EY تعلن عن وظيفة مدير استشارات تقنية - الأمن السيبراني وأمن الذكاء الاصطناعي في الرياض
Manager - Technology Consulting - Cybersecurity - AI Security - Riyadh
🏢 EY
تفاصيل الوظيفة
EY تبحث عن مدير للانضمام إلى فريق استشارات تكنولوجيا الأمن السيبراني في الرياض، للعمل على تقديم خدمات حوكمة الذكاء الاصطناعي وإدارة المخاطر والأمن للمؤسسات المالية والجهات الحكومية في الشرق الأوسط.
المهام والمسؤوليات
- قيادة تقييمات نضج حوكمة الذكاء الاصطناعي عبر بيئات الذكاء الاصطناعي المؤسسي والجيل التوليدي.
- تصميم وتنفيذ أطر حوكمة الذكاء الاصطناعي ونماذج التشغيل والسياسات والمعايير والإجراءات والمبادئ التوجيهية.
- تطوير استراتيجيات حوكمة الذكاء الاصطناعي على مستوى المؤسسة تتماشى مع الأهداف التنظيمية والمتطلبات التنظيمية.
- إنشاء لجان حوكمة الذكاء الاصطناعي ونماذج RACI وهياكل اتخاذ القرار.
- إنشاء عمليات حوكمة دورة حياة الذكاء الاصطناعي تشمل مراحل التصور والتطوير والتحقق والنشر والمراقبة والتقاعد.
- تطوير أطر ومنهجيات إدارة مخاطر الذكاء الاصطناعي، وتصنيفات المخاطر، وأطر الرقابة.
- إجراء تقييمات مخاطر الذكاء الاصطناعي والجيل التوليدي تغطي الأمن والخصوصية والامتثال والمخاطر التشغيلية والنموذجية وأطراف ثالثة.
- إعداد سجلات المخاطر وخرائط الحرارة وأطر تسجيل المخاطر وخطط المعالجة.
- تيسير ورش العمل والمقابلات مع المعنيين عبر فرق الأعمال والتكنولوجيا.
- إجراء تقييمات أمنية للذكاء الاصطناعي التوليدي وLLM وRAG وAgentic AI وحلول البحث المعرفي.
- إجراء تمارين نمذجة التهديدات باستخدام OWASP LLM Top 10 وMITRE ATLAS وSTRIDE والممارسات الصناعية الأخرى.
- تقييم التهديدات الخاصة بالذكاء الاصطناعي مثل حقن المطالبات والتسرب والاسترجاع السام وإساءة استخدام النموذج والهلوسة والوكالة المفرطة.
- تقييم فعالية حواجز الأمان وتصفية المحتوى وRBAC وDLP والمراقبة والتسجيل والضوابط الأمنية.
- تطوير مخططات أمنية وأطر رقابية للذكاء الاصطناعي.
- المساعدة في الامتثال التنظيمي للذكاء الاصطناعي والأمن السيبراني وفقًا لـ NIST AI RMF وISO/IEC 42001 وISO 27001 وNIST Cybersecurity Framework وGDPR وEU AI Act وPDPL ومتطلبات SAMA والمتطلبات الإقليمية لحوكمة الذكاء الاصطناعي.
- قيادة مهام استشارية متعددة وضمان تسليم مخرجات عالية الجودة في الوقت المناسب.
- إعداد تقارير تنفيذية وعروض تقديمية ومواد مناسبة لمجالس الإدارة.
- تيسير ورش العمل مع المعنيين من الإدارة العليا والأعمال والتكنولوجيا والمخاطر والقانون والامتثال والخصوصية والأمن.
- إدارة فرق العمل وتوجيه الاستشاريين والاستشاريين الأقدم.
- دعم أنشطة تطوير الأعمال بما في ذلك العروض والرد على طلبات العروض والحلول والعروض التقديمية للعملاء.
الشروط والمتطلبات
- درجة البكالوريوس أو الماجستير في تكنولوجيا المعلومات أو الأمن السيبراني أو علوم الحاسوب أو علوم البيانات أو ما يعادلها.
- 7-12 سنة من الخبرة في الأمن السيبراني أو مخاطر التكنولوجيا أو مخاطر تكنولوجيا المعلومات أو الامتثال أو الحوكمة أو المرونة أو الخدمات الاستشارية، بالإضافة إلى 3-4 سنوات خبرة في حوكمة الذكاء الاصطناعي وإدارة المخاطر ونمذجة التهديدات.
- خبرة في قيادة مهام مواجهة العملاء وإدارة الفرق.
- مهارات ممتازة في التواصل وتيسير ورش العمل وكتابة التقارير.
- خبرة في التعامل مع القيادة العليا والمعنيين التنفيذيين.
