Cybersecurity and Risk Management Specialist

7 days ago


Lahore, Punjab, Pakistan FINCA Impact Finance Full time

The Global Cybersecurity/SOC Manager is responsible for maintaining and continuously improving FINCA`s cybersecurity, monitoring and control framework.

">

This includes ensuring that effective security risk, threat, vulnerability and incident management practices are incorporated into IT and business practices within their FIF and subsidiaries.

">

The position requires developing and facilitating security logs and incident management, analytics and reporting capacities.

">

Working closely with global, regional and local Information Security and IT resources to design, test, implement effective security controls is another key responsibility of the position.

">

The following are key responsibilities:

">
  1. Communicate and collaborate with internal clients to contribute to security direction, and provide influence and technical guidance on current and future technical security directions
  2. Act as a cybersecurity subject matter expert throughout projects lifecycle, including functional requirements, design specifications, testing and quality assurance, implementation and support
  3. Provide input to the annual Information Security strategy cycle
  4. Ensure that security requirements are identified early on and are being incorporated into all projects/applications:
    1. Investigate, recommend, evaluate, deploy and integrate security tools and techniques to improve our ability to protect corporate assets and infrastructure
    2. Develop and maintain documentation of relevant IT systems and security controls
    3. Assess and capture security requirements within context of enterprise application architecture
    4. Ensure that application development and deployment meet FINCA security standards
    5. Provides security input to design and application architectural reviews
  5. Report on risks, risk mitigations, and residual business risks
  6. Develop comprehensive and accurate reports and presentations for both technical and executive audiences
  7. Develop recommendations for improvements
  8. Monitor appropriate sources for newly identified threats and vulnerabilities
  9. Effectively communicate findings and strategy to client stakeholders including technical staff, executive leadership, and legal counsel
  10. Recognize and safely utilize attacker tools, tactics, and procedures
  11. Develop methodologies to enhance red teaming processes
  12. Assist with scoping prospective engagements, leading engagements from kickoff through remediation, and mentoring less experienced staff
  13. Execute and/or lead (when required) red team assessments to highlight gaps impacting organization security posture
  14. Researching new/emerging security threats, vulnerabilities and exploit techniques
  15. Responding to new attack surfaces and help implement new requirements as needed
  16. Develop, manage, and maintain security testing industry frameworks and best practices: Cloud Security Alliance (CSA), NIST, SANS, CIS
  17. Partner with Global Information Security and Business Continuity team members across the network to drive secure outcomes based on industry best practices
  18. Play a key role in Global Cybersecurity Team on developing threat modeling and new detection techniques, based on trending attack surfaces
  19. Provide support to business digital projects through entire project lifecycle (threat modeling, requirements definition, verification and validation)
">

The ideal candidate will have:

">

Qualifications:

">
  • Bachelor's Degree in a technical discipline or equivalent work experience
  • Certifications are not required, but will be considered in the evaluation process. Applicable certifications include: SANS, Splunk, CISSP
  • Knowledge of security and control frameworks (such as ISO 27001, CobiT, NIST)
  • Security certifications (CISSP, GIAC, CEH, CISM, OSCP) will be an asset

Experience:

">
  • Minimum 4-6 years of experience in a Security Manager/Analyst Role;
  • Experience in a financial institution will be considered as a plus;
  • Experience working in a large international organization or network will be considered as a plus;
  • Experience with IT security assessments
  • Experience with common assessment tools (examples Qualys, Tenable, Rapid7)
  • Experience communicating assessment results to audiences with diverse technical proficiency
  • Experience constructively articulating business impact of vulnerabilities to various stakeholders
  • Experience with correlating and analyzing logs and events from various sources (e.g. Vulnerability Scanning, Virus Protection, SIEM)
  • Experience with producing and customizing security queries, reports and dashboards from various sources (e.g. Vulnerability Scanning, SIEM, Virus Protection)
  • Experience conducting application security reviews preferred
  • Experience with scripting languages desired

Skills:

