيذية)، المساعدين الذكيين (مساعدة الفريق في البحث عن الأطر والسياسات والأعمال السابقة)، كشف الشذوذ (حالات كشف مع SOC عند الاقتضاء).
- بناء خطوط أنابيب البيانات وعمليات التكامل مع أدوات الأمان ومنصات GRC وTPRM وأنظمة التذاكر وPower BI.
- اختيار النهج المناسب لكل مشكلة (قواعد، نصوص برمجية، تعلم آلي تقليدي، نماذج لغوية كبيرة - LLMs) دون افتراض استخدام الذكاء الاصطناعي افتراضيًا.
- جعل الذكاء الاصطناعي آمنًا ومسؤولًا عبر وضع معايير للاستخدام الآمن (معالجة البيانات، المراجعة البشرية لمخرجات الذكاء الاصطناعي، أمان النماذج، التسجيل)، حماية البيانات الحساسة ضمن البيئات المعتمدة مع الامتثال لمتطلبات PDPL وNCA وSDAIA، اختبار الحلول ضد هجمات حقن البرمجيات وتسرب البيانات والمخرجات غير الصحيحة وفقًا لـ OWASP Top 10 لتطبيقات LLM وNIST AI RMF.
- تطبيق ممارسات MLOps: التحكم بالإصدارات، الاختبار، المراقبة، تتبع أداء النماذج، والحوكمة الموثقة لكل حل.
- توثيق الحلول بوضوح وتدريب المتخصصين على استخدامها بفعالية.
- قياس التبني والوقت الموفّر، وتقديم النتائج إلى قيادة البرنامج بالتعاون مع فريق إدارة الأداء.
- تعزيز فهم القيم والغرض للشركة، واستكشاف فرص التأثير.
- إظهار التزام قوي بالتعلم والتطوير الشخصي، والعمل كسفير للعلامة التجارية لجذب المواهب.
- فهم التوقعات وتحمل المسؤولية الشخصية للحفاظ على الأداء في المسار الصحيح.
- التركيز على تطوير مهارات التواصل وبناء العلاقات بفعالية.
- فهم كيف يساهم العمل اليومي في أولويات الفريق والأعمال.
الشروط والمتطلبات
- إجمالي سنوات الخبرة المهنية: من 3 إلى 7 سنوات.
- درجة البكالوريوس أو الماجستير في علوم الحاسب، علم البيانات، الذكاء الاصطناعي أو مجال ذي صلة.
- إجادة قوية للغة Python مع خبرة في نشر حلول تعتمد على ML أو LLM في بيئات عملية (وليس مجرد نماذج أولية).
- خبرة مع أطر ML وLLM (مثل PyTorch, scikit-learn, LangChain, LlamaIndex أو ما يشابهها) وبناء حلول RAG (Retrieval-Augmented Generation).
- خبرة مع منصات الذكاء الاصطناعي السحابية (Azure OpenAI / Azure AI, AWS Bedrock / SageMaker أو GCP Vertex AI) وواجهات برمجة التطبيقات (APIs).
- مهارات في هندسة البيانات: SQL, pandas وبناء خطوط أنابيب البيانات.
- فهم ممارسات الذكاء الاصطناعي الآمن والمسؤول.
- خبرة في مجال الأمن السيبراني، GRC أو إدارة المخاطر.
- خبرة في التكامل مع ServiceNow, Archer, OneTrust أو واجهات برمجة التطبيقات لأدوات الأمان.
- خبرة في أدوات MLOps (MLflow, Docker, CI/CD).
- معرفة باللوائح السعودية للذكاء الاصطناعي والبيانات (مبادئ SDAIA لأخلاقيات الذكاء الاصطناعي، PDPL).
- اللغة العربية تعتبر ميزة إضافية.
- يفضل الحصول على شهادة واحدة على الأقل من: Microsoft Azure AI Engineer (AI-102), AWS Certified Machine Learning (Specialty or Engineer), Google Professional Machine Learning Engineer. كما تُقدّر شهادات: ISO/IEC 42001 Lead Implementer, IAPP AIGP.
- الإلمام بـ: NIST AI RMF 1.0, ISO/IEC 42001, مبادئ SDAIA لأخلاقيات الذكاء الاصطناعي, OWASP Top 10 لتطبيقات LLM, PDPL, NCA ECC-2:2024.
المهارات المطلوبة
- Python متقدم مع تطبيقات عملية في ML وLLM.
- أطر العمل: PyTorch, scikit-learn, LangChain, LlamaIndex.
- حلول RAG واسترجاع البيانات المعززة.
- منصات سحابية: Azure OpenAI/AI, AWS Bedrock/SageMaker, GCP Vertex AI.
