About Deloitte: When you work for us, you commit to a career at one of the largest and most prestigious professional services firms in the world. We have received numerous awards over the last few years, including Best Employer in the Middle East, and Best Consulting Firm, and the Middle East Training & Development Excellence Award.
Our Purpose
Deloitte makes an impact that matters. Every day we challenge ourselves to do what matters most—for clients, for our people, and for society. We serve clients distinctively, bringing innovative insights, solving complex challenges and unlocking sustainable growth. We inspire our talented professionals to deliver outstanding value to clients, providing an exceptional career experience and an inclusive and collaborative culture. We contribute to society, building confidence and trust in the markets, upholding the integrity of organizations and supporting our communities.
Our shared values guide the way we behave to make a positive, enduring impact:
During your tenure as a Senior Consultant/ Manager, you will demonstrate and develop your capabilities in the following areas
Find and prioritise opportunities
- Work with domain leads to map manual, repetitive and high-volume tasks across strategy, technical assessments, risk, compliance, TPRM, governance and performance management
- Build a prioritised backlog of AI and automation use cases, with expected time savings, risk and effort for each
- Track AI advancements and good practice, and share them with the Innovation Guidance Team and the wider programme
Build AI and automation solutions
- Design, build and deploy solutions such as:
- Evidence and document analysis: reviewing policies, contracts, SOC 2 reports and compliance evidence against required controls
- TPRM automation: pre-filling and reviewing supplier questionnaires and flagging gaps
- Vulnerability analytics: enriching and prioritising findings using asset, threat and exploit data
- Reporting automation: generating draft assessment reports, dashboards and executive summaries
- AI assistants: helping the team search frameworks, policies and past work
- Anomaly detection: detection use cases with the SOC where relevant
- Build data pipelines and integrations with security tools, GRC and TPRM platforms, ticketing systems and Power BI
- Choose the right approach for each problem, whether rules, scripts, classical ML or large language models (LLMs), rather than defaulting to AI
Make AI secure and responsible
- Define standards for safe AI use in the programme: data handling, human review of AI outputs, prompt and model security, and logging
- Protect sensitive data: keep it within approved environments and meet PDPL, NCA and SDAIA requirements
- Test AI solutions against prompt injection, data leakage and incorrect outputs, following OWASP Top 10 for LLM Applications and NIST AI RMF
- Apply MLOps practices: version control, testing, monitoring, model performance tracking and documented governance of each solution
Enable the team
- Document solutions clearly and train specialists to use them well
- Measure adoption and time saved, and report results to programme leadership with the Performance Management team
Leadership Capabilities
- Builds own understanding of our purpose and values; explores opportunities for impact.
- Demonstrates strong commitment to personal learning and development; acts as a brand ambassador to help attract top talent.
- Understands expectations and demonstrates personal accountability for keeping performance on track.
- Actively focuses on developing effective communication and relationship-building skills.
- Understands how their daily work contributes to the priorities of the team and the business.
Qualifications
- Total years of experience: 3-7 total professional years.
- Bachelor's or Master's in computer science, data science, AI or a related field
- Strong Python, with experience shipping ML or LLM-based solutions into real use, not only prototypes
- Experience with ML and LLM frameworks (e.g. PyTorch, scikit-learn, LangChain, LlamaIndex or similar) and building retrieval-augmented (RAG) solutions
- Experience with cloud AI platforms (Azure OpenAI / Azure AI, AWS Bedrock / SageMaker or GCP Vertex AI) and APIs
- Data engineering skills: SQL, pandas and building data pipelines
- Understanding of secure and responsible AI practices
- Cybersecurity, GRC or risk domain experience
- Experience integrating with ServiceNow, Archer, OneTrust or security tool APIs
- MLOps tooling (MLflow, Docker, CI/CD)
- Knowledge of Saudi AI and data regulations (SDAIA AI Ethics Principles, PDPL)
- Arabic language is a plus.
- At least one preferred: Microsoft Azure AI Engineer (AI-102), AWS Certified Machine Learning (Specialty or Engineer), Google Professional Machine Learning Engineer. Also valued: ISO/IEC 42001 Lead Implementer, IAPP AIGP.
