Manager - Technology Consulting - Cybersecurity - AI Security - Riyadh
Job description
As part of our Cyber Technology Consulting practice, you will lead the delivery of AI Governance, AI Risk Management, Responsible AI and AI Security engagements for leading financial institutions and government entities across the Middle East. This role will focus on helping clients establish enterprise-wide AI Governance frameworks, AI operating models, AI risk management methodologies, AI security assessment programs, and compliance with emerging AI regulations and standards. The successful candidate will work closely with executive stakeholders, risk teams, security teams, compliance functions, legal departments, and technology leaders to operationalize trustworthy and secure AI adoption. This role aligns closely with AI governance and security assessment programs involving AI inventory, AI risk assessments, threat modeling, governance framework development, AI control frameworks, and AI security blueprints.
The opportunity
We are looking for an experienced Manager with a strong consulting background and hands-on expertise in AI Governance, AI Risk Management, Responsible AI, AI Security, and Regulatory Compliance. This is an exceptional opportunity to work with executive leadership teams within major financial institutions and help shape the governance and security foundations of enterprise AI and Generative AI adoption.
The role requires a blend of governance, security, privacy, risk management, regulatory compliance, and stakeholder management capabilities. Applicants should be comfortable leading client engagements, managing teams, conducting assessments, and developing strategic governance frameworks.
Your key responsibilities
AI Governance & Operating Model
- Lead AI Governance assessments and maturity evaluations across enterprise AI and GenAI environments.
- Design and implement AI Governance Frameworks, Operating Models, Policies, Standards, Procedures, and Guidelines.
- Develop enterprise AI Governance strategies aligned with organizational objectives and regulatory requirements.
- Establish AI Governance Committees, RACI models, and decision-making structures.
- Create AI lifecycle governance processes covering ideation, development, validation, deployment, monitoring, and retirement.
AI Risk Management
- Develop AI Risk Management Frameworks and methodologies.
- Establish AI risk taxonomies, risk assessment methodologies, and AI control frameworks.
- Conduct AI and GenAI risk assessments covering security, privacy, regulatory, operational, model, and third-party risks.
- Develop AI risk registers, heatmaps, risk scoring frameworks, and remediation roadmaps.
- Facilitate risk workshops and stakeholder interviews across business and technology teams
AI Security & Threat Modeling
- Perform AI security assessments for Generative AI, LLM, RAG, Agentic AI, and Cognitive Search solutions.
- Conduct AI threat modeling exercises leveraging OWASP LLM Top 10, MITRE ATLAS, STRIDE, and other industry practices.
- Assess AI-specific threats including prompt injection, indirect prompt injection, data leakage, model abuse, hallucinations, retrieval poisoning, and excessive agency.
- Evaluate effectiveness of AI guardrails, content filtering, RBAC, DLP, monitoring, logging, and security controls.
- Develop AI Security Blueprints and AI Security Control Frameworks.
AI and Cyber Regulatory Compliance
- NIST AI RMF
- ISO/IEC 42001
- ISO 27001
- NIST Cybersecurity Framework
- GDPR
- EU AI Act
- PDPL
- SAMA-related requirements
- Regional AI governance requirements
Client Delivery and Leadership
- Lead multiple consulting engagements and ensure timely delivery of high-quality outputs.
- Develop executive-level reports, presentations, and board-ready materials.
- Facilitate workshops with senior business, technology, risk, legal, compliance, privacy, and security stakeholders.
- Manage engagement teams and mentor consultants and senior consultants.
- Support business development activities including proposals, RFP responses, solutioning, and client presentations
Skills and attributes for success
- Strong understanding of AI Governance, Responsible AI, AI Risk Management, and AI lifecycle governance.
- Experience developing AI Governance frameworks, policies, standards, procedures, and operating models.
- Strong understanding of AI use case inventory, AI risk classification, AI control frameworks, and AI oversight models.
- Understanding of AI Security concepts including but not limited to: Prompt Injection, Indirect Prompt Injection, Data Leakage, Retrieval Poisoning, Model Abuse, Hallucination Risk, AI Supply Chain Risk, Agentic AI Risks
- Experience performing security risk assessments, threat modeling, and control effectiveness reviews
- Strong understanding of regulatory compliance and governance programs
- Experience working within highly regulated sectors, particularly financial services and government.
- Ability to communicate effectively with executive stakeholders and board-level audiences.
- Strong consulting mindset with excellent presentation and stakeholder management skills.
- Excellent written, verbal, and presentation skills.
To qualify for the role, you must have
- A bachelor's or master’s degree in information technology, cyber security, computer science, data science etc.
- Excellent communication skills with a consulting mindset.
- 7-12 years of experience in cybersecurity, technology risk, IT risk, compliance, governance, resilience, or consulting services. Along with this 3-4 years of experience in AI Governance, AI Risk Management, AI Theat Modelling, etc.
- Experience leading client-facing engagements and managing teams.
- Excellent communication, workshop facilitation, and report-writing skills.
- Experience interacting with senior leadership and executive stakeholders.
Ideally, you’ll also have
- ISO/IEC 42001 Lead Implementer or Lead Auditor
- Industry-recognized certifications such as CISSP, CRISC, CISM ISO 27001 LA/LI
- Experience working with AI Tools
- Familiarity with cloud security, privacy, operational resilience, or third-party risk management programs
- Experience supporting clients in highly regulated sectors such as financial services or government
- Knowledge of regional frameworks and regulations within the Middle East
What we offer
We offer a competitive compensation package where you’ll be rewarded based on performance and recognized for the value you bring to our business. Plus, we offer:
- Continuous learning: You’ll develop the mindset and skills to navigate whatever comes next.
- Success as defined by you: We’ll provide the tools and flexibility, so you can make a meaningful impact, your way.
- Transformative leadership: We’ll give you the insights, coaching and confidence to be the leader the world needs.
- Diverse and inclusive culture: You’ll be embraced for who you are and empowered to use your voice to help others find theirs.
If you can demonstrate that you meet the criteria above, please contact us as soon as possible.
The exceptional EY experience. It’s yours to build.
EY | Shape The Future With Confidence