">
  • Able to explain and deliver technical solutions in a practical way
  • Able to manage simultaneously multiple projects involving various stakeholders and to deliver results within deadlines
  • Work well in a team environment including cross-functional and cross-organizational teams maintaining composure in difficult situations with a professional attitude and ownership mindset
  • Excellent communication (oral and written) and interpersonal skills
  • Proven ability to delegate and to empower teams
  • Ability to be a strongly credible ambassador for the FIF brand, including making presentations, and able to establish respect and credibility with media outlets
  • Strong skills in analysis, problem-solving, and resolving disputes
  • Strong technical reporting skills
  • High degree of initiative and ability to work with little supervision
  • Knowledge of Windows, Linux, and Unix operating systems. Hands-on experience a plus
  • High level of personal integrity, and the ability to professionally handle confidential matters with appropriate judgment and maturity
  • Penetration testing skills are considered a plus
  • Eager to learn and expand cybersecurity knowledge

Language Skills:

">
  • Fluency in English
  • Fluency in other FINCA working languages, such as Spanish, French, or Russian is a plus
  • Availability to travel up to 50% of the time


  • Lahore, Punjab, Pakistan ibex Full time

    OverviewThe ibex team is seeking a highly skilled Cybersecurity Specialist to join our ranks. As an integral part of our organization, you will be responsible for ensuring the security and integrity of our systems and data.Duties and ResponsibilitiesRisk ManagementConduct thorough risk assessments to identify potential vulnerabilities and ensure alignment...


  • Lahore, Punjab, Pakistan Genius Inc Full time

    At Genius Inc, we're seeking a highly skilled Cybersecurity Specialist to join our dynamic team of cybersecurity professionals. This is a full-time role that requires exceptional technical skills and a strong commitment to ethical hacking practices.Job OverviewWe are a leading organization in the field of cybersecurity, and we're looking for talented...


  • Lahore, Punjab, Pakistan FINCA Impact Finance Full time

    About the RoleThe Global Cybersecurity Specialist will be responsible for maintaining and continuously improving FINCA's cybersecurity posture, monitoring and control framework, ensuring that effective security risk, threat, vulnerability and incident management practices are incorporated into IT and business practices within their FIF and subsidiaries.This...


  • Lahore, Punjab, Pakistan Universal Digital Health Care (UDHC) Full time

    Job Overview:As the Head of Cybersecurity at Universal Digital Health Care (UDHC), you will lead our cybersecurity efforts and develop strategies to protect our organization from cyber threats. This is an exciting opportunity to join a dynamic team and make a significant impact on our organization's security posture.Responsibilities:The ideal candidate will...


  • Lahore, Punjab, Pakistan Pukat Digital Full time

    Cybersecurity Threat MitigatorPukat Digital is seeking a seasoned Cybersecurity Threat Mitigator to safeguard our organization's digital assets and networks.Key Responsibilities:Risk Assessment and Threat Management:Identify and mitigate potential security threatsConduct regular risk assessments and penetration testsDevelop strategies to address identified...


  • Lahore, Punjab, Pakistan FINCA Impact Finance Full time

    Job SummaryThe Cybersecurity and Risk Management Lead will play a pivotal role in maintaining and continuously improving FINCA's cybersecurity posture, monitoring and control framework, ensuring that effective security risk, threat, vulnerability and incident management practices are incorporated into IT and business practices within their FIF and...


  • Lahore, Punjab, Pakistan FINCA Impact Finance Full time

    As a Global Information Systems Auditor at FINCA Impact Finance, you will be responsible for evaluating and improving our organization's technology and cybersecurity infrastructure. Your analytical mind and expertise in IT systems, applications, and infrastructure will enable us to identify areas for improvement and optimize our processes.Main...


  • Lahore, Punjab, Pakistan NADRA Technologies Ltd Full time

    Risk Management SpecialistAbout the Role:We are seeking a highly skilled Risk Management Specialist to join our team at NADRA Technologies Ltd. As a key member of our organization, you will be responsible for identifying, assessing, and mitigating risks across various domains.About You:You possess a Bachelor's degree in Computer Science or a related field...


  • Lahore, Punjab, Pakistan Pukat Digital Full time

    Job DescriptionPukat Digital seeks a highly skilled Cybersecurity Threat Manager to safeguard our organization's digital infrastructure, networks, and sensitive information. The ideal candidate will possess strong analytical skills, a proactive approach to identifying and mitigating cyber threats, and the ability to implement and maintain security protocols...