- NIST AI RMF 1.0
- ISO/IEC 42001
- SDAIA AI Ethics Principles
- OWASP Top 10 for LLM Applications
- PDPL
- NCA ECC-2:2024
عن ديلويت: عندما تعمل معنا، فإنك تلتزم بمسيرة مهنية في واحدة من أكبر وأرقى شركات الخدمات المهنية في العالم. لقد حصلنا على العديد من الجوائز خلال السنوات القليلة الماضية، بما في ذلك جائزة أفضل عمل في الشرق الأوسط، وأفضل شركة استشارات، وجائزة التميز في التدريب والتطوير في الشرق الأوسط.
هدفنا
تصنع ديلويت أثراً ملموساً. كل يوم نتحدى أنفسنا للقيام بما هو أكثر أهمية - لعملائنا، ولأفرادنا، وللمجتمع. نحن نخدم العملاء بشكل متميز، ونقدم رؤى مبتكرة، ونحل التحديات المعقدة، ونحقق نمواً مستداماً. نحن نلهم مهنيينا الموهوبين لتقديم قيمة استثنائية للعملاء، وتوفير تجربة مهنية استثنائية وثقافة شاملة وتعاونية. نحن نساهم في المجتمع، ونبني الثقة والاطمئنان في الأسواق، ونحافظ على نزاهة المؤسسات، وندعم مجتمعاتنا.
توجهنا قيمنا المشتركة في كيفية تصرفنا لإحداث تأثير إيجابي ودائم:
خلال فترة عملك كاستشاري أول/مدير، ستثبت وتطور قدراتك في المجالات التالية:
تحديد الفرص وترتيب أولوياتها
- العمل مع قادة المجالات لتحديد المهام اليدوية والمتكررة وذات الحجم الكبير عبر الاستراتيجية والتقييمات الفنية والمخاطر والامتثال وإدارة مخاطر الأطراف الخارجية (TPRM) والحوكمة وإدارة الأداء
- بناء قائمة مهام مؤجلة مرتبة حسب الأولوية لحالات استخدام الذكاء الاصطناعي والأتمتة، مع تحديد الوقت المتوقع توفيره والمخاطر والجهد لكل منها
- متابعة تطورات الذكاء الاصطناعي والممارسات الجيدة، ومشاركتها مع فريق توجيه الابتكار والبرنامج بشكل أوسع
بناء حلول الذكاء الاصطناعي والأتمتة
- تصميم وبناء ونشر حلول مثل:
- تحليل الأدلة والوثائق: مراجعة السياسات والعقود وتقارير SOC 2 وأدلة الامتثال مقابل الضوابط المطلوبة
- أتمتة إدارة مخاطر الأطراف الخارجية (TPRM): تعبئة استبيانات الموردين ومراجعتها مسبقاً وتحديد الفجوات
- تحليلات الثغرات الأمنية: إثراء النتائج وترتيب أولوياتها باستخدام بيانات الأصول والتهديدات واستغلال الثغرات
- أتمتة التقارير: إنشاء مسودات تقارير التقييم ولوحات المعلومات والملخصات التنفيذية
- مساعدو الذكاء الاصطناعي: مساعدة الفريق في البحث في أطر العمل والسياسات والأعمال السابقة
- كشف الأنماط غير الطبيعية: حالات استخدام الكشف مع مركز العمليات الأمنية (SOC) عند الاقتضاء
- بناء خطوط نقل البيانات والتكامل مع الأدوات الأمنية، ومنصات الحوكمة والمخاطر والامتثال (GRC) وإدارة مخاطر الأطراف الخارجية (TPRM)، وأنظمة التذاكر و Power BI
- اختيار النهج المناسب لكل مشكلة، سواء كان القواعد أو البرامج النصية أو التعلم الآلي التقليدي أو النماذج اللغوية الكبيرة (LLMs)، بدلاً من الاعتماد الافتراضي على الذكاء الاصطناعي
جعل الذكاء الاصطناعي آمناً ومسؤولاً
- تحديد معايير الاستخدام الآمن للذكاء الاصطناعي في البرنامج: معالجة البيانات، المراجعة البشرية لمخرجات الذكاء الاصطناعي، أمان الموجهات والنماذج، والتدوين/التسجيل
