Manager Information Security

6 days ago


Karachi, Sindh, Pakistan HRSI Full time

About the job Manager Information Security

COMPANY OVERVIEW:

Our client, a Karachi-based, State Bank of Pakistan (SBP) regulated Electronic Money Institution (EMI), seeks to appoint an experienced professional for the following role:

As Manager Information Security, you will be responsible for establishing and enforcing security protocols that safeguard Cerismas information systems, digital assets, and customer data.

Key Areas of Responsibilities

  • Develop & Implement Information Security Strategy Design and execute a comprehensive information security roadmap aligned with Cerismas digital infrastructure, business model, and regulatory obligations
  • Cybersecurity Risk Management Identify, assess, and mitigate cybersecurity risks across infrastructure, applications, APIs, mobile platforms, and third-party integrations
  • Regulatory Compliance & SBP Alignment Ensure full compliance with SBP guidelines and international security frameworks (e.g., ISO 27001, NIST), and act as the point of contact for regulator-driven security reviews
  • Security Architecture & Operations Oversee the design, configuration, and monitoring of security systems including firewalls, endpoint protection, SIEM, encryption, and identity/access management tools
  • Incident Response & Threat Management Develop and lead the incident response process, including detection, containment, investigation, recovery, and post-mortem reporting
  • Security Audits & Penetration Testing Coordinate regular internal and third-party audits, vulnerability assessments, and penetration testing to ensure system hardening
  • Employee Awareness & Policy Enforcement Establish security awareness programs, train internal staff, and enforce information security policies across all departments
  • Collaboration with Internal Audit & IT Work closely with Internal Audit, Technology, and Compliance teams to ensure consistent enforcement of risk controls and secure infrastructure design

Education

  • Minimum 16 years of education, preferably, Masters from a renowned and HEC recognized university or institution/equivalent foreign degree holder institution, in any/or combination of the disciplines
  • Professional certifications such as CISSP, CISM, CEH, or ISO 27001 Lead Implementer/Auditor are highly desirable

Experience

  • Information Security Expertise Minimum 5 years of relevant experience in information security or cybersecurity roles, preferably within fintech, digital banking, or regulated financial institutions
  • Regulatory & Standards Knowledge Strong understanding of SBP cybersecurity guidelines, ISO 27001, NIST, and relevant global information security frameworks
  • Incident Management & Threat Response Demonstrated experience in handling security incidents, vulnerability assessments, and threat intelligence operations
  • Security Operations & Architecture Hands-on experience with firewalls, IDS/IPS, antivirus, endpoint protection, IAM, encryption, and secure network architecture

Key Requirements

  • Technical Cybersecurity Proficiency Deep technical knowledge of cybersecurity tools, infrastructure protection, and digital risk management in consumer-facing platforms
  • Regulatory & Audit Readiness Proven track record of preparing for and managing regulator-led audits, and aligning cybersecurity operations with legal and compliance standards
  • Risk & Policy Management Ability to define, implement, and enforce cybersecurity policies, standards, and control frameworks organization-wide
  • Cross-Functional Collaboration Strong interpersonal skills to work closely with technology, audit, risk, and compliance teams to embed a culture of security
  • Adaptability in Fast-Paced Environments Demonstrated ability to manage evolving security risks in dynamic, high-growth fintech ecosystems

Age

The candidate should preferably be not more than 35 years of age as of last date of submission of application.

If you have the required experience and educational qualification to take up the challenging role, you are requested to apply by July 03, 2025 at http://jobs.hrs-int.com/

Only shortlisted candidates will be contacted.
www.hrs-int.com

#J-18808-Ljbffr

  • Karachi, Sindh, Pakistan Sjggroup Full time

    Manager Infrastructure and Information SecurityManager Infrastructure and Information SecurityPosition titleManager Infrastructure and Information SecurityDescriptionWe are seeking an experienced and highly motivated Manager – Infrastructure and Information Security to lead the design, development, and execution of our IT infrastructure and cybersecurity...


  • Karachi, Sindh, Pakistan Aga Khan University Full time

    Get AI-powered advice on this job and more exclusive features.Direct message the job poster from Aga Khan University.Introduction to the Aga Khan University:Chartered in 1983, Aga Khan University (AKU) is a private, autonomous and self-governing international university with 13 teaching sites in 6 countries distributed across three continents. As an integral...


  • Karachi, Sindh, Pakistan VRG (Pvt) Ltd. Full time

    Job Description:Dear All,We are looking to hire Asst. Manager - Information Security – Financial ServicesJob description:Working with all business units to determine possible risks and risk management process, acquiring the correct technology and analyzing IT security threats and their mitigation.Ensuring the newly acquired technology complies with the SBP...


  • Karachi, Sindh, Pakistan Abroad Work Full time

    Information Security Analyst vacancy in Karachi, PakistanJunior Information Security AnalystWe are seeking a highly motivated Junior Information Security Analyst to join our team in Karachi. As a Junior Information Security Analyst, you will work with senior analysts to protect our company's data and systems from cyber threats. This is an excellent...


  • Karachi, Sindh, Pakistan HORO Digital Full time

    About the Company: Financial InstitutionKey ResponsibilitiesProvide leadership, vision, and direction on information security to the information security staff. Prepare and launch for various platforms (e.g. Android, iOS, web etc.).Oversee and coordinate all aspects of alignment of the Bank's information security policies and procedures aligned with industry...


  • Karachi, Sindh, Pakistan Halan Microfinance Bank Full time

    Get AI-powered advice on this job and more exclusive features.Ready for your next career move as a CISO? Join the fastest growing Microfinance BankHalan Microfinance Bank - one of the fastest growing banks in Pakistan, is expanding it's outreach. We are looking for enthusiastic individuals to join us and be part of Halan Family in this successful growth...


  • Karachi, Sindh, Pakistan beBeeInformationSecurity Full time

    Job TitleWe are seeking a highly skilled and experienced Information Security Manager to join our team.The successful candidate will be responsible for ensuring the confidentiality, integrity and availability of our organization's information assets.This is an exciting opportunity for someone who is passionate about security and wants to make a real...


  • Karachi, Sindh, Pakistan Astera Software, Inc. Full time

    Job Summary:The Cloud & Information Security Analyst is primarily responsible for ensuring the security of our On-premises & Cloud-based infrastructure and Information Systems. The incumbent will play a critical role in identifying potential security risks, implementing measures to mitigate those risks, and maintaining compliance with industry regulations...


  • Karachi, Sindh, Pakistan beBeeInformationSecurity Full time

    Job Title:Strategic Information Security LeadAbout the Role:This exciting opportunity calls for a highly skilled and experienced Strategic Information Security Lead to spearhead our organization's information security management system (ISMS). As a key member of our team, you will be responsible for implementing and managing our ISMS in accordance with ISO...


  • Karachi, Sindh, Pakistan beBee Careers Full time

    Security Risk Assessment SpecialistWe are seeking a senior level security risk assessment specialist to conduct reviews for application development/enhancement projects.Conducting thorough assessments to ensure successful implementation of security deliverables in accordance with industry best practices.Scheduling review meetings with project managers and...