Manager - Technology Consulting - Cybersecurity - AI Security - Riyadh
EY
- Location
- Riyadh, SA, 11391
- Work model
- On-Site
- Level
- Mid
Skills
About this role
As part of our Cyber Technology Consulting practice, you will lead the delivery of AI Governance, AI Risk Management, Responsible AI and AI Security engagements for leading financial institutions and government entities across the Middle East. This role will focus on helping clients establish enterprise-wide AI Governance frameworks, AI operating models, AI risk management methodologies, AI security assessment programs, and compliance with emerging AI regulations and standards. The successful candidate will work closely with executive stakeholders, risk teams, security teams, compliance functions, legal departments, and technology leaders to operationalize trustworthy and secure AI adoption. This role aligns closely with AI governance and security assessment programs involving AI inventory, AI risk assessments, threat modeling, governance framework development, AI control frameworks, and AI security blueprints. The opportunity We are looking for an experienced Manager with a strong consulting background and hands-on expertise in AI Governance, AI Risk Management, Responsible AI, AI Security, and Regulatory Compliance. This is an exceptional opportunity to work with executive leadership teams within major financial institutions and help shape the governance and security foundations of enterprise AI and Generative AI adoption. The role requires a blend of governance, security, privacy, risk management, regulatory compliance, and stakeholder management capabilities. Applicants should be comfortable leading client engagements, managing teams, conducting assessments, and developing strategic governance frameworks. Your key responsibilities AI Governance & Operating Model
Lead AI Governance assessments and maturity evaluations across enterprise AI and GenAI environments. Design and implement AI Governance Frameworks, Operating Models, Policies, Standards, Procedures, and Guidelines. Develop enterprise AI Governance strategies aligned with organizational objectives and regulatory requirements. Establish AI Governance Committees, RACI models, and decision-making structures. Create AI lifecycle governance processes covering ideation, development, validation, deployment, monitoring, and retirement.
AI Risk Management
Develop AI Risk Management Frameworks and methodologies. Establish AI risk taxonomies, risk assessment methodologies, and AI control frameworks. Conduct AI and GenAI risk assessments covering security, privacy, regulatory, operational, model, and third-party risks. Develop AI risk registers, heatmaps, risk scoring frameworks, and remediation roadmaps. Facilitate risk workshops and stakeholder interviews across business and technology teams
AI Security & Threat Modeling
Perform AI security assessments for Generative AI, LLM, RAG, Agentic AI, and Cognitive Search solutions. Conduct AI threat modeling exercises leveraging OWASP LLM Top 10, MITRE ATLAS, STRIDE, and other industry practices. Assess AI-specific threats including prompt injection, indirect prompt injection, data leakage, model abuse, hallucinations, retrieval poisoning, and excessive agency. Evaluate effectiveness of AI guardrails, content filtering, RBAC, DLP, monitoring, logging, and security controls. Develop AI Security Blueprints and AI Security Control Frameworks.
AI and Cyber Regulatory Compliance
NIST AI RMF ISO/IEC 42001 ISO 27001 NIST Cybersecurity Framework GDPR EU AI Act PDPL SAMA-related requirements Regional AI governance requirements
Client Delivery and Leadership
Lead multiple consulting engagements and ensure timely delivery of high-quality outputs. Develop executive-level reports, presentations, and board-ready materials. Facilitate workshops with senior business, technology, risk, legal, compliance, privacy, and security stakeholders. Manage engagement teams and mentor consultants and senior consultants. Support business