ديلويت تعلن عن وظيفة مستشار أول/مدير - أخصائي التوعية والتدريب في الأمن السيبراني بالرياض
تفاصيل الوظيفة
شركة Deloitte، إحدى أكبر شركات الخدمات المهنية وأكثرها شهرة على مستوى العالم، تبحث عن Senior Consultant/Manager في Cyber Operate تخصص Awareness, Training & Communications، للعمل في الرياض، المملكة العربية السعودية.
المهام والمسؤوليات
- بناء ثقافة أمن سيبراني لدى جميع الموظفين والقيادات، بحيث يُنظر إلى الأمن كمسؤولية الجميع وليس فقط فريق تقنية المعلومات.
- تعزيز عقلية تركز على الأمن السيبراني في القرارات اليومية، بدءاً من كيفية تعامل الموظفين مع البيانات والموردين وصولاً إلى تصميم المشاريع والخدمات.
- إشراك القيادات التنفيذية كقدوة مرئية من خلال رسائل قيادية ورعاية حملات والمشاركة في التمارين.
- قياس ثقافة الأمن السيبراني بمرور الوقت عبر الاستبيانات وبيانات السلوك وتقارير الاتجاهات، واستهداف المجالات الأضعف في الثقافة.
- تصميم إطار عمل الوعي والتدريب والثقافة السيبرانية واستراتيجية متعددة السنوات، تشمل الجماهير والسلوكيات الرئيسية والقنوات والخطة السنوية ومقاييس النجاح، بما يتوافق مع متطلبات الوعي والتدريب في NCA ECC.
- كتابة وصيانة سياسة الوعي والتدريب والإجراءات وسجلات إجراءات العمل التشغيلية، بما في ذلك قواعد التدريب الإلزامي ومتطلبات الإعداد والتمارين المحاكية للتصيد وقواعد التصعيد للمكررين.
- إجراء تحليل للجمهور لفهم مخاطر كل مجموعة وأنماط عملها وقنواتها المفضلة، بما في ذلك الموظفون الذين لا يستخدمون أجهزة كمبيوتر بانتظام.
- تصميم وإجراء تمارين محاكاة للطاولة (Tabletop Exercises) للقيادات وفرق إدارة الأزمات وتقنية المعلومات والتقنية التشغيلية ووحدات الأعمال، بناءً على سيناريوهات واقعية مثل برامج الفدية وخرق البيانات واختراق الموردين والاحتيال المالي وتعطيل العمليات.
- تيسير التمارين وتوثيق الدروس المستفادة وتتبع إجراءات التحسين بالتعاون مع فرق الحوكمة والمخاطر.
- تصميم حملات توعية حول مواضيع ذات أولوية مثل التصيد وكلمات المرور والمصادقة متعددة العوامل والهندسة الاجتماعية وحماية البيانات (PDPL) والاستخدام الآمن لأدوات الذكاء الاصطناعي وأمن الأجهزة المحمولة والسفر والأمن المادي.
- إنتاج محتوى جذاب باللغتين العربية والإنجليزية: النشرات الإخبارية والملصقات ومقاطع الفيديو القصيرة والرسوم البيانية وصفحات الإنترانت واللافتات الرقمية.
- تنظيم فعاليات مثل شهر التوعية السيبرانية والجولات والمسابقات وزيارات ميدانية لفرق العمليات والمواقع.
- تصميم وتقديم تدريب قائم على الأدوار لجميع الموظفين والقيادات وأعضاء مجلس الإدارة وفرق تقنية المعلومات والتقنية التشغيلية والمطورين والمستخدمين المميزين والمالية والمشتريات والمقاولين.
- بناء تدريب أمني للموظفين الجدد والمقاولين والعاملين الموسميين.
- إدارة المحتوى التدريبي والتكليفات في نظام إدارة التعلم (LMS) وتتبع معدلات الإنجاز.
- تقديم جلسات مباشرة وورش عمل وإحاطات تنفيذية.
- إصدار تنبيهات وتحذيرات أمنية واضحة للموظفين أثناء التهديدات النشطة، بالتنسيق مع مركز العمليات الأمنية والاتصالات المؤسسية.
- الإبلاغ عن تقدم برنامج الأمن السيبراني وإنجازاته داخلياً، ليُدرك الجميع أهمية الأمن.
- تخطيط وإجراء محاكاة للتصيد والرسائل النصية والهندسة الصوتية (مثل KnowBe4، Proofpoint) مع زيادة الصعوبة تدريجياً، وتقديم تدريب متابعة لمن يفشل.
