وصف الوظيفة
الأدوار والمسؤوليات
الفرصة
لدعم النمو الكبير في خدمة مخاطر التكنولوجيا لدينا في منطقة الشرق الأوسط وشمال أفريقيا، تبحث EY عن توظيف موارد عالية التأهيل. على وجه الخصوص، كجزء من هذا الإعلان عن الوظيفة، نحن نبحث عن مستشار أول / مدير مساعد. يعمل عبر العديد من الصناعات المختلفة، ستكون هذه الدور مسؤولاً عن تنفيذ وقيادة مشاريع تكنولوجيا المعلومات والأمن السيبراني. الأمر كله يتعلق بالاستماع إلى عملائنا، وطرح الأسئلة الأفضل، ودعمهم في المجالات التي لا توجد فيها حلول جاهزة على الرف.
مسؤولياتك الأساسية
سيكون جزء كبير من الدور متعلقًا بتسليم الت engagements وستتوقع EY من المرشحين قيادة وتسليم engagements مع إشراف بسيط جدًا. كما تتوقع EY من المرشحين دعم التنفيذيين في تطوير المقترحات والعروض وأنشطة تطوير الأعمال الأخرى. سيكون المرشح مسؤولاً عن تسليم وجودة التقارير النهائية لعملاء EY.
من المتوقع أن يمتلك جميع المرشحين سجلًا حافلًا في تقديم engagements ناجحة في مجال مخاطر التكنولوجيا. الخلفية في Big 4 أو خبرة استشارية مكافئة تعتبر ميزة كبيرة. من المتوقع وجود خلفية واسعة عبر تكنولوجيا المعلومات والأمن السيبراني مع خبرة محددة في المجالات التالية:
- الخبرة في أطر العمل الخاصة بالمخاطر والحوكمة، بما في ذلك أطر حوكمة تكنولوجيا المعلومات (مثل COBIT، ITIL، NIST)، معايير ISO 27001، مبادئ أمن المعلومات، وضع السياسات، وتقييم المخاطر.
- الإتقان في تدقيق أنظمة تكنولوجيا المعلومات، بما في ذلك التخطيط والتنفيذ ومنهجيات التدقيق وتقييم بيئة تكنولوجيا معلومات معقدة، وتحديد نقاط الضعف في الضوابط، ونقل النتائج بفعالية.
- معرفة شاملة بالضوابط الداخلية المتعلقة بالتقارير المالية (ICFR)، بما في ذلك ITGCs وITACs ومتطلبات SOX، دعم التدقيقات المالية بخبرة في تكنولوجيا المعلومات، ومهارات الربط القوية مع مدققي المالية.
- فهم جيد لأنظمة التطبيقات مثل SAP وOracle وMicrosoft Dynamics وأنظمة التشغيل وقواعد البيانات.
- فهم قوي لتخطيط استمرارية الأعمال (BCP)، بما في ذلك مبادئ BCP/DRP، تحليلات تأثير الأعمال، تطوير استراتيجيات التعافي، واختبار الخطة.
- فهم قوي لأساسيات أمن المعلومات، بما في ذلك التهديدات الشائعة والثغرات والمبادئ الأساسية والمساهمة في مناقشات الأمن السيبراني.
- المهارات العامة: مهارات تحليلية ممتازة، وحل المشكلات، والتواصل، والعرض، وإدارة المشاريع، والتنظيم، والقيادة، وخدمة العملاء، وتطوير الأعمال.
المهارات والصفات اللازمة للنجاح
- درجة البكالوريوس في تكنولوجيا المعلومات أو الأمن السيبراني أو علوم الكمبيوتر أو في مجال ذي صلة.
- الشهادات المهنية ذات الصلة (مثل CISA، CISSP، CISM، ISO 27001 Lead Auditor) مطلوبة.
- خبرة من 3 إلى 5 سنوات في تدقيق تكنولوجيا المعلومات أو أمن المعلومات أو المجالات ذات الصلة.
- معرفة قوية بـ ITGC/ITAC، أطر أمن المعلومات، وأفضل ممارسات الأمن السيبراني.
- مهارات تحليلية قوية، وحل المشكلات، والتواصل.
- القدرة على العمل بشكل مستقل وتعاوني ضمن فريق.
Job Description
Roles & Responsibilities
The opportunity
To support the significant growth of our Technology Risk service in MENA, EY is looking to hire highly qualified resources. Specifically, as part of this job posting, we are looking for a Senior Consultant / Assistant Manager. Working across many different industries, this role will be responsible for executing and leading IT and cybersecurity projects. It is all about listening to our clients, asking the better questions, and supporting them in areas where there are no off-the-shelf solutions.
Your key responsibilities
A large part of the role will be engagement delivery and EY will expect the candidates to lead and deliver engagements with very minimal supervision. EY also expects the candidates to support executives in development of proposals, presentations and other business development activities. The candidate will be responsible for the delivery and quality of the final reports to EY's clients.
An existing track record of successful engagement delivery in Technology Risk is expected of all candidates for this role. A Big 4 background or comparable consulting experience is highly advantageous. A broad background across IT and Cybersecurity is expected with specific experience in the following areas:
- Expertise in Risk and Governance Frameworks, including IT governance frameworks (e.g., COBIT, ITIL, NIST), ISO 27001 standards, information security principles, policy development, and risk assessment.
- Proficiency in IT Systems Audit, encompassing planning, execution, audit methodologies, complex IT environment evaluation, control weakness identification, and effective communication of findings.
- Comprehensive knowledge of internal controls over financial reporting (ICFR), covering ITGCs, ITACs, SOX requirements, supporting financial audits with IT expertise, and strong liaison skills with financial auditors.
- Good understanding around the application systems such as SAP, Oracle, Microsoft Dynamics and operating systems and databases.
- Strong understanding of Business Continuity Planning (BCP), including BCP/DRP principles, business impact analyses, recovery strategy development, and plan testing.
- Strong understanding of cybersecurity fundamentals, including common threats, vulnerabilities, basic principles, and contributions to cybersecurity discussions.
- General Skills: Excellent analytical, problem-solving, communication, presentation, project management, organizational, leadership, client service, and business development skills.
Skills and attributes for success
- Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or in a related field.
- Relevant professional certifications (e.g., CISA, CISSP, CISM, ISO 27001 Lead Auditor) are preferred.
- Minimum of 3 to 5 years of experience in IT audit, information security, or related fields.
- Strong knowledge of ITGC/ITAC, information security frameworks, and cybersecurity best practices.
- Excellent analytical, problem-solving, and communication skills.
- Ability to work independently and collaboratively within a team environment.