The opportunity
We are looking for an experienced Manager with a strong consulting background and hands-on expertise in AI Governance, AI Risk Management, Responsible AI, AI Security, and Regulatory Compliance. This is an exceptional opportunity to work with executive leadership teams within major financial institutions and help shape the governance and security foundations of enterprise AI and Generative AI adoption.
The role requires a blend of governance, security, privacy, risk management, regulatory compliance, and stakeholder management capabilities. Applicants should be comfortable leading client engagements, managing teams, conducting assessments, and developing strategic governance frameworks.
Your key responsibilities
AI Governance & Operating Model
Lead AI Governance assessments and maturity evaluations across enterprise AI and GenAI environments.
Design and implement AI Governance Frameworks, Operating Models, Policies, Standards, Procedures, and Guidelines.
Develop enterprise AI Governance strategies aligned with organizational objectives and regulatory requirements.
Establish AI Governance Committees, RACI models, and decision-making structures.
Create AI lifecycle governance processes covering ideation, development, validation, deployment, monitoring, and retirement.
AI Risk Management
Develop AI Risk Management Frameworks and methodologies.
Establish AI risk taxonomies, risk assessment methodologies, and AI control frameworks.
Conduct AI and GenAI risk assessments covering security, privacy, regulatory, operational, model, and third-party risks.
Develop AI risk registers, heatmaps, risk scoring frameworks, and remediation roadmaps.
Facilitate risk workshops and stakeholder interviews across business and technology teams
AI Security & Threat Modeling
Perform AI security assessments for Generative AI, LLM, RAG, Agentic AI, and Cognitive Search solutions.
Conduct AI threat modeling exercises leveraging OWASP LLM Top 10, MITRE ATLAS, STRIDE, and other industry practices.
Assess AI-specific threats including prompt injection, indirect prompt injection, data leakage, model abuse, hallucinations, retrieval poisoning, and excessive agency.
Evaluate effectiveness of AI guardrails, content filtering, RBAC, DLP, monitoring, logging, and security controls.
Develop AI Security Blueprints and AI Security Control Frameworks.
AI and Cyber Regulatory Compliance
NIST AI RMF
ISO/IEC 42001
ISO 27001
NIST Cybersecurity Framework
GDPR
EU AI Act
PDPL
SAMA-related requirements
Regional AI governance requirements
Client Delivery and Leadership
Lead multiple consulting engagements and ensure timely delivery of high-quality outputs.
Develop executive-level reports, presentations, and board-ready materials.
Facilitate workshops with senior business, technology, risk, legal, compliance, privacy, and security stakeholders.
Manage engagement teams and mentor consultants and senior consultants.
Support business development activities including proposals, RFP responses, solutioning, and client presentations
Skills and attributes for success
Strong understanding of AI Governance, Responsible AI, AI Risk Management, and AI lifecycle governance.
Experience developing AI Governance frameworks, policies, standards, procedures, and operating models.
Strong understanding of AI use case inventory, AI risk classification, AI control frameworks, and AI oversight models.
Understanding of AI Security concepts including but not limited to: Prompt Injection, Indirect Prompt Injection, Data Leakage, Retrieval Poisoning, Model Abuse, Hallucination Risk, AI Supply Chain Risk, Agentic AI Risks
Experience performing security risk assessments, threat modeling, and control effectiveness reviews
Strong understanding of regulatory compliance and governance programs
Experience working within highly regulated sectors, particularly financial services and government.
Ability to communicate effectively with executive stakeholders and board-level audiences.
Strong consulting mindset with excellent presentation and stakeholder management skills.
Excellent written, verbal, and presentation skills.
To qualify for the role, you must have
A bachelor's or master s degree in information technology, cyber security, computer science, data science etc.
Excellent communication skills with a consulting mindset.
7-12 years of experience in cybersecurity, technology risk, IT risk, compliance, governance, resilience, or consulting services. Along with this 3-4 years of experience in AI Governance, AI Risk Management, AI Theat Modelling, etc.
Experience leading client-facing engagements and managing teams.
Excellent communication, workshop facilitation, and report-writing skills.
Experience interacting with senior leadership and executive stakeholders.
Ideally, you ll also have
ISO/IEC 42001 Lead Implementer or Lead Auditor
Industry-recognized certifications such as CISSP, CRISC, CISM ISO 27001 LA/LI
Experience working with AI Tools
Familiarity with cloud security, privacy, operational resilience, or third-party risk management programs
Experience supporting clients in highly regulated sectors such as financial services or government
Knowledge of regional frameworks and regulations within the Middle East
Desired Candidate Profile
A bachelor's or master s degree in information technology, cyber security, computer science, data science etc.
Excellent communication skills with a consulting mindset.
