About Deloitte: When you work for us, you commit to a career at one of the largest and most prestigious professional services firms in the world. We have received numerous awards over the last few years, including Best Employer in the Middle East, and Best Consulting Firm, and the Middle East Training & Development Excellence Award.
Our PurposeDeloitte makes an impact that matters. Every day we challenge ourselves to do what matters most—for clients, for our people, and for society. We serve clients distinctively, bringing innovative insights, solving complex challenges and unlocking sustainable growth. We inspire our talented professionals to deliver outstanding value to clients, providing an exceptional career experience and an inclusive and collaborative culture. We contribute to society, building confidence and trust in the markets, upholding the integrity of organizations and supporting our communities.
Our shared values guide the way we behave to make a positive, enduring impact:
During your tenure as a Senior Consultant/Manager, you will demonstrate and develop your capabilities in the following areas
Build a cybersecurity culture
- Build a sense of cybersecurity ownership across the workforce and executives, so security is seen as everyone's responsibility, not only the IT team's
- Drive a cybersecurity-first mindset in day-to-day decisions, from how staff handle data and suppliers to how projects and services are designed
- Engage executives and senior leaders as visible role models: leadership messages, sponsorship of campaigns and participation in exercises
- Measure cybersecurity culture over time through surveys, behaviour data and reporting trends, and target the areas where culture is weakest
Design the awareness programme
- Design the cybersecurity awareness, training and culture framework and multi-year strategy: audiences, key behaviours, channels, annual plan and success measures, aligned with NCA ECC awareness and training requirements
- Write and maintain the awareness and training policy, procedures and SOPs, including mandatory training rules, onboarding requirements, phishing simulation rules and escalation for repeat clickers
- Run audience analysis to understand each group's risks, working patterns and preferred channels, including staff without regular computer access
Design tabletop exercises and campaigns
- Design and run cybersecurity tabletop exercises for executives, crisis management teams, IT, OT and business units, based on realistic scenarios such as ransomware, data breach, supplier compromise, payment fraud and disruption to venue or guest operations
- Facilitate the exercises, capture lessons learned, and track improvement actions with the Governance and Risk teams
- Design themed awareness campaigns on priority topics such as phishing, passwords and MFA, social engineering, data protection (PDPL), safe use of AI tools, mobile and travel security, and physical security
- Produce engaging content in Arabic and English: newsletters, posters, short videos, infographics, intranet pages and digital signage
- Organise events such as cybersecurity awareness month, roadshows, competitions and site visits to operational and venue teams
Deliver role-based training
- Design and deliver role-based training for all staff, executives and board members, IT and OT teams, developers, privileged users, finance and procurement, and contractors
- Build onboarding security training for new joiners, contractors and seasonal staff
- Manage training content and assignments in the learning management system (LMS), and track completion against targets
- Run live sessions, workshops and executive briefings
Communicate
- Issue clear security advisories and alerts to staff during active threats, in coordination with the SOC and Corporate Communications
- Communicate the cybersecurity programme's progress and achievements internally, so people see why security matters
Test and measure behaviour
- Plan and run phishing, smishing and vishing simulations (e.g. KnowBe4, Proofpoint), increasing difficulty over time, with follow-up training for those who fail
- Measure what changes, not just attendance: click and report rates, repeat offenders, incident reporting trends, exercise outcomes and culture survey results
- Report programme results and trends to the Governance and Performance Management teams, and adjust the plan based on the data
Work across the organisation
- Work with HR on onboarding, mandatory training and policy acknowledgement
- Work with Corporate Communications on brand, tone and channels
- Build a network of security champions across departments and sites to carry the culture into every team
Leadership Capabilities
- * Builds own understanding of our purpose and values; explores opportunities for impact.
- Demonstrates strong commitment to personal learning and development; acts as a brand ambassador to help attract top talent.
- Understands expectations and demonstrates personal accountability for keeping performance on track.
- Actively focuses on developing effective communication and relationship-building skills.
- Understands how their daily work contributes to the priorities of the team and the business.
Qualifications
- * Years of experience: 3-7 total professional years.
- Bachelor's in communications, cybersecurity, IT, education or a related field
- Has designed or run a security awareness or culture programme, including phishing simulations (Senior); has delivered awareness campaigns and training (Mid)
- Experience designing or facilitating cybersecurity tabletop exercises (Senior)
- Excellent writing and content creation skills in both Arabic and English
- Solid understanding of common cyber threats (phishing, social engineering, account takeover) and NCA ECC awareness requirements
- Confident presenter to audiences from front-line staff to executives
- Experience with phishing simulation and awareness platforms (KnowBe4, Proofpoint, Cofense or similar) and LMS administration
- Experience measuring security culture (culture surveys, behaviour metrics)
- Content design skills (Canva, Adobe, short video editing)
- Experience with large, mixed workforces such as hospitality, venues, operations or contractors
- Behavioural science or adult learning background
- Arabic Language is a plus.
- At least one preferred: SANS Security Awareness Professional (SSAP), CompTIA Security+, CISM. Also valued: SANS Security Culture (LDR433), CIPD or other learning and development or communications qualifications.
- NCA ECC-2:2024 (awareness and training)
- NIST SP 800-50 Rev 1
- NIST SP 800-84 (exercises)
- ISO/IEC 27001:2022 (A.6.3)
- PDPL (awareness of obligations)