Information Security Engineer

3 days ago


Lahore, Punjab, Pakistan Kualitatem Inc. Full time
Information Security Engineer - Compliance

KUALITATEM is a global Consulting, Audit, and Assurance company specializing in Software Quality Assurance, Information Security, Technology Process Optimization & Cloud Infrastructure. Kualitatem is an ISO 9001:2015 and ISO 27001:2013 certified company.

Required Experience - 4+ Years

Department - Information Security

Reporting - HOD

Job Description

  • Responsible for taking up external and internal projects at Kualitatem.
  • External projects will be the Client projects around compliance and assurance of desired information security standards.
  • Similarly, internal projects may include compliance and assurance on adapted information security standards of the company.
  • Client projects will require travel within Pakistan and abroad for the successful completion of the tasks.
  • Collaborate on critical IT projects to ensure that security policy/risk issues are addressed throughout the project life cycle.
  • Conduct thorough Risk Assessment and Threat Modelling exercises for various clients.
  • Identify major risk factors for IS/IT Governance and develop and coordinate the implementation of strategies to reduce/remediate process, operational, regulatory, and compliance risks.
  • Provide hands-on support and oversight to Company's and its Client's various IT/IS audit projects, including audits of its internal controls.
  • Enable clients against various standards by doing Internal Audits and Gap Assessments and further building controls for compliance.
  • Review, revise, and, where appropriate, propose new policies and procedures to ensure compliance with applicable laws and regulations or standards.
  • Deliver security services such as GRC Audit and Implementation to Clients, which includes technical security assessments of applications and infrastructure, security design reviews as well as risk assessments.
  • Perform application and infrastructure Cyber Security Assessments, as well as physical security review and social engineering tests for our global clients.
  • Ensure that the appropriate IT controls are considered throughout new system implementation projects and review documentation for new IT processes that impact compliance, as required.
  • Work on improvements for provided security services, including the continuous enhancement of existing methodology material and supporting assets.

Required Skillset

  • Master's or Bachelor's degree in business / IT, with IT audit or compliance experience, or computer science, with business and IT audit or compliance experience desired.
  • Knowledge and understanding of ISO 27001, ISO 9001, GRC, NIST and SOC-2 information security standards.
  • Working knowledge of common IT security-related regulations and/or standards such as Sarbanes-Oxley and ISO highly desired.
  • Minimum five years' experience conducting security control assessments or audits.
  • Minimum two years' experience developing or managing a security awareness program.
  • At least one industry certification (e.g. CISA, CISM, CRISC, CISSP, ISAAP) highly desired.
  • Strong oral and written communication skills.
  • Ability to maintain security documentation and manuals.
  • Must have strong analytical and critical-thinking skills.
  • High-level of attention to detail and focus on the end goal.
  • Self-starter with ability to work independently, multi-task and adjust to shifting priorities.

Seniority level: Mid-Senior level

Employment type: Full-time

Job function: Information Technology

Industries: IT Services and IT Consulting

#J-18808-Ljbffr

  • Lahore, Punjab, Pakistan Catalyic Security Full time

    Senior Offensive Security Engineer: Catalyic Security is seeking an experienced Senior Offensive Security Engineer to lead red team operations and deliver penetration testing projects. This role requires expertise in mobile penetration testing, network and web skills, and familiarity with cloud environments.Key Skills:Mobile penetration testingNetwork and...


  • Lahore, Punjab, Pakistan Catalyic Security Full time

    About the PositionThe Senior OT Penetration Tester will be responsible for leading our red team operations and conducting comprehensive penetration tests on IoT devices, industrial protocols, and web-based HMI interfaces. The successful candidate will also manage a team of 2-3 penetration testers, providing technical guidance, career development, and quality...


  • Lahore, Punjab, Pakistan UOH Full time

    About the Role:The University of Buner is seeking an experienced Information Security Officer to join our IT department and play a key role in ensuring the security and integrity of our systems and data.The successful candidate will be responsible for designing and implementing effective security strategies, conducting risk assessments, and developing...


  • Lahore, Punjab, Pakistan Catalyic Security Full time

    Key Responsibilities:Architect and execute advanced red team simulations mimicking nation-state adversariesLead a team of 2–3 engineers in delivering penetration tests projectsReverse-engineer mobile applications (APK/iOS IPA) to identify cryptographic flaws, insecure data storage, and insecure communicationAssess web applications and APIs for...


  • Lahore, Punjab, Pakistan FINCA Impact Finance Full time

    Job Title: Information Security StrategistAbout the Position:We are seeking an experienced Information Security Strategist to join our Global Cybersecurity team. The successful candidate will be responsible for developing and implementing FINCA's information security strategy.Key responsibilities include:Developing and implementing information security...


  • Lahore, Punjab, Pakistan Descon Full time

    We are seeking a skilled Information Security Specialist to join our team at Descon. The successful candidate will be responsible for developing, implementing, and maintaining an Information Security Management System (ISMS) aligned with ISO 27001 standards.Key Responsibilities:Develop and implement ISMS policies, procedures, and standards to ensure the...