المهارات المطلوبة
- فهم قوي لحوكمة الذكاء الاصطناعي والذكاء الاصطناعي المسؤول وإدارة مخاطر الذكاء الاصطناعي وحوكمة دورة الحياة.
- خبرة في تطوير أطر و سياسات ومعايير وإجراءات ونماذج تشغيل حوكمة الذكاء الاصطناعي.
- فهم قوي لسجل حالات استخدام الذكاء الاصطناعي وتصنيف المخاطر وأطر الرقابة ونماذج الإشراف.
- فهم مفاهيم أمن الذكاء الاصطناعي مثل حقن المطالبات والتسرب والاسترجاع السام ومخاطر سلسلة التوريد والوكالة المفرطة.
- خبرة في إجراء تقييمات مخاطر أمنية ونمذجة التهديدات ومراجعات فعالية الرقابة.
- فهم قوي لبرامج الامتثال التنظيمي والحوكمة.
- خبرة في العمل ضمن قطاعات شديدة التنظيم، خاصة الخدمات المالية والحكومة.
- القدرة على التواصل بفعالية مع المعنيين التنفيذيين ومستوى مجالس الإدارة.
- عقلية استشارية قوية ومهارات ممتازة في العرض وإدارة المعنيين.
- مهارات ممتازة في الكتابة والتحدث والعرض.
- يُفضل الحصول على شهادات مثل ISO/IEC 42001 Lead Implementer/Lead Auditor وCISSP وCRISC وCISM وISO 27001 LA/LI.
- خبرة في العمل مع أدوات الذكاء الاصطناعي.
- الإلمام بأمن السحابة والخصوصية والمرونة التشغيلية أو إدارة مخاطر الطرف الثالث.
- خبرة في دعم العملاء في القاعات شديدة التنظيم مثل الخدمات المالية أو الحكومة.
- معرفة بالأطر واللوائح الإقليمية في الشرق الأوسط.
المزايا
نقدم حزمة تعويضات تنافسية حيث ستتم مكافأتك بناءً على الأداء والتقدير للقيمة التي تضيفها لأعمالنا. بالإضافة إلى ذلك، نقدم: التعلم المستمر لتطوير العقلية والمهارات اللازمة للمستقبل، النجاح كما تحدده أنت مع الأدوات والمرونة اللازمة لتحقيق تأثير هادف بطريقتك، القيادة التحويلية من خلال الرؤى والتوجيه والثقة لتصبح القائد الذي يحتاجه العالم، وثقافة متنوعة وشاملة حيث يتم احتضانك لشخصك وتمكينك لاستخدام صوتك لمساعدة الآخرين في العثور على أصواتهم.
عرض النص الأصلي للإعلان
As part of our Cyber Technology Consulting practice, you will lead the delivery of AI Governance, AI Risk Management, Responsible AI and AI Security engagements for leading financial institutions and government entities across the Middle East. This role will focus on helping clients establish enterprise-wide AI Governance frameworks, AI operating models, AI risk management methodologies, AI security assessment programs, and compliance with emerging AI regulations and standards. The successful candidate will work closely with executive stakeholders, risk teams, security teams, compliance functions, legal departments, and technology leaders to operationalize trustworthy and secure AI adoption. This role aligns closely with AI governance and security assessment programs involving AI inventory, AI risk assessments, threat modeling, governance framework development, AI control frameworks, and AI security blueprints.
The opportunity
We are looking for an experienced Manager with a strong consulting background and hands-on expertise in AI Governance, AI Risk Management, Responsible AI, AI Security, and Regulatory Compliance. This is an exceptional opportunity to work with executive leadership teams within major financial institutions and help shape the governance and security foundations of enterprise AI and Generative AI adoption.
The role requires a blend of governance, security, privacy, risk management, regulatory compliance, and stakeholder management capabilities. Applicants should be comfortable leading client engagements, managing teams, conducting assessments, and developing strategic governance frameworks.
Your Key Responsibilities
AI Governance & Operating Model
We offer a competitive compensation package where you’ll be rewarded based on performance and recognized for the value you bring to our business. Plus, we offer:
The Exceptional EY Experience. It’s Yours To Build.
EY | Shape The Future With Confidence
The opportunity
We are looking for an experienced Manager with a strong consulting background and hands-on expertise in AI Governance, AI Risk Management, Responsible AI, AI Security, and Regulatory Compliance. This is an exceptional opportunity to work with executive leadership teams within major financial institutions and help shape the governance and security foundations of enterprise AI and Generative AI adoption.
The role requires a blend of governance, security, privacy, risk management, regulatory compliance, and stakeholder management capabilities. Applicants should be comfortable leading client engagements, managing teams, conducting assessments, and developing strategic governance frameworks.
