During your tenure as a Senior Consultant/ Manager, you will demonstrate and develop your capabilities in the following areas
Find and prioritise opportunities
· Work with domain leads to map manual, repetitive and high-volume tasks across strategy, technical assessments, risk, compliance, TPRM, governance and performance management
· Build a prioritised backlog of AI and automation use cases, with expected time savings, risk and effort for each
· Track AI advancements and good practice, and share them with the Innovation Guidance Team and the wider programme
Build AI and automation solutions
· Design, build and deploy solutions such as:
o Evidence and document analysis: reviewing policies, contracts, SOC 2 reports and compliance evidence against required controls
o TPRM automation: pre-filling and reviewing supplier questionnaires and flagging gaps
o Vulnerability analytics: enriching and prioritising findings using asset, threat and exploit data
o Reporting automation: generating draft assessment reports, dashboards and executive summaries
o AI assistants: helping the team search frameworks, policies and past work
o Anomaly detection: detection use cases with the SOC where relevant
· Build data pipelines and integrations with security tools, GRC and TPRM platforms, ticketing systems and Power BI
· Choose the right approach for each problem, whether rules, scripts, classical ML or large language models (LLMs), rather than defaulting to AI
Make AI secure and responsible
· Define standards for safe AI use in the programme: data handling, human review of AI outputs, prompt and model security, and logging
· Protect sensitive data: keep it within approved environments and meet PDPL, NCA and SDAIA requirements
· Test AI solutions against prompt injection, data leakage and incorrect outputs, following OWASP Top 10 for LLM Applications and NIST AI RMF
· Apply MLOps practices: version control, testing, monitoring, model performance tracking and documented governance of each solution
Enable the team
· Document solutions clearly and train specialists to use them well
· Measure adoption and time saved, and report results to programme leadership with the Performance Management team
Leadership Capabilities:
Builds own understanding of our purpose and values; explores opportunities for impact.
Demonstrates strong commitment to personal learning and development; acts as a brand ambassador to help attract top talent.
Understands expectations and demonstrates personal accountability for keeping performance on track.
Actively focuses on developing effective communication and relationship-building skills.
Understands how their daily work contributes to the priorities of the team and the business.
Qualifications:
· Total years of experience: 3-7 total professional years.
· Bachelor's or Master's in computer science, data science, AI or a related field
· Strong Python, with experience shipping ML or LLM-based solutions into real use, not only prototypes
· Experience with ML and LLM frameworks (e.g. PyTorch, scikit-learn, LangChain, LlamaIndex or similar) and building retrieval-augmented (RAG) solutions
· Experience with cloud AI platforms (Azure OpenAI / Azure AI, AWS Bedrock / SageMaker or GCP Vertex AI) and APIs
· Data engineering skills: SQL, pandas and building data pipelines
· Understanding of secure and responsible AI practices
· Cybersecurity, GRC or risk domain experience
· Experience integrating with ServiceNow, Archer, OneTrust or security tool APIs
· MLOps tooling (MLflow, Docker, CI/CD)
· Knowledge of Saudi AI and data regulations (SDAIA AI Ethics Principles, PDPL)
· Arabic language is a plus.
· At least one preferred: Microsoft Azure AI Engineer (AI-102), AWS Certified Machine Learning (Specialty or Engineer), Google Professional Machine Learning Engineer. Also valued: ISO/IEC 42001 Lead Implementer, IAPP AIGP.
Desired Candidate Profile
خلال فترة عملك كاستشاري أول / مدير، ستثبت وتطور قدراتك في المجالات التالية
تحديد الفرص وتحديد أولوياتها