  • Lahore, Punjab, Pakistan TUV Austria Full time

    We are seeking a highly skilled Information Security Auditor to join our team at TUV Austria. The ideal candidate will have a Bachelor's degree in IT or a relevant field and a minimum of 3-4 years of experience in data security and network security.A strong background in ISO 27001 is required, with a Lead Auditor Course certification being a plus.Experience...


  • Lahore, Punjab, Pakistan Dukan Full time

    Network Department, Lahore Apply By Jan 5, 2025We are looking for a skilled Information Security Analyst to protect our organization's information assets and maintain the integrity of our systems.In this role, you will monitor network security, assess risks, and identify potential threats while conducting thorough incident response.A strong understanding of...

  • Security Engineer

    2 weeks ago


    Lahore, Punjab, Pakistan UOH Full time

    Position: Security EngineerLocation: The University of Buner, Lahore, PakistanJob Posting Date: December 15, 2024Application Deadline: December 26, 2024Job Description:The University of Buner is seeking qualified candidates for the position of Security Engineer. This role is essential for ensuring the security protocols and systems within the university...


  • Lahore, Punjab, Pakistan The Children's Place Full time

    Information Security ExpertThe Information Security Expert will play a key role in ensuring the overall security posture of The Children's Place. This includes developing and implementing information security governance frameworks, managing risks, and ensuring compliance with regulatory requirements.Key Responsibilities:Security Governance: Develop and...


  • Lahore, Punjab, Pakistan ibex Full time

    Information Technology Security SpecialistObjectives:ISO 27001 and ITGC auditsDescription:As a member of the Information Security team, this position will maintain ISO 27001 certification and practice to ensure that the IBEX complies with industry and regulatory requirements like ISO 27001/2, SOC2 Type 2, and SOX audit. This position will liaise closely with...


  • Lahore, Punjab, Pakistan Dukan Full time

    Dukan is looking for a highly skilled Information Security Professional to join our team.In this role, you will be responsible for protecting our organization's digital assets and maintaining the integrity of our systems.This position involves:Monitoring network security to identify potential threats and breachesAssessing risks and developing strategies to...


  • Lahore, Punjab, Pakistan The Children's Place Full time

    Direct message the job poster from The Children's PlaceTechnical Recruiter | 360 Recruitment | HR Operations | Performance Management | Talent Acquisition SpecialistPosition SummaryThe Information Security Analyst will be responsible for providing key development, design, integration, and enhancement of information security governance and frameworks...


  • Lahore, Punjab, Pakistan Prime System Solutions Full time

    About the RoleWe are looking for an experienced Information Security Professional to join our team at Prime System Solutions. The successful candidate will be responsible for providing monitoring of deployed customer environments for security events.Responsibilities:Monitor and analyze system, security, and application logs to diagnose faults and identify...


  • Lahore, Punjab, Pakistan Kualitatem Inc. Full time

    Cybersecurity Expert Job DescriptionKualitatem Inc. is a renowned consulting, audit, and assurance company specializing in software quality assurance, information security, and technology process optimization.We are seeking an experienced cybersecurity expert to lead external and internal projects at Kualitatem, ensuring compliance with desired information...


  • Lahore, Punjab, Pakistan UNAVAILABLE Full time

    Job DetailsUNAVAILABLE is looking for a Senior IT Security Specialist to join our team.This position will be responsible for developing and implementing an effective cybersecurity strategy to protect our organization's data and infrastructure.ResponsibilitiesThe successful candidate will have a strong background in Network and Cyber Security functions and...


  • Lahore, Punjab, Pakistan NADRA Technologies Ltd Full time

    About UsNADRA Technologies Ltd is a leading provider of innovative technology solutions. We are committed to protecting our assets and ensuring the security and integrity of our systems and data.We are seeking a talented Governance and Risk Management Lead to join our GRC team. As a key member of our organization, you will play a critical role in ensuring...


  • Lahore, Punjab, Pakistan UNAVAILABLE Full time

    Duties and ResponsibilitiesKey Responsibilities:Develop and Implement Information Security Policies: The successful candidate will develop and implement information security policies and procedures that align with industry best practices.Lead SOC 2 Type II Project Implementation: This role will lead the implementation of SOC 2 Type II project, including...


  • Lahore, Punjab, Pakistan Devsinc Full time

    Devsinc is a dynamic organization looking for a passionate Cybersecurity Threat Analyst to join our team. The Cybersecurity Threat Analyst will serve as a key member of our cybersecurity team, responsible for monitoring, analyzing, and responding to security threats and incidents.Responsibilities:Monitor security event logs, network traffic, and system...


  • Lahore, Punjab, Pakistan ibex Full time

    Job Overview:As a member of the Information Security team at ibex, this position plays a crucial role in maintaining ISO 27001 certification and ensuring compliance with industry and regulatory requirements. This includes collaborating closely with internal business units, HR, and other relevant departments to identify and implement necessary controls.Key...