  • Lahore, Punjab, Pakistan ICE Consulting - Managed IT & Cybersecurity for Life Sciences Full time

    Career Opportunity: Cybersecurity and Systems Administration ProfessionalICE Consulting - Managed IT & Cybersecurity for Life Sciences invites applications from experienced cybersecurity and systems administration professionals.This role offers a unique opportunity to work with a talented team of experts in the life sciences industry.The ideal candidate will...


  • Lahore, Punjab, Pakistan AppsGenii Technologies (Pvt) Ltd. Full time

    AppsGenii Technologies (Pvt) Ltd. is seeking an experienced .Net Developer to join our team. As a cybersecurity specialist, you will be responsible for designing and developing secure software applications using the Microsoft Technology Stack.Responsibilities:Design and develop secure software applications using .NET framework.Implement security measures to...


  • Lahore, Punjab, Pakistan Silicon Technologies Full time

    Silicon Technologies is dedicated to providing top-notch technology solutions to our clients. We are seeking a seasoned Cybersecurity Specialist – Presales to join our team.In this role, you will be responsible for designing and implementing cybersecurity solutions such as ESET Endpoint, Kaspersky Endpoint Solutions and Symantec Endpoint Solutions.Key...


  • Lahore, Punjab, Pakistan Pukat Digital Full time

    Job Description: Cybersecurity SpecialistPosition: Cybersecurity SpecialistLocation: LahoreEmployment Type: Full TimeExperience Level: Senior-LevelJob SummaryWe are seeking a skilled Cybersecurity Specialist to safeguard our organization's digital infrastructure, networks, and sensitive information. The ideal candidate will have strong analytical skills, a...


  • Lahore, Punjab, Pakistan CureMD Full time

    Job OverviewCureMD seeks a skilled Cybersecurity Analyst to safeguard our applications, data, and systems from security threats. This role requires in-depth technical expertise and proactive measures to maintain application integrity, confidentiality, and availability. As a key member of our dynamic team, you will contribute to the organization's overall...


  • Lahore, Punjab, Pakistan TalentPop App Full time

    About Us:TalentPop App is seeking skilled professionals to strengthen our security measures. As a Cybersecurity Operations Specialist, your role will involve managing user accounts and configuring security software.Provision access control and configure security protocols.Implement multifactor authentication for enhanced protection.Key...


  • Lahore, Punjab, Pakistan Ebryx Pvt Ltd Full time

    At Ebryx Pvt Ltd, we are seeking a highly skilled Cybersecurity Threat Intelligence Specialist to join our team.Job Description:Key ResponsibilitiesThreat Hunting: Utilize both manual and automated methods to identify potential security threats.Automated Threat Hunting Project: Develop and maintain an automated project involving Natural Language Processing...


  • Lahore, Punjab, Pakistan ibex Full time

    Job SummaryThe Risk and Compliance Expert will be responsible for assessing and mitigating risks associated with our operations. This includes conducting regular vulnerability assessments and ensuring compliance with relevant regulations.ResponsibilitiesRisk Assessment and MitigationConduct regular vulnerability assessments to identify potential risks and...


  • Lahore, Punjab, Pakistan People Full time

    About the job Team Head CybersecurityJob Description:Implement and maintain secure coding standards to mitigate secure coding vulnerabilities.Analyze, detect and respond to cyber threats through real-time monitoring and proactive defense strategies.Conduct vulnerability assessments, penetration testing and risk evaluations to identify and mitigate security...


  • Lahore, Punjab, Pakistan ACCA Careers Full time

    Job OverviewThe role of Audit and Risk Management Specialist at ACCA Careers involves executing audit field work in line with the approved engagement plan within the agreed timelines.Responsibilities include ensuring compliance with Internal Audit policies and executing audits while finalizing reports.You will identify risks related to each observation and...


  • Lahore, Punjab, Pakistan Icap Full time

    Compliance and Risk Management SpecialistIcap seeks a highly experienced Compliance and Risk Management Specialist to join our Audit Practice Review & Support Program (APRSP). In this role, you will assist the Secretary SMP Committee in various tasks.About the RoleSupport the Secretary SMP Committee in preparing meeting materials and maintaining...