Job Description
Roles & Responsibilities
At EY, we re all in to shape your future with confidence.
We ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go.
Join EY and help to build a better working world.
The opportunity
To support the significant growth of our Technology Risk service in MENA, EY is looking to hire highly qualified resources. Specifically, as part of this job posting, we are looking for a Senior Consultant. Working across many different industries, this role will be responsible for executing and leading IT and cybersecurity projects. It is all about listening to our clients, asking the better questions, and supporting them in areas where there are no off-the-shelf solutions.
Your key responsibilities
A large part of the role will be engagement delivery and EY will expect the candidates to lead and deliver engagements with very minimal supervision. EY also expects the candidates to support executives in development of proposals, presentations and other business development activities. The candidate will be responsible for the delivery and quality of the final reports to EY's clients.
An existing track record of successful engagement delivery in Technology Risk is expected of all candidates for this role. A Big 4 background or comparable consulting experience is highly advantageous. A broad background across IT and Cybersecurity is expected with specific experience in the following areas:
Expertise in Risk and Governance Frameworks, including IT governance frameworks (e.g., COBIT, ITIL, NIST), ISO 27001 standards, information security principles, policy development, and risk assessment.
Proficiency in IT Systems Audit, encompassing planning, execution, audit methodologies, complex IT environment evaluation, control weakness identification, and effective communication of findings.
Comprehensive knowledge of internal controls over financial reporting (ICFR), covering ITGCs, ITACs, SOX requirements, supporting financial audits with IT expertise, and strong liaison skills with financial auditors.
Good understanding around the application systems such as SAP, Oracle, Microsoft Dynamics and operating systems and databases.
Strong understanding of Business Continuity Planning (BCP), including BCP/DRP principles, business impact analyses, recovery strategy development, and plan testing.
Strong understanding of cybersecurity fundamentals, including common threats, vulnerabilities, basic principles, and contributions to cybersecurity discussions.
General Skills: Excellent analytical, problem-solving, communication, presentation, project management, organizational, leadership, client service, and business development skills.
Skills and attributes for success
What we offer you
At EY, we ll develop you with future-focused skills and equip you with world-class experiences. We ll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more .
Are you ready to shape your future with confidence? Apply today.
To help create an equitable and inclusive experience during the recruitment process, please inform us as soon as possible about any disability-related adjustments or accommodations you may need.
EY | Building a better working world
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
Desired Candidate Profile
Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or in a related field.
Relevant professional certifications (e.g., CISA, CISSP, CISM, ISO 27001 Lead Auditor) are preferred.
Minimum of 3 to 5 years of experience in IT audit, information security, or related fields.
Strong knowledge of ITGC/ITAC, information security frameworks, and cybersecurity best practices.
Excellent analytical, problem-solving, and communication skills.
Ability to work independently and collaboratively within a team environment.
وصف الوظيفة
الأدوار والمسؤوليات
في EY، نحن ملتزمون بشدة بتشكيل مستقبلك بثقة.
سوف نساعدك على النجاح في قوة عالمية مترابطة من فرق متنوعة ونتيح لك اختيار مسارك المهني أينما تريد أن يأخذك.
انضم إلى EY وساعد في بناء عالم عمل أفضل.
الفرصة
لدعم النمو الكبير في خدمة مخاطر التقنية لدينا في منطقة الشرق الأوسط وشمال أفريقيا، تبحث EY عن توظيف موارد عالية الكفاءة. وبشكل خاص، كجزء من هذا الإعلان الوظيفي، نحن نبحث عن مستشار أول. العمل عبر العديد من الصناعات، سيكون هذا الدور مسؤولاً عن تنفيذ وقيادة مشاريع تكنولوجيا المعلومات والأمن السيبراني. كل ذلك يتعلق بالإنصات إلى عملائنا، وطرح الأسئلة الأفضل، ودعمهم في المجالات التي لا توجد فيها حلول جاهزة.
مسؤولياتك الأساسية
جزء كبير من الدور سيكون في تنفيذ الت engagements وتتوقع EY من المرشحين قيادة وتقديم engagements بأقل قدر من الإشراف. كما تتوقع EY من المرشحين دعم التنفيذيين في تطوير المقترحات والعروض التقديمية وأنشطة تطوير الأعمال الأخرى. سيكون المرشح مسؤولاً عن تقديم وجودة التقارير النهائية لعملاء EY.