- قياس ما يتغير فعلياً، وليس مجرد الحضور: معدلات النقر والإبلاغ، والمكررين، واتجاهات الإبلاغ عن الحوادث، ونتائج التمارين، واستبيانات الثقافة.
- الإبلاغ عن نتائج البرنامج واتجاهاته لفرق الحوكمة وإدارة الأداء، وتعديل الخطة بناءً على البيانات.
- العمل مع الموارد البشرية بشأن الإعداد والتدريب الإلزامي والإقرار بالسياسات.
- العمل مع الاتصالات المؤسسية بشأن العلامة التجارية والنبرة والقنوات.
- بناء شبكة من سفراء الأمن عبر الأقسام والمواقع لنشر الثقافة في كل فريق.
الشروط والمتطلبات
- خبرة مهنية إجمالية من 3 إلى 7 سنوات.
- درجة البكالوريوس في الاتصالات أو الأمن السيبراني أو تقنية المعلومات أو التعليم أو مجال ذي صلة.
- خبرة في تصميم أو إدارة برنامج توعية أو ثقافة أمنية، بما في ذلك محاكاة التصيد (للمستوى Senior)؛ خبرة في تقديم حملات توعية وتدريب (للمستوى Mid).
- خبرة في تصميم أو تيسير تمارين محاكاة الطاولة السيبرانية (لل Senior).
- إجادة ممتازة للكتابة وإنشاء المحتوى باللغتين العربية والإنجليزية.
- فهم متين للتهديدات السيبرانية الشائعة (التصيد، الهندسة الاجتماعية، سرقة الحسابات) ومتطلبات الوعي من NCA ECC.
- مقدم عروض واثق لجماهير تتراوح من موظفي الخط الأمامي إلى القيادات التنفيذية.
- خبرة مع منصات محاكاة التصيد والوعي (KnowBe4، Proofpoint، Cofense أو ما شابه) وإدارة نظام إدارة التعلم (LMS).
- خبرة في قياس الثقافة الأمنية (استبيانات الثقافة، مقاييس السلوك).
- مهارات تصميم المحتوى (Canva، Adobe، تحرير فيديو قصير).
- خبرة مع قوى عاملة مختلطة كبيرة مثل الضيافة والمواقع والعمليات أو المقاولين.
- خلفية في العلوم السلوكية أو تعليم الكبار.
- اللغة العربية تعتبر ميزة إضافية.
- شهادة واحدة على الأقل مفضلة: SANS Security Awareness Professional (SSAP)، CompTIA Security+، CISM. وكذلك SANS Security Culture (LDR433)، CIPD أو مؤهلات أخرى في التعلم والتطوير أو الاتصالات.
- معرفة بمعايير مثل NCA ECC-2:2024 (الوعي والتدريب)، NIST SP 800-50 Rev 1، NIST SP 800-84 (التمارين)، ISO/IEC 27001:2022 (A.6.3)، PDPL (الوعي بالالتزامات).
المهارات المطلوبة
- بناء فهم شخصي لغرض الشركة وقيمها، واستكشاف فرص التأثير.
- إظهار التزام قوي بالتعلم والتطوير الشخصي؛ والعمل كسفير للعلامة التجارية للمساعدة في جذب أفضل المواهب.
- فهم التوقعات وإظهار المساءلة الشخصية للحفاظ على الأداء في مساره الصحيح.
- التركيز بنشاط على تطوير مهارات التواصل الفعال وبناء العلاقات.
- فهم كيفية مساهمة العمل اليومي في أولويات الفريق والأعمال.
- مهارات متقدمة في الكتابة والتحدث بالعربية والإنجليزية.
- إتقان استخدام أدوات التصميم والمحتوى الرقمي.
- القدرة على تحليل البيانات واستخلاص الأفكار لتحسين البرامج.
- مهارات تنظيمية وتنسيقية عالية لإدارة حملات متزامنة.
- مهارات تسهيل ورش العمل والجلسات التفاعلية.
عرض النص الأصلي للإعلان
Our Purpose
Deloitte makes an impact that matters. Every day we challenge ourselves to do what matters most-for clients, for our people, and for society. We serve clients distinctively, bringing innovative insights, solving complex challenges and unlocking sustainable growth. We inspire our talented professionals to deliver outstanding value to clients, providing an exceptional career experience and an inclusive and collaborative culture. We contribute to society, building confidence and trust in the markets, upholding the integrity of organizations and supporting our communities.