· العمل مع قادة المجالات لتحديد المهام اليدوية والمكررة والمتكررة بكثرة عبر الاستراتيجية والتقييمات الفنية والمخاطر والامتثال وإدارة مخاطر الأطراف الخارجية (TPRM) والحوكمة وإدارة الأداء
· إنشاء قائمة مهام مؤجلة ومحددة الأولويات لحالات استخدام الذكاء الاصطناعي والأتمتة، مع تحديد الوقت المتوقع توفيره والمخاطر والجهد لكل منها
· متابعة تطورات الذكاء الاصطناعي والممارسات الجيدة، ومشاركتها مع فريق توجيه الابتكار والبرنامج الشامل
بناء حلول الذكاء الاصطناعي والأتمتة
· تصميم وبناء ونشر حلول مثل:
o تحليل الأدلة والمستندات: مراجعة السياسات والعقود وتقارير SOC 2 وأدلة الامتثال مقابل الضوابط المطلوبة
o أتمتة إدارة مخاطر الأطراف الخارجية (TPRM): التعبئة المسبقة لاستبيانات الموردين ومراجعتها وتحديد الفجوات
o تحليلات الثغرات الأمنية: إثراء النتائج وترتيب أولوية المعالجة باستخدام بيانات الأصول والتهديدات والاستغلال
o أتمتة التقارير: إنشاء مسودات تقارير التقييم واللوحات الإرشادية والملخصات التنفيذية
o مساعدو الذكاء الاصطناعي: مساعدة الفريق في البحث في أطر العمل والسياسات والأعمال السابقة
o اكتشاف الأنماط غير الطبيعية: حالات استخدام الاكتشاف مع مركز العمليات الأمنية (SOC) عند الاقتضاء
· بناء خطوط معالجة البيانات والتكامل مع الأدوات الأمنية ومنصات الحوكمة والمخاطر والامتثال (GRC) وإدارة مخاطر الأطراف الخارجية (TPRM) وأنظمة التذاكر و Power BI
· اختيار النهج المناسب لكل مشكلة، سواء كانت قواعد أو نصوص برمجية أو تعلم آلي تقليدي أو نماذج لغوية كبيرة (LLMs)، بدلاً من الاعتماد التلقائي على الذكاء الاصطناعي
جعل الذكاء الاصطناعي آمناً ومسؤولاً
· تحديد معايير الاستخدام الآمن للذكاء الاصطناعي في البرنامج: التعامل مع البيانات، والمراجعة البشرية لمخرجات الذكاء الاصطناعي، وأمان الأوامر والنماذج، وتسجيل الأنشطة
· حماية البيانات الحساسة: إبقاؤها ضمن البيئات المعتمدة وتلبية متطلبات نظام حماية البيانات الشخصية (PDPL) والهيئة الوطنية للأمن السيبراني (NCA) وسدايا (SDAIA)
· اختبار حلول الذكاء الاصطناعي ضد هجمات حقن الأوامر (prompt injection)، وتسريب البيانات، والمخرجات الخاطئة، باتباع قائمة OWASP Top 10 لتطبيقات LLM وإطار إدارة مخاطر الذكاء الاصطناعي من NIST (NIST AI RMF)
· تطبيق ممارسات MLOps: التحكم في الإصدارات، والاختبار، والمراقبة، وتتبع أداء النموذج، والحوكمة الموثقة لكل حل
تمكين الفريق
· توثيق الحلول بوضوح وتدريب المتخصصين على استخدامها بشكل جيد
· قياس معدل الاستخدام والوقت الموفر، ورفع التقارير بالنتائج إلى قيادة البرنامج بالتعاون مع فريق إدارة الأداء
قدرات القيادة:
يبني فهمه الخاص لهدفنا وقيمنا؛ ويستكشف الفرص لإحداث تأثير.
يظهر التزاماً قوياً بالتعلم والتطوير الشخصي؛ ويعمل كسفير للعلامة التجارية للمساعدة في جذب أفضل المواهب.
يفهم التوقعات ويظهر مسؤولية شخصية للحفاظ على مسار الأداء الصحيح.
يركز بفعالية على تطوير مهارات التواصل وبناء العلاقات الفعالة.
يفهم كيف يساهم عمله اليومي في أولويات الفريق والأعمال.
المؤهلات:
· إجمالي سنوات الخبرة: 3-7 سنوات من الخبرة المهنية الإجمالية.
· درجة البكالوريوس أو الماجستير في علوم الحاسوب، أو علوم البيانات، أو الذكاء الاصطناعي، أو مجال ذي صلة
· إتقان قوي للغة Python، مع خبرة في تقديم ونشر حلول قائمة على التعلم الآلي أو النماذج اللغوية الكبيرة (LLM) في الاستخدام الفعلي، وليس فقط النماذج الأولية
· خبرة في أطر عمل التعلم الآلي والنماذج اللغوية الكبيرة (مثل PyTorch و scikit-learn و LangChain و LlamaIndex أو ما يماثلها) وبناء حلول التوليد المعزز بالاسترجاع (RAG)
· خبرة في منصات الذكاء الاصطناعي السحابية (Azure OpenAI / Azure AI أو AWS Bedrock / SageMaker أو GCP Vertex AI) وواجهات برمجة التطبيقات (APIs)
· مهارات هندسة البيانات: SQL و pandas وبناء خطوط معالجة البيانات
· فهم ممارسات الذكاء الاصطناعي الآمن والمسؤول
· خبرة في مجالات الأمن السيبراني، أو الحوكمة والمخاطر والامتثال (GRC)، أو إدارة المخاطر
· خبرة في التكامل مع واجهات برمجة التطبيقات لـ ServiceNow أو Archer أو OneTrust أو الأدوات الأمنية
· أدوات MLOps مثل (MLflow، Docker، CI/CD)
· معرفة باللوائح السعودية للذكاء الاصطناعي والبيانات (مبادئ أخلاقيات الذكاء الاصطناعي الصادرة عن سدايا، نظام حماية البيانات الشخصية PDPL)
· تعتبر اللغة العربية ميزة إضافية.
· يفضل الحصول على واحدة على الأقل من الشهادات التالية: Microsoft Azure AI Engineer (AI-102)، AWS Certified Machine Learning (Specialty أو Engineer)، Google Professional Machine Learning Engineer. كما تُقدر أيضاً شهادات: ISO/IEC 42001 Lead Implementer، IAPP AIGP.
الملف الشخصي للمرشح المطلوب