Your Key Responsibilities
AI Governance & Operating Model
- Lead AI Governance assessments and maturity evaluations across enterprise AI and GenAI environments.
- Design and implement AI Governance Frameworks, Operating Models, Policies, Standards, Procedures, and Guidelines.
- Develop enterprise AI Governance strategies aligned with organizational objectives and regulatory requirements.
- Establish AI Governance Committees, RACI models, and decision-making structures.
- Create AI lifecycle governance processes covering ideation, development, validation, deployment, monitoring, and retirement.
- Develop AI Risk Management Frameworks and methodologies.
- Establish AI risk taxonomies, risk assessment methodologies, and AI control frameworks.
- Conduct AI and GenAI risk assessments covering security, privacy, regulatory, operational, model, and third-party risks.
- Develop AI risk registers, heatmaps, risk scoring frameworks, and remediation roadmaps.
- Facilitate risk workshops and stakeholder interviews across business and technology teams
- Perform AI security assessments for Generative AI, LLM, RAG, Agentic AI, and Cognitive Search solutions.
- Conduct AI threat modeling exercises leveraging OWASP LLM Top 10, MITRE ATLAS, STRIDE, and other industry practices.
- Assess AI-specific threats including prompt injection, indirect prompt injection, data leakage, model abuse, hallucinations, retrieval poisoning, and excessive agency.
- Evaluate effectiveness of AI guardrails, content filtering, RBAC, DLP, monitoring, logging, and security controls.
- Develop AI Security Blueprints and AI Security Control Frameworks.
- NIST AI RMF
- ISO/IEC 42001
- ISO 27001
- NIST Cybersecurity Framework
- GDPR
- EU AI Act
- PDPL
- SAMA-related requirements
- Regional AI governance requirements
- Lead multiple consulting engagements and ensure timely delivery of high-quality outputs.
- Develop executive-level reports, presentations, and board-ready materials.
- Facilitate workshops with senior business, technology, risk, legal, compliance, privacy, and security stakeholders.
- Manage engagement teams and mentor consultants and senior consultants.
- Support business development activities including proposals, RFP responses, solutioning, and client presentations
- Strong understanding of AI Governance, Responsible AI, AI Risk Management, and AI lifecycle governance.
- Experience developing AI Governance frameworks, policies, standards, procedures, and operating models.
- Strong understanding of AI use case inventory, AI risk classification, AI control frameworks, and AI oversight models.
- Understanding of AI Security concepts including but not limited to: Prompt Injection, Indirect Prompt Injection, Data Leakage, Retrieval Poisoning, Model Abuse, Hallucination Risk, AI Supply Chain Risk, Agentic AI Risks
- Experience performing security risk assessments, threat modeling, and control effectiveness reviews
- Strong understanding of regulatory compliance and governance programs
- Experience working within highly regulated sectors, particularly financial services and government.
- Ability to communicate effectively with executive stakeholders and board-level audiences.
- Strong consulting mindset with excellent presentation and stakeholder management skills.
- Excellent written, verbal, and presentation skills.
- A bachelor's or master’s degree in information technology, cyber security, computer science, data science etc.
- Excellent communication skills with a consulting mindset.
- 7-12 years of experience in cybersecurity, technology risk, IT risk, compliance, governance, resilience, or consulting services. Along with this 3-4 years of experience in AI Governance, AI Risk Management, AI Theat Modelling, etc.
- Experience leading client-facing engagements and managing teams.
- Excellent communication, workshop facilitation, and report-writing skills.
- Experience interacting with senior leadership and executive stakeholders.
- ISO/IEC 42001 Lead Implementer or Lead Auditor
- Industry-recognized certifications such as CISSP, CRISC, CISM ISO 27001 LA/LI
- Experience working with AI Tools
- Familiarity with cloud security, privacy, operational resilience, or third-party risk management programs
- Experience supporting clients in highly regulated sectors such as financial services or government
- Knowledge of regional frameworks and regulations within the Middle East
We offer a competitive compensation package where you’ll be rewarded based on performance and recognized for the value you bring to our business. Plus, we offer:
- Continuous learning: You’ll develop the mindset and skills to navigate whatever comes next.
- Success as defined by you: We’ll provide the tools and flexibility, so you can make a meaningful impact, your way.
- Transformative leadership: We’ll give you the insights, coaching and confidence to be the leader the world needs.
- Diverse and inclusive culture: You’ll be embraced for who you are and empowered to use your voice to help others find theirs.
The Exceptional EY Experience. It’s Yours To Build.
EY | Shape The Future With Confidence
المصدر: LinkedIn - أُضيفت للموقع في 1 أغسطس 2026
وظائف أخرى لدى EY