- هندسة البيانات: SQL, pandas.
- ممارسات الأمن السيبراني والذكاء الاصطناعي المسؤول.
- خبرة في GRC وأدوات التكامل (ServiceNow, Archer, OneTrust).
- MLOps: MLflow, Docker, CI/CD.
- اللوائح المحلية: SDAIA, PDPL, NCA.
- الشهادات المفضلة: AI-102, AWS ML Specialty, Google ML Engineer, ISO 42001, IAPP AIGP.
- اللغة العربية (ميزة إضافية).
عرض النص الأصلي للإعلان
Our Purpose
Deloitte makes an impact that matters. Every day we challenge ourselves to do what matters most-for clients, for our people, and for society. We serve clients distinctively, bringing innovative insights, solving complex challenges and unlocking sustainable growth. We inspire our talented professionals to deliver outstanding value to clients, providing an exceptional career experience and an inclusive and collaborative culture. We contribute to society, building confidence and trust in the markets, upholding the integrity of organizations and supporting our communities.
Our shared values guide the way we behave to make a positive, enduring impact:
During your tenure as a Senior Consultant/ Manager, you will demonstrate and develop your capabilities in the following areas
Find and prioritise opportunities
- Work with domain leads to map manual, repetitive and high-volume tasks across strategy, technical assessments, risk, compliance, TPRM, governance and performance management
- Build a prioritised backlog of AI and automation use cases, with expected time savings, risk and effort for each
- Track AI advancements and good practice, and share them with the Innovation Guidance Team and the wider programme
- Design, build and deploy solutions such as:
- Evidence and document analysis: reviewing policies, contracts, SOC 2 reports and compliance evidence against required controls
- TPRM automation: pre-filling and reviewing supplier questionnaires and flagging gaps
- Vulnerability analytics: enriching and prioritising findings using asset, threat and exploit data
- Reporting automation: generating draft assessment reports, dashboards and executive summaries
- AI assistants: helping the team search frameworks, policies and past work
- Anomaly detection: detection use cases with the SOC where relevant
- Build data pipelines and integrations with security tools, GRC and TPRM platforms, ticketing systems and Power BI
- Choose the right approach for each problem, whether rules, scripts, classical ML or large language models (LLMs), rather than defaulting to AI
- Define standards for safe AI use in the programme: data handling, human review of AI outputs, prompt and model security, and logging
- Protect sensitive data: keep it within approved environments and meet PDPL, NCA and SDAIA requirements
- Test AI solutions against prompt injection, data leakage and incorrect outputs, following OWASP Top 10 for LLM Applications and NIST AI RMF
- Apply MLOps practices: version control, testing, monitoring, model performance tracking and documented governance of each solution
- Document solutions clearly and train specialists to use them well
- Measure adoption and time saved, and report results to programme leadership with the Performance Management team
- Builds own understanding of our purpose and values; explores opportunities for impact.
- Demonstrates strong commitment to personal learning and development; acts as a brand ambassador to help attract top talent.
- Understands expectations and demonstrates personal accountability for keeping performance on track.
- Actively focuses on developing effective communication and relationship-building skills.
- Understands how their daily work contributes to the priorities of the team and the business.
- Total years of experience: 3-7 total professional years.
- Bachelor's or Master's in computer science, data science, AI or a related field
- Strong Python, with experience shipping ML or LLM-based solutions into real use, not only prototypes
- Experience with ML and LLM frameworks (e.g. PyTorch, scikit-learn, LangChain, LlamaIndex or similar) and building retrieval-augmented (RAG) solutions
- Experience with cloud AI platforms (Azure OpenAI / Azure AI, AWS Bedrock / SageMaker or GCP Vertex AI) and APIs
- Data engineering skills: SQL, pandas and building data pipelines
- Understanding of secure and responsible AI practices
- Cybersecurity, GRC or risk domain experience
- Experience integrating with ServiceNow, Archer, OneTrust or security tool APIs
- MLOps tooling (MLflow, Docker, CI/CD)
- Knowledge of Saudi AI and data regulations (SDAIA AI Ethics Principles, PDPL)
- Arabic language is a plus.
- At least one preferred: Microsoft Azure AI Engineer (AI-102), AWS Certified Machine Learning (Specialty or Engineer), Google Professional Machine Learning Engineer. Also valued: ISO/IEC 42001 Lead Implementer, IAPP AIGP.
- NIST AI RMF 1.0
- ISO/IEC 42001
- SDAIA AI Ethics Principles
- OWASP Top 10 for LLM Applications
- PDPL
- NCA ECC-2:2024
رقم الإعلان لدى المصدر: 4477414296