Specialist, Information Security

2 weeks ago


Karachi, Sindh, Pakistan Aga Khan University Full time

Get AI-powered advice on this job and more exclusive features.

Direct message the job poster from Aga Khan University.

Introduction to the Aga Khan University:

Chartered in 1983, Aga Khan University (AKU) is a private, autonomous and self-governing international university with 13 teaching sites in 6 countries distributed across three continents. As an integral part of the Aga Khan Development Network, AKU provides higher education in several disciplines, carries out research pertinent to the countries in which it exists and has campuses, programmes and/or teaching hospitals in Afghanistan, Kenya, Pakistan, Tanzania, Uganda and the UK. As an international institution, AKU operates on the core principles of quality, relevance, impact and access; and AKU is a model of academic excellence and an agent of social change.

As an equal opportunity employer, AKU believes in promoting a diverse and inclusive culture and is committed to adopt appropriate standards for safeguarding and promoting a respectful relationship with and between diverse workforce of its faculty, staff, trainees, volunteers, beneficiaries, wider communities, and other stakeholders with whom it works, including children and vulnerable adults and expects all employees/trainees and partners to share this commitment.

Job Role / Responsibilities:

Reporting to the Senior Manager, AKU Information Security. You will be responsible for:

  • Preparing, assessing and enforcing information security policies, standards, guidelines and procedures to ensure ongoing maintenance of security for all campuses.
  • Ensuring all IT and Information Security programs and policies are in compliance with applicable privacy and identity theft laws and other regulations such as ISO 27001, GDPR etc.
  • Assisting in the implementation of ISO-27001 security controls, and information security management system (ISMS) at AKU.
  • Monitoring security trends and driving security best practices throughout the organization.
  • Monitoring for security breaches and investigating violations when they occur; preparing reports that document security breaches and the extent of the damage caused by the breaches.
  • Evaluating and recommending counter measures against threats to information or privacy globally.
  • Identifying/recommending tools, processes, software, and hardware to improve or replace current security infrastructure practices, services, or technologies used globally to meet future requirements.
  • Coordinating with internal and external auditors, third party firms and consultants for audits, security risk assessments, vulnerability scans and penetration tests.
  • Managing and driving remediation efforts related to information security; remediation may be from incidents, penetration tests, vulnerability scans, internal/external audits for all campuses and critical practice assessments.
  • Understanding the business activities performed by AKU, and based on this understanding, suggesting appropriate information security solutions that adequately protect these activities AKU-wide.
  • Organizing, planning and conducting AKU-wide security awareness programs and campaigns, that are aligned with global security policy, standards, regulatory requirements, and industry practices.
  • Identifying information security weaknesses and/or gaps in the current operations and working with other teams to bring information security operations up to standards AKU-wide.
  • Working with other departments such as internal audit, legal and vendors to supervise AKU-wide information security requirements are incorporated into the rollout of new systems.
  • Providing support and guidance to internal users when they need to learn about new security products and procedures.
  • Working with the Technology team to manage threat protection strategies to include all layers of Information Security strategies such as firewalls, patching, anti-virus, log monitoring, data backup, disaster recovery, etc.

Eligibility Criteria / Requirements:

You should have:

  • A Master's degree in Computer Science, Information Technology, Information Security or related field.
  • 4-6 years of hands-on experience in IT and Information Security Management.
  • Possession of standard certifications including CISSP, CISM, CISA, strongly preferred.
  • Strong knowledge of Information Security and technology standards including but not limited to ISO 27001, NIST, COBIT, ITIL, HIPAA etc.
  • Experience or good understanding of implementing and maintaining ISO 27001 information security management system (ISMS).
  • The ability to perform information security risk assessments. IT security assessments and identify information security weaknesses and/or gaps in the current operations is a must.
  • The capability to evaluate and recommend new global information security technologies and counter measures against threats to information or privacy globally.
  • The ability to administer incident response planning and investigation processes of security breaches globally, and facilitate the management with disciplinary and legal matters associated with such breaches as necessary.
  • Knowledge of Business Continuity Planning, IT Disaster Recovery, auditing, and risk management, as well as contract and vendor negotiation.
  • The ability to manage and drive remediation efforts related to information security; remediation may be from incidents, penetration tests, vulnerability scans, internal/external audits for all campuses and critical practice assessments.
  • Experience of understanding the business activities performed by AKU, and based on this understanding, suggests appropriate information security solutions that adequately protect these activities AKU-wide.
  • The ability to work with other departments and vendors to supervise AKU-wide information security requirements are incorporated into the rollout of new systems.
  • Experience of working with a diverse group of individuals in a collaborative team environment.
  • Must be highly analytical and effectively able to troubleshoot and prioritize needs, requirements and other issues.
  • Aside from technical skills; excellent communications, teamwork, leadership and conflict management skills.