Our shared values guide the way we behave to make a positive, enduring impact:
During your tenure as a Senior Consultant/Manager, you will demonstrate and develop your capabilities in the following areas
Build a cybersecurity culture
- Build a sense of cybersecurity ownership across the workforce and executives, so security is seen as everyone's responsibility, not only the IT team's
- Drive a cybersecurity-first mindset in day-to-day decisions, from how staff handle data and suppliers to how projects and services are designed
- Engage executives and senior leaders as visible role models: leadership messages, sponsorship of campaigns and participation in exercises
- Measure cybersecurity culture over time through surveys, behaviour data and reporting trends, and target the areas where culture is weakest
- Design the cybersecurity awareness, training and culture framework and multi-year strategy: audiences, key behaviours, channels, annual plan and success measures, aligned with NCA ECC awareness and training requirements
- Write and maintain the awareness and training policy, procedures and SOPs, including mandatory training rules, onboarding requirements, phishing simulation rules and escalation for repeat clickers
- Run audience analysis to understand each group's risks, working patterns and preferred channels, including staff without regular computer access
- Design and run cybersecurity tabletop exercises for executives, crisis management teams, IT, OT and business units, based on realistic scenarios such as ransomware, data breach, supplier compromise, payment fraud and disruption to venue or guest operations
- Facilitate the exercises, capture lessons learned, and track improvement actions with the Governance and Risk teams
- Design themed awareness campaigns on priority topics such as phishing, passwords and MFA, social engineering, data protection (PDPL), safe use of AI tools, mobile and travel security, and physical security
- Produce engaging content in Arabic and English: newsletters, posters, short videos, infographics, intranet pages and digital signage
- Organise events such as cybersecurity awareness month, roadshows, competitions and site visits to operational and venue teams
- Design and deliver role-based training for all staff, executives and board members, IT and OT teams, developers, privileged users, finance and procurement, and contractors
- Build onboarding security training for new joiners, contractors and seasonal staff
- Manage training content and assignments in the learning management system (LMS), and track completion against targets
- Run live sessions, workshops and executive briefings
- Issue clear security advisories and alerts to staff during active threats, in coordination with the SOC and Corporate Communications
- Communicate the cybersecurity programme's progress and achievements internally, so people see why security matters
- Plan and run phishing, smishing and vishing simulations (e.g. KnowBe4, Proofpoint), increasing difficulty over time, with follow-up training for those who fail
- Measure what changes, not just attendance: click and report rates, repeat offenders, incident reporting trends, exercise outcomes and culture survey results
- Report programme results and trends to the Governance and Performance Management teams, and adjust the plan based on the data
- Work with HR on onboarding, mandatory training and policy acknowledgement
- Work with Corporate Communications on brand, tone and channels
- Build a network of security champions across departments and sites to carry the culture into every team
- Builds own understanding of our purpose and values; explores opportunities for impact.
- Demonstrates strong commitment to personal learning and development; acts as a brand ambassador to help attract top talent.
- Understands expectations and demonstrates personal accountability for keeping performance on track.
- Actively focuses on developing effective communication and relationship-building skills.
- Understands how their daily work contributes to the priorities of the team and the business.
- Years of experience: 3-7 total professional years.
- Bachelor's in communications, cybersecurity, IT, education or a related field
- Has designed or run a security awareness or culture programme, including phishing simulations (Senior); has delivered awareness campaigns and training (Mid)
- Experience designing or facilitating cybersecurity tabletop exercises (Senior)
- Excellent writing and content creation skills in both Arabic and English
- Solid understanding of common cyber threats (phishing, social engineering, account takeover) and NCA ECC awareness requirements
- Confident presenter to audiences from front-line staff to executives
- Experience with phishing simulation and awareness platforms (KnowBe4, Proofpoint, Cofense or similar) and LMS administration
- Experience measuring security culture (culture surveys, behaviour metrics)
- Content design skills (Canva, Adobe, short video editing)
- Experience with large, mixed workforces such as hospitality, venues, operations or contractors
- Behavioural science or adult learning background
- Arabic Language is a plus.
- At least one preferred: SANS Security Awareness Professional (SSAP), CompTIA Security+, CISM. Also valued: SANS Security Culture (LDR433), CIPD or other learning and development or communications qualifications.
- NCA ECC-2:2024 (awareness and training)
- NIST SP 800-50 Rev 1
- NIST SP 800-84 (exercises)
- ISO/IEC 27001:2022 (A.6.3)
- PDPL (awareness of obligations)
رقم الإعلان لدى المصدر: 4477402765