وظائف فى تلال الإمارات
٢ وظائف شاغرة
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<span>Provide secured remote operational support across identity and access management and vulnerability management.<br> The role performs approved technical activities and tracking; access approvals, security policy, risk acceptance and regulatory accountability.<br> • Support user, privileged and service-account administration through approved requests and access workflows.<br> • Assist with periodic access reviews, joiner/mover/leaver controls and evidence preparation.<br> • Operate approved vulnerability scanning and reporting tools and validate findings with system owners.<br> • Maintain vulnerability, exception and remediation trackers and coordinate technical follow-up.<br> • Support IAM, MFA, privileged-access and directory-service incidents within authorised access boundaries.<br> • Provide metrics, evidence and trend analysis for security reporting and governance reviews.<br> • Escalate overdue, critical or policy-related matters to the onsite Security Engineer.<br> • Maintain operational procedures, access-control records and vulnerability-management documentation.<br> • Minimum 5 years of relevant IAM and/or vulnerability-management experience, with credible practical exposure to both domains.<br> • Experience with Microsoft identity services, SailPoint, CyberArk or equivalent IAM/PAM platforms.<br> • Experience with enterprise vulnerability-scanning and remediation-tracking platforms.<br> • Microsoft Identity, SailPoint, CyberArk, CEH, OSCP, GPEN or equivalent certification preferred.<br> • Strong understanding of privileged access, least privilege, remediation governance and audit evidence.<br> Preferred Profile • Previous experience supporting UAE government or regulated cybersecurity environments.<br> • Working knowledge of TDRA-hosted environments and related security-access processes.<br> • Experience operating through secured remote-access and privileged-session controls.<br> Expected Contribution • Access and vulnerability activities are completed only through approved workflows.<br> • Critical findings and overdue actions are escalated with clear ownership.<br> • Evidence and trackers remain accurate, current and audit-ready.<br></span> </div>
<p>In the context of developing its Technology Risk activity, EY Tunisia is looking for Junior Auditors / Consultants specializing in Information Systems and innovative technologies. Technology Risk is also integrated within a larger department called Business Consulting, comprising approximately 220 people, thus allowing for more diverse opportunities and/or continuous evolution on complex mixed business and IS issues.</p><p><strong>The Opportunity</strong></p><p>Our Technology Risk team currently has more than 60 consultants and supports major companies in various sectors (Banks, insurance, industry, public sector, telecom, etc.) and different geographies (Tunisia/ Maghreb/ Africa/ Europe: France, Luxembourg, Germany, etc./ Middle East: Qatar, UAE, Saudi Arabia, Egypt, etc.) in transforming their IS to meet strategic, regulatory, and security challenges broadly.</p><p>By joining us, you will have the opportunity to develop various business and technical expertise by participating in various audit and consulting missions.</p><p>You will also benefit from training and close coaching throughout your professional career within the Firm.</p><p><strong>Your Missions</strong></p><p>You will be trained in our methodologies and will have the opportunity to work, according to your skills and aptitude, within multidisciplinary teams on various types of audit and consulting missions:</p><ul><li>Management and control of risks related to information systems and cybersecurity</li><li>Program/Project Risk Management</li><li>Information system audit across all SI layers: application, network (LDAP directories, Active Directory), infrastructure (servers, databases)</li><li>Review of IT system implementations, both on the application layer and the infrastructure layer (application server, database)</li><li>SOCR (Service Organizations Control Reporting) projects</li><li>Business Continuity Plan, Crisis Management</li><li>Cybersecurity readiness assessments</li><li>Support for the implementation of an information security management system</li><li>Regulatory audit and in accordance with standards and best practices (ISO27001/ ISO27002/ ISO22301/ NCA ECC/ SWIFT CSP/ NIST/ etc.)</li></ul><p><strong>Your Responsibilities:</strong></p><ul><li>You actively participate in the execution of missions with our clients in close collaboration with experienced consultants and managers.</li><li>You intervene at the core of companies and their business processes to provide advice aimed at helping them manage their operational or technological risks, particularly in the context of audit missions.</li><li>You support management in implementing their risk management frameworks (risk mapping, process modeling, other diagnostics...).</li><li>You base your work on qualitative and quantitative analyses from sometimes large and complex data.</li></ul><p><strong>Desired Candidate Profile</strong></p><p>Graduate of an engineering school, management school, or university, you have successful prior experience (internship, apprenticeship) in a company, audit firm, or consulting firm in the field of Information Systems.</p><p>Enthusiastic, dynamic, committed, you have a strong ability to adapt and enjoy working in a team.</p><p>Your rigor, interpersonal skills, and ease in oral and written communication will contribute to the excellence of our service to clients.</p><p>Advanced English</p><p>Good communication in French</p><p>International experience is a plus.</p><p>As part of its Diversity policy, EY considers all applications, including those from people with disabilities, on equal terms.</p>