من المتوقع أن يمتلك جميع المرشحين سجلًا حافلًا في تقديم engagements ناجحة في مخاطر التكنولوجيا. وجود خلفية في Big 4 أو خبرة استشارية مماثلة ميزة كبيرة. يُتوقع وجود خلفية واسعة عبر تكنولوجيا المعلومات والأمن السيبراني مع خبرة محددة في المجالات التالية:
الخبرة في أطر الحوكمة والمخاطر، بما في ذلك أطر حوكمة تكنولوجيا المعلومات (مثل COBIT، ITIL، NIST)، معايير ISO 27001، مبادئ أمن المعلومات، تطوير السياسات، وتقييم المخاطر.
المهارة في تدقيق أنظمة تكنولوجيا المعلومات، بما في ذلك التخطيط، التنفيذ، منهجيات التدقيق، تقييم بيئة تكنولوجيا المعلومات المعقدة، تحديد نقاط الضعف في الرقابة، والتواصل الفعّال للنتائج.
معرفة شاملة بالضوابط الداخلية على التقارير المالية (ICFR)، بما في ذلك ITGCs، ITACs، متطلبات SOX، دعم التدقيقات المالية بخبرة في تكنولوجيا المعلومات، ومهارات تواصل قوية مع مدققي المالية.
فهم جيد لأنظمة تطبيق مثل SAP وOracle وMicrosoft Dynamics وأنظمة التشغيل وقواعد البيانات.
فهم قوي لتخطيط استمرارية الأعمال (BCP)، بما في ذلك مبادئ BCP/DRP، تحليل تأثير الأعمال، تطوير استراتيجيات الاسترداد، واختبار الخطة.
فهم قوي لأساسيات الأمن السيبراني، بما في ذلك التهديدات الشائعة، والثغرات، والمبادئ الأساسية، والمساهمة في مناقشات الأمن السيبراني.
المهارات العامة: مهارات تحليلية ممتازة، وحل المشكلات، والتواصل، وتقديم العروض، وإدارة المشاريع، والتنظيم، والقيادة، وخدمة العملاء، وتطوير الأعمال.
المهارات والصفات للنجاح
ماذا نقدم لك
في EY، سنُنمّيك بمهارات تركّز على المستقبل ونزوّدك بتجارب عالمية المستوى. سنمكّنك في بيئة مرنة، ونغذيك بمواهبك الاستثنائية في ثقافة شاملة ومتنوعة من فرق مرتبطة عالميًا. تعرف على المزيد .
هل أنت مستعد لتشكيل مستقبلك بثقة؟ قدِّم اليوم.
لمساعدة خلق تجربة عادلة وشاملة أثناء عملية التوظيف، يرجى إبلاغنا في أقرب وقت ممكن عن أي تعديلات أو تسهيلات تتعلق بالإعاقة قد تحتاجها.
EY | Building a better working world
تعمل EY على بناء عالم عمل أفضل من خلال خلق قيمة جديدة للعملاء والناس والمجتمع والكوكب، مع بناء الثقة في الأسواق المالية.
بدعم من البيانات والذكاء الاصطناعي والتقنيات المتقدمة، تساعد فرق EY العملاء على تشكيل المستقبل بثقة وتطوير الإجابات لأهم القضايا اليوم وغدًا.
تعمل فرق EY عبر مجموعة كاملة من الخدمات في assurance، consulting، tax، strategy and transactions. مدفوعة برؤى القطاع، وشبكة عالمية متصلة ومتعددة التخصصات وشركاء النظام البيئي المتنوع، يمكن لفرق EY تقديم الخدمات في أكثر من 150 دولة وإقليم.
الملف المطلوب للمرشح
درجة البكالوريوس في تكنولوجيا المعلومات، الأمن السيبراني، علوم الحاسب، أو في مجال ذي صلة.
شهادات مهنية ذات صلة (مثل CISA، CISSP، CISM، ISO 27001 Lead Auditor) مفضلة.
خبرة من 3 إلى 5 سنوات على الأقل في تدقيق تكنولوجيا المعلومات، أمن المعلومات، أو المجالات ذات الصلة.
معرفة قوية بـ ITGC/ITAC، أطر أمن المعلومات، وأفضل ممارسات الأمن السيبراني.
مهارات تحليلية، وحل المشكلات، والتواصل ممتازة.
القدرة على العمل بشكل مستقل وبالتعاون ضمن فريق.