📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة

وظيفة مدير مخاطر المؤسسات والحوكمة لدى ديلويت بالرياض

Manager | Enterprise Risk | GRC | Middle East
🏢 Deloitte
🕒 نُشرت: (أمس) 📍 الرياض وظائف المالية والمحاسبة
التقديم على الوظيفة من المصدر الرسمي ↗

تفاصيل الوظيفة

فرصة للعمل كمدير (Manager) في مجال إدارة المخاطر المؤسسية والحوكمة والامتثال والالتزام (GRC) لدى Deloitte في الرياض، المملكة العربية السعودية. Deloitte هي واحدة من أكبر شركات الخدمات المهنية وأكثرها شهرة عالمياً، وقد حصلت على جوائز عديدة تشمل أفضل شركة استشارية وأفضل صاحب عمل في الشرق الأوسط.

المهام والمسؤوليات

  • قيادة وإدارة برامج تنفيذ Archer كاملة دورة الحياة: تحديد النطاق والتخطيط وتخصيص الموارد والميزانية وإدارة المخاطر والمشكلات وإعداد التقارير التنفيذية.
  • العمل كجهة الاتصال الرئيسية للعميل أثناء تسليم المهام، وإدارة توقعات مدراء المخاطر (CROs) ومدراء أمن المعلومات (CISOs) ورؤساء الامتثال ورعاة البرامج.
  • تحديد النماذج التشغيلية المستهدفة للحوكمة والامتثال والالتزام (GRC)، وهياكل حلول Archer، وخرائط الطريق متعددة السنوات التي تغطي حالات استخدام إدارة المخاطر التشغيلية (ORM) وإدارة استمرارية الأعمال (BCM) وإدارة مخاطر الطرف الثالث (TPRM) والمرونة التشغيلية (Operational Resilience) والسياسات والتدقيق والامتثال.
  • تقديم ضمان الجودة والسلطة التصميمية على تصاميم الحلول والتكوينات والمخرجات التي ينتجها الفريق.
  • قيادة فرق من 3 إلى 10 مستشارين عبر مناطق جغرافية متعددة؛ إدارة الاستفادة والتدريب والتغذية الراجعة حول الأداء والتطوير الوظيفي.
  • دفع تطوير الأعمال: تحديد الفرص، وقيادة العروض والمناقشات الشفهية، وتشكيل النماذج التجارية، وبناء العلاقات مع فرق تحالف Archer.
  • تقديم المشورة للعملاء حول مواءمة برامج GRC الخاصة بهم مع اللوائح (مثل متطلبات SAMA BCM وتوقعات CBUAE للمرونة التشغيلية وقواعد الاستعانة بمصادر خارجية من البنك المركزي).
  • المساهمة في تطوير الممارسة: المعجلات، والمنهجيات، والقيادة الفكرية، والتدريب الداخلي.