- حماية البيانات الحساسة: إبقاؤها ضمن البيئات المعتمدة وتلبية متطلبات نظام حماية البيانات الشخصية (PDPL) والهيئة الوطنية للأمن السيبراني (NCA) والهيئة السعودية للذكاء الاصطناعي (SDAIA)
- اختبار حلول الذكاء الاصطناعي ضد حقن الموجهات، وتسريب البيانات، والمخرجات الخاطئة، باتباع معايير OWASP Top 10 لتطبيقات النماذج اللغوية الكبيرة وإطار إدارة مخاطر الذكاء الاصطناعي من NIST (NIST AI RMF)
- تطبيق ممارسات عمليات التعلم الآلي (MLOps): التحكم في الإصدارات، الاختبار، المراقبة، تتبع أداء النموذج، والحوكمة الموثقة لكل حل
تمكين الفريق
- توثيق الحلول بوضوح وتدريب المتخصصين على استخدامها بشكل جيد
- قياس مستوى الاعتماد والوقت الموفر، ورفع تقارير بالنتائج إلى قيادة البرنامج مع فريق إدارة الأداء
قدرات القيادة
- يبني فهمه الخاص لهدفنا وقيمنا؛ ويستكشف فرص إحداث الأثر.
- يظهر التزاماً قوياً بالتعلم والتطوير الشخصي؛ ويعمل كسفير للعلامة التجارية للمساعدة في جذب أفضل المواهب.
- يفهم التوقعات ويظهر مسؤولية شخصية للحفاظ على سير الأداء في المسار الصحيح.
- يركز بفاعلية على تطوير مهارات التواصل الفعال وبناء العلاقات.
- يفهم كيف يساهم عمله اليومي في أولويات الفريق والأعمال.
المؤهلات
- إجمالي سنوات الخبرة: 3-7 سنوات مهنية إجمالاً.
- درجة البكالوريوس أو الماجستير في علوم الحاسب، أو علوم البيانات، أو الذكاء الاصطناعي، أو مجال ذات صلة
- إتقان قوي للغة بايثون (Python)، مع خبرة في إطلاق حلول قائمة على التعلم الآلي أو النماذج اللغوية الكبيرة للاستخدام الفعلي، وليس فقط النماذج الأولية
- خبرة في أطر عمل التعلم الآلي والنماذج اللغوية الكبيرة (مثل PyTorch و scikit-learn و LangChain و LlamaIndex أو ما يماثلها) وبناء حلول التوليد المُعَزَّز بالاسترجاع (RAG)
- خبرة في منصات الذكاء الاصطناعي السحابية (Azure OpenAI / Azure AI أو AWS Bedrock / SageMaker أو GCP Vertex AI) وواجهات برمجة التطبيقات (APIs)
- مهارات هندسة البيانات: SQL و pandas وبناء خطوط نقل البيانات
- فهم ممارسات الذكاء الاصطناعي الآمن والمسؤول
- خبرة في مجالات الأمن السيبراني أو الحوكمة والمخاطر والامتثال (GRC) أو إدارة المخاطر
- خبرة في التكامل مع واجهات برمجة التطبيقات لـ ServiceNow أو Archer أو OneTrust أو أدوات الأمن
- أدوات MLOps (مثل MLflow و Docker و CI/CD)
- معرفة باللوائح السعودية للذكاء الاصطناعي والبيانات (مبادئ أخلاقيات الذكاء الاصطناعي الصادرة عن سدايا SDAIA، ونظام حماية البيانات الشخصية PDPL)
- إتقان اللغة العربية يُعد ميزة إضافية.
- يُفضل الحصول على شهادة واحدة على الأقل من: Microsoft Azure AI Engineer (AI-102)، أو AWS Certified Machine Learning (Specialty or Engineer)، أو Google Professional Machine Learning Engineer. كما تُثمن الشهادات التالية: ISO/IEC 42001 Lead Implementer، و IAPP AIGP.
- NIST AI RMF 1.0
- ISO/IEC 42001
- SDAIA AI Ethics Principles
- OWASP Top 10 for LLM Applications
- PDPL
- NCA ECC-2:2024