Location
Amman, Cairo, Jeddah, Riyadh
About Deloitte: When you work for us, you commit to a career at one of the largest and most prestigious professional services firms in the world. We have received numerous awards over the last few years, including Best Employer in the Middle East, and Best Consulting Firm, and the Middle East Training & Development Excellence Award.
Our Purpose
Deloitte makes an impact that matters. Every day we challenge ourselves to do what matters most—for clients, for our people, and for society. We serve clients distinctively, bringing innovative insights, solving complex challenges and unlocking sustainable growth. We inspire our talented professionals to deliver outstanding value to clients, providing an exceptional career experience and an inclusive and collaborative culture. We contribute to society, building confidence and trust in the markets, upholding the integrity of organizations and supporting our communities.
Our shared values guide the way we behave to make a positive, enduring impact:
• Lead the way
• Serve with integrity
• Take care of each other
• Foster inclusion
• Collaborate for measurable impact
During your tenure as a Manager, you will demonstrate and develop your capabilities in the following areas
• Lead and manage full-lifecycle Archer implementation programmes: scoping, planning, resourcing, budgeting, risk/issue management, and executive reporting.
• Act as the primary client contact for engagement delivery, managing expectations of CROs, CISOs, Heads of Compliance, and programme sponsors.
• Define target-state GRC operating models, Archer solution architectures, and multi-year platform roadmaps covering ORM, BCM, TPRM, Operational Resilience, Policy, Audit, and Compliance use cases.
• Provide quality assurance and design authority over solution designs, configurations, and deliverables produced by the team.
• Lead teams of 3–10 consultants across multiple geographies; manage utilization, coaching, performance feedback, and career development.
• Drive business development: identify opportunities, lead proposals and orals, shape commercial models, and build relationships with Archer alliance teams.
• Advise clients on regulatory alignment of their GRC programmes (e.g., SAMA BCM requirements, CBUAE operational resilience expectations, central bank outsourcing rules).
• Contribute to practice development: accelerators, methodologies, thought leadership, and internal training.
GRC Domain Experience (BCM, TPRM & Operational Resilience)
• Substantial experience designing and implementing BCM programmes and technology: BIA methodology, continuity/DR planning, exercising regimes, and crisis management aligned to ISO 22301 and regional central bank BCM regulations.
• Proven delivery of TPRM transformations: third-party risk operating models, tiering and due-diligence methodologies, assessment automation, continuous monitoring, and fourth-party/concentration risk considerations.
• Strong grasp of Operational Resilience regimes: critical/important business services, impact tolerances, severe-but-plausible scenario testing, and resource mapping — and the ability to translate these into Archer solution designs.
• Ability to advise on convergence of BCM, TPRM, and resilience within an integrated risk management framework.
Leadership Capabilities:
• Builds own understanding of our purpose and values; explores opportunities for impact.
• Demonstrates strong commitment to personal learning and development; acts as a brand ambassador to help attract top talent.
• Understands expectations and demonstrates personal accountability for keeping performance on track.
• Actively focuses on developing effective communication and relationship-building skills.
• Understands how their daily work contributes to the priorities of the team and the business.
Qualifications:
• Bachelor's degree required; Master's degree (e.g., MBA, MSc in Risk/Information Security) is a plus.
• Professional certifications such as MBCI/CBCP, CTPRP/CTPRA, CRISC, CISA, PMP, or ISO 22301/27001 Lead Implementer are highly desirable.
• Significant experience in Big 4, top-tier consulting, or GRC technology delivery organizations preferred.
• 8–12 years of total experience, including 5+ years of Archer implementation experience and 2+ years managing GRC technology engagements or teams.
• Track record of delivering at least 3–5 full-lifecycle Archer implementations as a lead or manager.
• Strong command of Archer architecture, use-case design, Advanced Workflow, integrations, environment strategy, and licensing constructs.
• Archer certifications (Archer Certified Professional or equivalent) strongly preferred; familiarity with competing platforms (ServiceNow IRM, MetricStream, Diligent) is an advantage.
• Experience with programme governance methodologies (Agile, hybrid, waterfall) and tools such as Jira/Azure DevOps.
• Understanding of regional regulatory landscapes, including SAMA Cyber Security Framework and BCM requirements, NCA ECC (KSA), CBUAE regulations and NESA/SIA (UAE), Central Bank of Egypt directives, Central Bank of Jordan regulations, and State Bank of Pakistan / SECP guidelines.
• Familiarity with regional operational resilience and outsourcing/third-party regulations issued by GCC central banks and financial regulators.
• Experience delivering projects in the Middle East, North Africa, or South Asia is strongly preferred.
• Fluency in English is required; Arabic language skills are a strong advantage for UAE, KSA, Egypt, and Jordan-based roles.