الشروط والمتطلبات

  • درجة البكالوريوس مطلوبة؛ درجة الماجستير (مثل ماجستير إدارة الأعمال أو ماجستير العلوم في المخاطر/أمن المعلومات) تعتبر ميزة إضافية.
  • الشهادات المهنية مثل MBCI/CBCP أو CTPRP/CTPRA أو CRISC أو CISA أو PMP أو ISO 22301/27001 Lead Implementer مرغوبة بشدة.
  • خبرة كبيرة في الشركات الأربع الكبرى أو الاستشارات من الدرجة الأولى أو تقديم تقنية GRC مفضلة.
  • 8-12 سنة من الخبرة الإجمالية، بما في ذلك أكثر من 5 سنوات من خبرة تنفيذ Archer وسنتين أو أكثر من إدارة مهام أو فرق تقنية GRC.
  • سجل في تسليم ما لا يقل عن 3-5 عمليات تنفيذ كاملة لـ Archer كقائد أو مدير.
  • إتقان قوي لهندسة Archer المعمارية وتصميم حالات الاستخدام وAdvanced Workflow والتكاملات واستراتيجية البيئة وتراخيص الاستخدام.
  • شهادات Archer (Archer Certified Professional أو ما يعادله) مفضلة بشدة؛ الإلمام بالمنصات المنافسة (ServiceNow IRM، MetricStream، Diligent) يعتبر ميزة.
  • خبرة في منهجيات حوكمة البرامج (Agile، hybrid، waterfall) وأدوات مثل Jira/Azure DevOps.
  • فهم المشهد التنظيمي الإقليمي بما في ذلك إطار الأمن السيبراني SAMA ومتطلبات BCM، وNCA ECC (KSA)، ولوائح CBUAE وNESA/SIA (UAE)، وتوجيهات البنك المركزي المصري، ولوائح البنك المركزي الأردني، وإرشادات State Bank of Pakistan / SECP.
  • الإلمام بلوائح المرونة التشغيلية الإقليمية والاستعانة بمصادر خارجية/الطرف الثالث الصادرة عن البنوك المركزية والهيئات التنظيمية المالية في دول مجلس التعاون الخليجي.
  • خبرة في تسليم المشاريع في الشرق الأوسط أو شمال أفريقيا أو جنوب آسيا مفضلة بشدة.
  • إتقان اللغة الإنجليزية مطلوب؛ مهارات اللغة العربية تعد ميزة قوية للأدوار في الإمارات والسعودية ومصر والأردن.

المهارات المطلوبة

  • خبرة واسعة في مجال GRC (إدارة استمرارية الأعمال BCM، إدارة مخاطر الطرف الثالث TPRM والمرونة التشغيلية): تصميم وتنفيذ برامج BCM والتقنيات ذات الصلة، منهجية تحليل تأثير الأعمال (BIA) وتخطيط استمرارية/تعافي الكوارث وتمارين الاختبار وإدارة الأزمات بما يتوافق مع ISO 22301 ولوائح BCM للبنوك المركزية الإقليمية.
  • سجل مثبت في تحولات TPRM: نماذج تشغيل مخاطر الطرف الثالث، منهجيات التصنيف والعناية الواجبة، أتمتة التقييم، المراقبة المستمرة، واعتبارات مخاطر الطرف الرابع/التركيز.
  • فهم قوي لأنظمة المرونة التشغيلية: الخدمات التجارية الهامة/الحرجة، تحمل التأثير، اختبار السيناريوهات الشديدة ولكن المعقولة، وتخطيط الموارد - والقدرة على ترجمة ذلك إلى تصاميم حلول Archer.
  • القدرة على تقديم المشورة حول التقارب بين BCM وTPRM والمرونة ضمن إطار إدارة مخاطر متكامل.
  • مهارات قيادية: بناء فهم للغرض والقيم، واستكشاف فرص التأثير، والالتزام بالتعلم والتطوير الشخصي، والعمل كسفير للعلامة التجارية لجذب المواهب.
  • فهم التوقعات وإظهار المساءلة الشخصية لإبقاء الأداء على المسار الصحيح.
  • التركيز على تطوير مهارات التواصل الفعال وبناء العلاقات.
  • فهم كيفية مساهمة العمل اليومي في أولويات الفريق والأعمال.
عرض النص الأصلي للإعلان
About Deloitte: When you work for us, you commit to a career at one of the largest and most prestigious professional services firms in the world. We have received numerous awards over the last few years, including Best Employer in the Middle East, and Best Consulting Firm, and the Middle East Training & Development Excellence Award.

Our Purpose

Deloitte makes an impact that matters. Every day we challenge ourselves to do what matters most-for clients, for our people, and for society. We serve clients distinctively, bringing innovative insights, solving complex challenges and unlocking sustainable growth. We inspire our talented professionals to deliver outstanding value to clients, providing an exceptional career experience and an inclusive and collaborative culture. We contribute to society, building confidence and trust in the markets, upholding the integrity of organizations and supporting our communities.

