Senior Consultant | Risk, Regulatory & Forensic | Enterprise Risk | Egypt
About Deloitte: When you work for us, you commit to a career at one of the largest and most prestigious professional services firms in the world. We have received numerous awards over the last few years, including Best Employer in the Middle East, and Best Consulting Firm, and the Middle East Training & Development Excellence Award.
Our Purpose
Deloitte makes an impact that matters. Every day we challenge ourselves to do what matters most—for clients, for our people, and for society. We serve clients distinctively, bringing innovative insights, solving complex challenges and unlocking sustainable growth. We inspire our talented professionals to deliver outstanding value to clients, providing an exceptional career experience and an inclusive and collaborative culture. We contribute to society, building confidence and trust in the markets, upholding the integrity of organizations and supporting our communities.
Our shared values guide the way we behave to make a positive, enduring impact:
During your tenure as a Senior Consultant, you will demonstrate and develop your capabilities in the following areas
- Execute IT risk, cybersecurity, and internal controls engagements across a range of industries and client environments, independently managing key workstreams and contributing to high-quality, insight-driven client deliverables.
- Perform IT general controls reviews covering areas such as user access management, privileged access, password configuration, joiner-mover-leaver processes, change management, program development, batch jobs, incident management, backup and recovery, and IT operations.
- Assess application controls and perform application controls testing across key financial and operational systems, including input, processing, interface, master data, workflow, configurable, and reporting controls.
- Support IT internal audit and integrated internal audit engagements by performing risk assessments, walkthroughs, control documentation, testing, issue identification, and reporting.
- Evaluate the design and operating effectiveness of technology and process controls relevant to ICFR, internal control reviews, and compliance programs.
- Support cybersecurity-related assessments such as cyber risk reviews, security governance assessments, identity and access management reviews, controls maturity assessments, and control gap analyses.
- Contribute to enterprise risk management, broader risk assessment, and compliance engagements where technology risk intersects with business, financial, and operational control environments.
- Work closely with clients to assess risks, evaluate controls, perform testing, and support practical remediation and transformation initiatives.
- Develop process narratives, risk and control matrices, testing templates, workpapers, and issue logs in line with engagement requirements.
- Identify control deficiencies, root causes, and practical remediation actions, and communicate findings clearly to client stakeholders, including translating technical observations into business risk implications.
- Support Managers in preparing client presentations, audit reports, steering materials, and status updates.
- Guide Analysts or Consultants on specific testing areas, workpaper quality, and day-to-day execution, providing oversight and coaching where required.
- Apply a strong understanding of technology environments, control frameworks, and business processes to support effective risk assessment, control evaluation, and engagement delivery.
GRC Domain Experience Support the delivery of internal audit co-sourcing and outsourcing engagements across a range of client environments.
- Contribute to the design, assessment, and enhancement of enterprise risk management frameworks.
- Perform governance, risk, and compliance assessments across business, operational, and control environments.
- Assist with third-party risk management assessments and related control evaluations.
- Contribute to business continuity management and resilience-related reviews.
- Execute internal controls reviews and support controls improvement initiatives.
- Support ICFR readiness engagements, including documentation, controls testing, and remediation tracking.
- Assess risk and compliance operating models, including governance structures, roles, and responsibilities.
- Review and help redesign policies, processes, and controls to strengthen governance, compliance, and operational effectiveness.
- Prepare reporting materials and insights for management, board, and audit committee stakeholders.
- Perform IT general controls reviews across key areas of the technology control environment.
- Assess and test application controls across financial and operational systems.
- Conduct IT risk assessments to identify technology-related risks, control gaps, and improvement opportunities.
- Support cybersecurity governance and controls assessments, including maturity assessments and gap analyses.
- Deliver internal audit and integrated audit support through walkthroughs, testing, documentation, and issue identification.
- Execute compliance and regulatory controls assessments across technology and business processes.
- Review ERP and core business application controls to evaluate design and operating effectiveness.
Leadership Capabilities:
- Builds own understanding of our purpose and values; explores opportunities for impact.
- Demonstrates strong commitment to personal learning and development; acts as a brand ambassador to help attract top talent.
- Understands expectations and demonstrates personal accountability for keeping performance on track.
- Actively focuses on developing effective communication and relationship-building skills.
- Understands how their daily work contributes to the priorities of the team and the business.
Qualifications:
- Bachelor’s degree in Information Systems, Computer Science, Cybersecurity, Accounting, Finance, Engineering, or a related discipline; a Master’s degree such as an MBA or MSc in Risk or Information Security is an advantage.
- Relevant professional certification(s), such as CISA, CISSP, CRISC, ISO 27001, CIA, or CPA, or demonstrable progress toward obtaining them.
- 4–6 years of relevant professional experience in IT audit, IT risk, cybersecurity, internal controls, internal audit, risk advisory, or related consulting environments.
- Demonstrated capability in cybersecurity controls assessments, identity and access management reviews, vulnerability management governance reviews, and/or security operations controls reviews.
- Practical knowledge of IT general controls testing, application controls testing, process walkthroughs, control documentation, and issue identification and reporting.
- Sound understanding of risk and control principles across both technology and business process environments.
- Familiarity with recognized control frameworks and standards such as COBIT, ISO 27001, NIST, COSO, or similar frameworks.
- Working knowledge of ERP and enterprise application environments such as SAP, Oracle, Microsoft Dynamics, or other major business platforms.
- Exposure to ICFR, SOX-type controls programs, technology risk assessments, and compliance-related controls reviews.
- Awareness of analytics-enabled auditing, GRC platforms, workflow tools, and controls automation capabilities would be beneficial.
- Strong analytical, documentation, report-writing, and stakeholder communication skills.
- Ability to translate technical control issues into clear business risk implications and practical recommendations.
- Prior exposure to proposal support, business development, and practice-building activities would be advantageous.
- Experience gained within Big 4, top-tier consulting, or GRC technology delivery organizations is preferred.
- Proven involvement in delivering multiple GRC engagements within the telecommunications sector globally.
- Regional project exposure across the Middle East, North Africa, or South Asia is strongly preferred, with broader Middle East experience considered an advantage.
- Industry background in regulated sectors such as telecommunications, media, technology, sports, or large diversified groups would be valuable.
- Fluency in English is required; Arabic language capability would be a strong advantage.