IT Governance and Security Expert

7 days ago


Islamabad, Islamabad, Pakistan beBeeGovernance Full time

Job Title: IT Governance and Security Specialist

Job Summary:

We are seeking an experienced IT Governance and Security Specialist to drive our organization's IT governance, compliance, and security initiatives.

About the Role:

Key Responsibilities:
  • IT Governance:
  • Develop and implement effective IT governance frameworks, policies, and procedures to ensure alignment with corporate governance principles, regulatory requirements, and industry standards.
  • Promote transparency, accountability, and ethical use of IT resources.
  • Provide strategic guidance on IT investments, risk management, and service delivery.
  • Security Governance and Assurance:
  • Design and enforce robust security frameworks, policies, processes, and standards across all IT domains.
  • Establish baseline security controls, ensure regular reviews, and align them with regulatory and corporate requirements.
  • Develop executive-level dashboards and compliance reporting to provide visibility into risk posture and progress.
  • Cloud Security and Compliance:
  • Develop and manage governance frameworks for multi-cloud environments, ensuring secure deployments and adherence to regulatory and industry best practices.
  • Collaborate with enterprise-wide IT teams to embed security and governance.
  • Automate compliance monitoring and reporting using policy as code and infrastructure as code approaches.
  • Risk and Audit Management:
  • Conduct enterprise-wide IT risk assessments, maintain risk registers, and implement mitigation plans.
  • Lead IT-related internal, external, and third-party audits, ensuring evidence is available and findings are resolved on time.
  • Continuously improve governance and compliance programs to remain aligned with evolving threats, business priorities, and regulations.
  • Security Operations and Controls:
  • Oversee deployment and management of key security controls, including Identity and Access Management (IAM), Privileged Access Management (PAM), Email Security Gateway (ESG), endpoint protection, Web Application Firewalls (WAF), network firewalls, and vulnerability management.
  • Implement modern security models such as Zero Trust and ensure continuous monitoring of IT and cloud environments.
  • Leverage AI-driven monitoring and analytics for anomaly detection, predictive threat intelligence, and real-time risk management.
  • Incident Response and Operational Resilience:
  • Develop, maintain, and test incident response frameworks compliant with regulatory and industry requirements.
  • Lead cross-functional teams during incidents and provide clear, timely communication to senior stakeholders.
  • Conduct post-incident reviews and embed lessons learned into governance and operational practices.
  • Business Continuity and Disaster Recovery:
  • Design, implement, and maintain Business Continuity and Disaster Recovery programs for critical services, aligned with regulatory, industry, and international standards.
  • Conduct Business Impact Analyses (BIAs), ensure RTO and RPO compliance, and regularly test recovery strategies.
  • Use AI-enabled simulations to assess readiness and strengthen recovery effectiveness.
  • Vendor and Third-Party Risk Governance:
  • Embed governance and security requirements in vendor and partner contracts, aligned with regulatory and industry standards.
  • Ensure vendors and partners adhere to organizational, regulatory, and industry governance standards.
  • Conduct third-party risk assessments, monitor remediation activities, and track ongoing compliance.
  • Ensure outsourced and partner-operated services consistently meet governance and security requirements.
  • Leadership and Stakeholder Engagement:
  • Lead and mentor the IT Governance and Security team, building capability, innovation, and resilience.
  • Foster a security-first and compliance-driven culture that promotes accountability and responsible innovation.
  • Act as the key liaison with executives, regulators, auditors, and other stakeholders.

Qualifications:

  • Bachelor's degree in Information Security, Computer Science, IT, or a related field.
  • 4+ years progressive experience in IT Governance, Security, or Risk Management.
  • Preferred: Experience in cloud governance, multi-cloud security, and hybrid IT environments.
  • Proven use of automation and AI-enabled governance, monitoring, and threat detection solutions.
  • Professional certifications preferred: CISSP, CISM, CISA, CRISC, ISO 27001 Lead Auditor/Implementer, ITIL.
  • Track record in managing audits, regulatory compliance programs, and enterprise-wide risk initiatives.