7-12 years of experience in cybersecurity, technology risk, IT risk, compliance, governance, resilience, or consulting services. Along with this 3-4 years of experience in AI Governance, AI Risk Management, AI Theat Modelling, etc.
Experience leading client-facing engagements and managing teams.
Excellent communication, workshop facilitation, and report-writing skills.
Experience interacting with senior leadership and executive stakeholders.
Ideally, you ll also have
ISO/IEC 42001 Lead Implementer or Lead Auditor
Industry-recognized certifications such as CISSP, CRISC, CISM ISO 27001 LA/LI
Experience working with AI Tools
Familiarity with cloud security, privacy, operational resilience, or third-party risk management programs
Experience supporting clients in highly regulated sectors such as financial services or government
Knowledge of regional frameworks and regulations within the Middle East
الفرصة
نحن نبحث عن مدير متمرس بخلفية استشارية قوية وخبرة عملية في حوكمة الذكاء الاصطناعي، إدارة مخاطر AI، الذكاء الاصطناعي المسؤول، أمان الذكاء الاصطناعي، والامتثال التنظيمي. هذه فرصة استثنائية للعمل مع فرق القيادة التنفيذية داخل مؤسسات مالية كبرى والمساعدة في تشكيل أسس الحوكمة والأمن لاعتماد الذكاء الاصطناعي المؤسسي و Generative AI.
يتطلب الدور مزيجاً من الحوكمة، الأمن، الخصوصية، إدارة المخاطر، الامتثال التنظيمي، وإدارة أصحاب المصلحة. يجب أن يكون المتقدمون مرتاحين لقيادة تعاملات العملاء، إدارة الفرق، إجراء التقييمات، وتطوير أطر حوكمة استراتيجية.
مسؤولياتك الرئيسية
حوكمة الذكاء الاصطناعي ونموذج التشغيل
قيادة تقييمات حوكمة الذكاء الاصطناعي وتقييمات النضج عبر بيئات AI المؤسسية وGenAI.
تصميم وتنفيذ أطر حوكمة الذكاء الاصطناعي، نماذج التشغيل، السياسات، المعايير، الإجراءات، والإرشادات.
تطوير استراتيجيات حوكمة الذكاء الاصطناعي المؤسسية بما يتماشى مع أهداف المؤسسة والمتطلبات التنظيمية.
إسناد لجان حوكمة الذكاء الاصطناعي، نماذج RACI، وهياكل اتخاذ القرار.
وضع عمليات حوكمة دورة حياة الذكاء الاصطناعي تغطي التوليد، التطوير، التحقق، النشر، الرصد، والإيقاف.
إدارة مخاطر AI
تطوير أطر ومنهجيات إدارة مخاطر الذكاء الاصطناعي.
إعداد تصنيف مخاطر AI، منهجيات تقييم المخاطر، وأطر التحكم في AI.
إجراء تقييمات مخاطر AI و GenAI تغطي الأمن، الخصوصية، التنظيم، التشغيلي، النموذجي، ومخاطر الأطراف الثالثة.
تطوير سجلات مخاطر AI، خرائط الحرارة، أطر تسجيل المخاطر، وخطط التخفيف.
تسهيل ورش عمل المخاطر ومقابلات أصحاب المصلحة عبر فرق الأعمال والتقنية
أمان AI ونمذجة التهديدات
إجراء تقييمات أمان AI لحلول Generative AI، LLM، RAG، AI الوكيل، والبحث المعرفي.
إجراء تمارين نمذجة التهديدات AI مستفيدة من OWASP LLM Top 10، MITRE ATLAS، STRIDE وغيرها من ممارسات الصناعة.
تقييم التهديدات الخاصة بـ AI بما في ذلك: حقن الأوامر، حقن الأوامر غير المباشرة، تسرب البيانات، إساءة استخدام النموذج، الهلوسة، تسميم الاسترجاع، وفرط الوكالة.
تقييم فعالية حدود AI، ترشيح المحتوى، RBAC، DLP، الرصد، سجلات الأحداث، وأطر الأمان.
وضع مخططات أمان AI وأطر تحكم أمان AI.
الامتثال التنظيمي لـ AI وCyber
NIST AI RMF
ISO/IEC 42001
ISO 27001
NIST إطار الأمن السيبراني
GDPR
EU AI Act
PDPL
متطلبات مرتبطة بـ SAMA
متطلبات حوكمة AI إقليمية
تسليم العملاء والقيادة
قيادة عدة تعاملات استشارية وضمان تسليم عالي الجودة في الوقت المحدد.
إعداد تقارير تنفيذية وعروض تقديمية ومواد جاهزة للحوكمة العليا.