Our shared values guide the way we behave to make a positive, enduring impact:

  • Lead the way
  • Serve with integrity
  • Take care of each other
  • Foster inclusion
  • Collaborate for measurable impact

During your tenure as a Manager, you will demonstrate and develop your capabilities in the following areas

  • Lead and manage full-lifecycle Archer implementation programmes: scoping, planning, resourcing, budgeting, risk/issue management, and executive reporting.
  • Act as the primary client contact for engagement delivery, managing expectations of CROs, CISOs, Heads of Compliance, and programme sponsors.
  • Define target-state GRC operating models, Archer solution architectures, and multi-year platform roadmaps covering ORM, BCM, TPRM, Operational Resilience, Policy, Audit, and Compliance use cases.
  • Provide quality assurance and design authority over solution designs, configurations, and deliverables produced by the team.
  • Lead teams of 3-10 consultants across multiple geographies; manage utilization, coaching, performance feedback, and career development.
  • Drive business development: identify opportunities, lead proposals and orals, shape commercial models, and build relationships with Archer alliance teams.
  • Advise clients on regulatory alignment of their GRC programmes (e.g., SAMA BCM requirements, CBUAE operational resilience expectations, central bank outsourcing rules).
  • Contribute to practice development: accelerators, methodologies, thought leadership, and internal training.

GRC Domain Experience (BCM, TPRM & Operational Resilience)

  • Substantial experience designing and implementing BCM programmes and technology: BIA methodology, continuity/DR planning, exercising regimes, and crisis management aligned to ISO 22301 and regional central bank BCM regulations.
  • Proven delivery of TPRM transformations: third-party risk operating models, tiering and due-diligence methodologies, assessment automation, continuous monitoring, and fourth-party/concentration risk considerations.
  • Strong grasp of Operational Resilience regimes: critical/important business services, impact tolerances, severe-but-plausible scenario testing, and resource mapping - and the ability to translate these into Archer solution designs.
  • Ability to advise on convergence of BCM, TPRM, and resilience within an integrated risk management framework.

Leadership Capabilities

  • Builds own understanding of our purpose and values; explores opportunities for impact.
  • Demonstrates strong commitment to personal learning and development; acts as a brand ambassador to help attract top talent.
  • Understands expectations and demonstrates personal accountability for keeping performance on track.
  • Actively focuses on developing effective communication and relationship-building skills.
  • Understands how their daily work contributes to the priorities of the team and the business. 

Qualifications

  • Bachelor's degree required; Master's degree (e.g., MBA, MSc in Risk/Information Security) is a plus.
  • Professional certifications such as MBCI/CBCP, CTPRP/CTPRA, CRISC, CISA, PMP, or ISO 22301/27001 Lead Implementer are highly desirable.
  • Significant experience in Big 4, top-tier consulting, or GRC technology delivery organizations preferred.
  • 8-12 years of total experience, including 5+ years of Archer implementation experience and 2+ years managing GRC technology engagements or teams.
  • Track record of delivering at least 3-5 full-lifecycle Archer implementations as a lead or manager.
  • Strong command of Archer architecture, use-case design, Advanced Workflow, integrations, environment strategy, and licensing constructs.
  • Archer certifications (Archer Certified Professional or equivalent) strongly preferred; familiarity with competing platforms (ServiceNow IRM, MetricStream, Diligent) is an advantage.
  • Experience with programme governance methodologies (Agile, hybrid, waterfall) and tools such as Jira/Azure DevOps.
  • Understanding of regional regulatory landscapes, including SAMA Cyber Security Framework and BCM requirements, NCA ECC (KSA), CBUAE regulations and NESA/SIA (UAE), Central Bank of Egypt directives, Central Bank of Jordan regulations, and State Bank of Pakistan / SECP guidelines.
  • Familiarity with regional operational resilience and outsourcing/third-party regulations issued by GCC central banks and financial regulators.
  • Experience delivering projects in the Middle East, North Africa, or South Asia is strongly preferred.
  • Fluency in English is required; Arabic language skills are a strong advantage for UAE, KSA, Egypt, and Jordan-based roles.
المصدر: LinkedIn - أُضيفت للموقع في 20 يوليو 2026

وظائف أخرى لدى Deloitte