  • Islamabad, Islamabad, Pakistan ITCS (IT Consulting and Services) Full time

    Position OverviewWe are seeking a skilled Microsoft Defender for Endpoint Specialist to join our team in Islamabad. The ideal candidate will play a key role in deploying and managing Microsoft Defender for Endpoint solutions to ensure robust endpoint security across the organization.ResponsibilitiesDeploy and configure Microsoft Defender for Endpoint...

  • Bidding Expert

    2 days ago


    Islamabad, Islamabad, Pakistan ATMT Limited Full time

    OverviewATMT Limited is looking for a skilled Bidding Expert to manage the complete tendering and contracts process. The ideal candidate will have strong experience with government and private sector bids, excellent documentation skills, and the ability to deliver winning proposals under tight deadlines.ResponsibilitiesSearch and evaluate relevant tenders...


  • Islamabad, Islamabad, Pakistan Zones IT Solutions Full time

    Information Security Analyst – Compliance & Risk ManagementJoin to apply for the Information Security Analyst – Compliance & Risk Management role at Zones IT SolutionsInformation Security Analyst – Compliance & Risk ManagementJoin to apply for the Information Security Analyst – Compliance & Risk Management role at Zones IT SolutionsGet AI-powered...


  • Islamabad, Islamabad, Pakistan beBeeDataProtection Full time

    Job Title: Chief Information Security OfficerAbout the Job:We are seeking a visionary and technically proficient Data Protection Officer (DPO) to lead our enterprise-wide data protection and privacy program. Reporting directly to the Head of Information Security, the DPO will be responsible for establishing the governance, architecture, and operational...


  • Islamabad, Islamabad, Pakistan beBeeSecurity Full time 12,000,000 - 15,000,000

    Network Security SpecialistWe are seeking a highly skilled Network Security Specialist to join our team. The ideal candidate will possess deep technical expertise in network security, along with the ability to take initiatives for enhancing network security posture of IP core & edge network domain, ensure compliance of internal policies & procedures, and...


  • Islamabad, Islamabad, Pakistan beBeeCybersecurity Full time $90,000 - $120,000

    Senior Cybersecurity AnalystOur company seeks an experienced cybersecurity professional to join our team in a senior analyst role. The ideal candidate will possess a strong background in vulnerability assessment and penetration testing, with expertise in API testing, code review, security automation, threat modeling, and Governance, Risk, and Compliance...


  • Islamabad, Islamabad, Pakistan National Job Portal (NJP) Full time

    Commissioner at Securities and Exchange Commission of Pakistan (SECP)At least 10 years of experience in the field of Securities and Financial Market, Insurance and IndustryMalePublic SectorOfficerDepartmentSecurities and Exchange Commission of Pakistan (SECP)The Securities and Exchange Commission of Pakistan (SECP) is currently seeking a qualified individual...


  • Islamabad, Islamabad, Pakistan Mobiz IT Full time

    OverviewJoin to apply for the Cloud Solutions Architect role at Mobiz ITMobiz is an information technology firm, and we do three things exceptionally well: cloud and network automation, digital transformation, and data protection. Double-digit growth year-over-year has driven us to grow our team and ensure we stay ahead of the curve.What Can You Expect?Every...


  • Islamabad, Islamabad, Pakistan beBeeCloud Full time $90,000 - $120,000

    Cloud Security and Automation Engineer">As a Cloud Security and Automation Engineer, you will play a crucial role in strengthening the security and resilience of our infrastructure and development pipeline. This position is integral to building and securing our cloud environments, developing automated solutions for infrastructure and security, and...

  • Azure Expert

    2 days ago


    Islamabad, Islamabad, Pakistan MAF Software & Technologies Full time

    OverviewWe are looking for a Senior Consultant to join our team to work on a corporate wide large program. This is a hands-on technical role where you will spend as much time building solutions as you do in designing and working with others to deliver them.You will be able to span the disciplines of Solution Architect and Developer, as comfortable with "nuts...