تسهيل ورش العمل مع كبار أصحاب المصلحة في الأعمال، التقنية، المخاطر، القانونية، الامتثال، الخصوصية، والأمن.
إدارة فرق التعاملات وتوجيه المستشارين والاستشاريين الأولين.
دعم أنشطة تطوير الأعمال بما في ذلك المقترحات، ردود RFP، الحلول، وعروض العملاء
المهارات والسمات اللازمة للنجاح
فهم قوي لحوكمة AI، AI المسؤول، إدارة مخاطر AI، وحوكمة دورة حياة AI.
خبرة في تطوير أطر حوكمة AI، السياسات، المعايير، الإجراءات، ونماذج التشغيل.
فهم قوي لمخزون حالات استخدام AI، تصنيف مخاطر AI، أطر التحكم في AI، ونماذج إشراف AI.
فهم مفاهيم أمان AI بما في ذلك لكن لا تقتصر على: حقن الأوامر، حقن الأوامر غير المباشرة، تسرب البيانات، تسميم الاسترجاع، إساءة استخدام النموذج، مخاطر الهلوسة، مخاطر سلسلة توريد AI، مخاطر AI الوكيل
خبرة في إجراء تقييمات مخاطر الأمان، نمذجة التهديدات، ومراجعات فاعلية الضوابط
فهم قوي للامتثال التنظيمي وبرامج الحوكمة
خبرة في العمل ضمن قطاعات عالية التنظيم، خصوصاً الخدمات المالية والحكومة.
القدرة على التواصل بشكل فعال مع أصحاب المصلحة التنفيذيين وجمهور المجلس
فكر استشاري قوي مع مهارات عرض ممتازة وإدارة أصحاب المصلحة.
مهارات كتابة، تحدث، وتقديم ممتازة.
للتأهل للدور، يجب أن تمتلك
درجة بكالوريوس أو ماجستير في تكنولوجيا المعلومات، الأمن السيبراني، علوم الكمبيوتر، علم البيانات، إلخ.
مهارات اتصال ممتازة مع عقلية استشارية.
7-12 عاماً من الخبرة في الأمن السيبراني، مخاطر التكنولوجيا، مخاطر IT، الامتثال، الحوكمة、 المرونة، أو خدمات الاستشارات. مع 3-4 سنوات خبرة في حوكمة AI، إدارة مخاطر AI، نمذجة تهديد AI، وغيرها.
خبرة في قيادة تعاملات مواجهة العملاء وإدارة الفرق.
مهارات تواصل، تسهيل ورش العمل، وكتابة التقارير ممتازة.
خبرة في التفاعل مع كبار القيادة وأصحاب المصلحة التنفيذيين.
من الأفضل أن تكون لديك أيضاً
ISO/IEC 42001 مُنفِّذ رائد أو مُدقق رئيسي
شهادات معترف بها صناعيًا مثل CISSP، CRISC، CISM ISO 27001 LA/LI
خبرة في العمل مع أدوات AI
الإلمام بسلامة السحابة، الخصوصية، المرونة التشغيلية، أو برامج إدارة مخاطر الأطراف الثالثة
خبرة في دعم العملاء في قطاعات Highly regulated مثل الخدمات المالية أو الحكومة
معرفة بالأطر واللوائح الإقليمية في الشرق الأوسط
المرشح المثالي
درجة بكالوريوس أو ماجستير في تكنولوجيا المعلومات، الأمن السيبراني، علوم الكمبيوتر، علم البيانات، إلخ.
مهارات اتصال ممتازة مع عقلية استشارية.
7-12 عاماً من الخبرة في الأمن السيبراني، مخاطر التكنولوجيا، مخاطر IT، الامتثال، الحوكمة、 المرونة، أو خدمات الاستشارات. مع 3-4 سنوات خبرة في AI Governance، AI Risk Management، AI Threat Modelling، إلخ.
خبرة في قيادة تعاملات مواجهة العملاء وإدارة الفرق.
مهارات تواصل، تسهيل ورش العمل، وكتابة التقارير ممتازة.
خبرة في التفاعل مع كبار القيادة وأصحاب المصلحة التنفيذيين.
من الأفضل أن تكون لديك أيضاً
ISO/IEC 42001 Lead Implementer أو Lead Auditor
شهادات معترف بها صناعيًا مثل CISSP، CRISC، CISM ISO 27001 LA/LI
خبرة في العمل مع أدوات AI
الإلمام بسلامة السحابة، الخصوصية، المرونة التشغيلية، أو برامج إدارة مخاطر الأطراف الثالثة
خبرة في دعم العملاء في قطاعات Highly regulated مثل الخدمات المالية أو الحكومة
معرفة بالأطر واللوائح الإقليمية في الشرق الأوسط