img
Contract TypeFull-time
Workplace typeOn-site
LocationJeddah

Job Description

About the Role

As a Manager, ServiceNow Integrated Risk Management (IRM) at Deloitte Saudi Arabia, you will lead full-lifecycle IRM programs. This full-time role involves serving as a senior delivery contact for clients and managing teams across multiple countries. Based in Jeddah or Riyadh, you will define GRC target operating models, drive business development, and advise clients on aligning ServiceNow IRM implementations with regional regulations and international standards. The role also includes contributing to building practice assets and thought leadership.

Key Responsibilities

  • Lead full-lifecycle ServiceNow IRM programmes covering Risk, Policy & Compliance, Audit, BCM, TPRM, and Operational Resilience, from scoping and planning through deployment and value realization.
  • Serve as the senior delivery contact for clients, managing CRO/CISO/Head of Compliance stakeholders, steering committees, and escalations.
  • Define GRC target operating models, ServiceNow solution architectures, module rollout roadmaps, and integration strategies (ITSM, CMDB, SecOps, HR, vendor-intelligence feeds).
  • Provide design authority and quality assurance over solution designs, configurations, and all client-facing deliverables.
  • Manage and develop teams of 3–10 consultants across multiple countries, overseeing utilization, coaching, and performance management.
  • Drive business development activities, including pipeline generation, proposals, orals, commercial structuring, and collaboration with ServiceNow alliance and sales teams.
  • Advise clients on aligning ServiceNow IRM implementations with regional regulations (*, SAMA, NCA, CBUAE, CBE, CBJ, SBP) and international standards.
  • Build practice assets such as accelerators, pre-configured regulatory content, delivery methodologies, and thought leadership on resilience and third-party risk.

Specialized GRC Domain Experience

  • Substantial experience designing and delivering BCM programmes and technology, including BIA methodologies, continuity/DR planning, exercising regimes, and crisis management aligned to ISO 22301 and regional central bank BCM circulars.
  • Proven leadership of TPRM transformations, covering third-party risk operating models, tiering and due-diligence design, assessment and monitoring automation, concentration and fourth-party risk, and regulatory outsourcing compliance.
  • Deep understanding of Operational Resilience regimes, including identification of critical/important business services, setting impact tolerances, severe-but-plausible scenario testing, and end-to-end dependency mapping, with the ability to operationalize these in ServiceNow ORM.
  • Ability to advise clients on converging BCM, TPRM, and operational resilience into a single integrated risk framework on the ServiceNow platform.

Leadership Attributes

  • Builds understanding of Deloitte's purpose and values, exploring opportunities for impact.
  • Demonstrates strong commitment to personal learning and development, acting as a brand ambassador to attract top talent.
  • Understands expectations and demonstrates personal accountability for keeping performance on track.
  • Actively focuses on developing effective communication and relationship-building skills.
  • Understands how daily work contributes to the priorities of the team and the business.

Qualifications and Professional Experience

  • Education: Bachelor's degree required. A Master's degree (MBA or MSc in Risk, Information Security, or related field) is a plus.
  • Certifications: MBCI/CBCP, CTPRP/CTPRA, CRISC, CISA, PMP, or ISO 22301/27001 Lead Implementer certifications are highly desirable. ServiceNow CSA required; CIS-Risk & Compliance and CIS-TPRM strongly preferred; ITIL and Agile/Scrum credentials are a plus.
  • Professional Background: Prior experience in Big 4, top-tier consulting, or a ServiceNow partner delivery organization is strongly preferred.
  • Total Experience: 8–12 years of total experience, including 5+ years on the ServiceNow platform with 3+ years focused on GRC/IRM, and 2+ years managing engagements or teams.
  • Implementation Track Record: Proven track record of leading at least 3–5 full-lifecycle ServiceNow IRM implementations, including BCM and/or TPRM modules.
  • Platform Command: Strong command of ServiceNow platform architecture, licensing/SKU constructs, instance strategy, upgrade management, IntegrationHub, and Performance Analytics.
  • Tooling Market: Familiarity with adjacent platforms (Archer, MetricStream, Diligent) and the broader GRC tooling market is an advantage.
  • Regulatory Knowledge: Understanding of regional regulatory landscapes, including SAMA Cyber Security Framework and BCM requirements, NCA ECC (KSA), CBUAE regulations and NESA/SIA (UAE), Central Bank of Egypt directives, Central Bank of Jordan regulations, and State Bank of Pakistan / SECP guidelines. Familiarity with regional operational resilience and outsourcing/third-party regulations issued by GCC central banks and financial regulators.
  • Regional Project Experience: Experience delivering projects in the Middle East, North Africa, or South Asia is strongly preferred.

Work Location

This full-time position is based in either Jeddah or Riyadh, Saudi Arabia, offering the opportunity to work with diverse teams across multiple countries.


Requirements

  • Requires 5-10 Years experience

Similar Jobs