Comprehensive employment reference checks will be conducted.

Seniority level
  • Mid-Senior level
Employment type
  • Full-time
Job function
  • Information Technology
  • Industries: Higher Education and Hospitals and Health Care
#J-18808-Ljbffr

  • Karachi, Sindh, Pakistan beBee Careers Full time

    Senior Cyber Security Governance SpecialistCareer Opportunity in Senior Cyber Security Governance SpecialistWe are seeking an experienced Senior Cyber Security Governance Specialist to join our team. The ideal candidate will have hands-on experience implementing PCI DSS requirements and ISO 27001 standards, including leading or supporting end-to-end...

  • Sales Trainee

    4 weeks ago


    Karachi, Sindh, Pakistan Trillium Information Security Systems Full time

    Company DescriptionTrillium Information Security Systems (TISS) is a global cybersecurity solutions provider established in 2005. With a team of over 100 cybersecurity specialists holding over 400 certifications, TISS offers cutting-edge cybersecurity services to clients worldwide. TISS is committed to providing robust and effective cybersecurity solutions...


  • Karachi, Sindh, Pakistan beBee Careers Full time

    Key Responsibilities:Evaluate and assess the security posture of On-premises & cloud-based infrastructure, applications, and services.Assess and implement security tools & controls for Cloud platforms, such as AWS, Azure, or Google Cloud to enhance the organization's security posture.Configure and monitor On-premises & cloud security tools and services,...


  • Karachi, Sindh, Pakistan beBee Careers Full time

    Security Specialist RoleWe require a highly skilled Security Specialist to provide high-quality customer service solutions in the Consumer Services industry.The successful candidate will have strong problem-solving skills, excellent communication skills, and the ability to work independently and in a team environment.Develop, implement and maintain security...


  • Karachi, Sindh, Pakistan beBee Careers Full time

    Security Risk Assessment SpecialistWe are seeking a senior level security risk assessment specialist to conduct reviews for application development/enhancement projects.Conducting thorough assessments to ensure successful implementation of security deliverables in accordance with industry best practices.Scheduling review meetings with project managers and...


  • Karachi, Sindh, Pakistan beBee Careers Full time

    Information Security Governance, Risk & ComplianceThis role requires close collaboration with both business and technical teams across the global organisation to execute the Information Security strategy, extending and tailoring processes as needed to help identify, assess, and manage information security risks to an acceptable level.Support the influence...


  • Karachi, Sindh, Pakistan Trillium Information Security Systems Full time

    Head Of Sales @ Trillium Information Security SystemsCompany DescriptionTrillium Information Security Systems (TISS) is a leading global provider of cybersecurity solutions and services, established in 2005. With nearly two decades of experience, TISS has a proven track record of delivering cutting-edge cybersecurity solutions to clients worldwide. Our team...


  • Karachi, Sindh, Pakistan Abroad Work Full time

    Information Security Analyst vacancy in Karachi, PakistanJunior Information Security AnalystWe are seeking a highly motivated Junior Information Security Analyst to join our team in Karachi. As a Junior Information Security Analyst, you will work with senior analysts to protect our company's data and systems from cyber threats. This is an excellent...


  • Karachi, Sindh, Pakistan Trillium Information Security Systems Full time

    Head Of Sales at Trillium Information Security SystemsCompany OverviewWe are Trillium Information Security Systems (TISS), a leading global provider of cybersecurity solutions and services, established in 2005. With nearly two decades of experience, TISS has a proven track record of delivering cutting-edge cybersecurity solutions to clients worldwide.Our...


  • Karachi, Sindh, Pakistan beBee Careers Full time

    An IT Security Manager is responsible for safeguarding an organization's networks, systems, and sensitive data from cyber threats. This includes implementing best practices for new and existing IT security solutions, developing and implementing incident response plans, and collaborating with IT teams, management, and other stakeholders to integrate security...