A complete application in a minute — tailored resume and cover letter, ready to send.
Deloitte in Saudi Arabia is seeking a Consultant – Manager, Cyber Operate, Cybersecurity Risk Specialist to lead risk design and governance across enterprise IT and critical infra. You will define the risk framework, assess top cyber risks, oversee treatment plans and produce clear reports for management and risk committees.
4–8 years’ experience and a Bachelor’s in cybersecurity or related field are required; Arabic language is preferred.
About Deloitte : When you work for us, you commit to a career at one of the largest and most prestigious professional services firms in the world. We have received numerous awards over the last few years, including Best Employer in the Middle East, and Best Consulting Firm, and the Middle East Training & Development Excellence Award.
Our Purpose
Deloitte makes an impact that matters. Every day we challenge ourselves to do what matters most—for clients, for our people, and for society. We serve clients distinctively, bringing innovative insights, solving complex challenges and unlocking sustainable growth. We inspire our talented professionals to deliver outstanding value to clients, providing an exceptional career experience and an inclusive and collaborative culture. We contribute to society, building confidence and trust in the markets, upholding the integrity of organizations and supporting our communities.
Our shared values guide the way we behave to make a positive, enduring impact:
During your tenure as a Consultant – Manager, you will demonstrate and develop your capabilities in the following areas.
Leadership Capabilities:
Qualifications:
Years of experience: 4-8 total years
Bachelor's in cybersecurity, IT, risk management or a related field
Has designed or substantially improved a cyber or IT risk methodology (Senior), or run risk assessments end to end (Mid)
Strong understanding of cybersecurity threats and controls, enough to judge technical risk credibly
Working knowledge of ISO/IEC 27005, NIST SP 800-30, ISO 31000 and NCA ECC
Clear written English for management and committee reporting
Experience with a GRC platform (Archer, ServiceNow IRM, MetricStream or similar) is preferred.
Quantitative risk analysis experience (FAIR) is preferred.
Experience linking cyber risk to enterprise risk management in a large organisation is preferred.
Background in large-scale development, hospitality, financial services or critical infrastructure is preferred.
Arabic Language is preferred.