Chief Information Security Officer

7 days ago


Islamabad, Islamabad, Pakistan easypaisa digital bank Full time $800,000 - $2,400,000 per year

POSITION SUMMARY:

The CISO is responsible for management and mitigation of information/cyber security risks across the enterprise and devising strategies to monitor and address current and emerging risks. The CISO is independent of IT and provides assurance reporting on Information/Cyber Security Posture (risk profile) and control health status to management and the Board as part of Risk Management Division. The role serves as the key personnel to liaise with Bank's Management, Board and other stakeholders on Information Security matters and support in achieving the bank's objectives. The CISO (Chief Information Security Officer) must possess deep expertise spanning the
Banking Business
,
Digital Financial Services
, and the
Technology domains
. This comprehensive understanding is essential for designing and delivering security solutions and strategic advisory that are aligned with and tailored to the Bank's Vision, Mission, and core Strategy.

DUTIES & RESPONSIBILITIES:

  1. Develop, implement, and maintain a comprehensive information security vision and strategy aligned with the bank's business objectives and digital transformation efforts
  2. Develop and execute the Bank's Information/Cyber Security Risk Management Program and activities to identify, prioritize and protect Bank's Information and IT Assets against Cyber and physical Security threats.
  3. Establish and oversee the information security governance framework, policies, standards, and procedures. Design, recommend & Implement IS Policies & Procedures aligned to SBP guidelines and best practices.
  4. Ensure compliance with relevant Banking financial industry laws, regulations and best practices / standards e.g., ISO 27001, PCI DSS, Data Privacy, NIST, local central bank guidelines like those from the SBP.
  5. Oversee and manage periodic IT security risk assessments and vulnerability analyses, communicating potential impacts to senior management and the board. Coordinate with IT and other functions to fix the issues.
  6. Oversee the design, implementation, and maintenance of security controls and technologies (e.g., firewalls, intrusion detection/prevention systems, SIEM solutions, encryption etc) across cloud-native environments and IT infrastructure.
  7. Manage security incident detection, response, and recovery, including leading investigations into breaches to minimize damage and ensure rapid restoration of services.
  8. Serve as a primary liaison with internal/external stakeholders, auditors, inspectors, regulators, and effectively translate complex technical risks into business language for executive leadership and the board.
  9. Improve Banks Administrative, technical and process Controls Maturity around Information & IT Assets including Applications, Databases, Endpoints, Network & Infrastructure, Access, Policies and Procedures and stakeholders and employee Awareness & Training etc.
  10. Maintain information security risk management register and coordinate with FLOD/SLOD functions and advise them on the management of Key Information Security & Cyber Security Risks and implementation of corresponding controls.
  11. Develop the Information Security/Cyber Security action Plan and roadmap and periodically inform the Senior Management & BITC on the progress of the Plan and its implementation status.
  12. Drive/oversee and Coordinate Risk based internal and external Vulnerability Assessment Program for EasyPaisa Digital Bank (EDB) Information Assets and supporting infrastructure aligned with Bank's strategy and growth plans. Perform Risk Assessment & Management actions to secure against the identified threats & vulnerabilities to support in meeting business objectives.
  13. Ensure that information assets are protected from unauthorized use, systems are available, and the continued integrity of information and processes is assured. Ensure Threat Intel Monitoring is carried out to mitigate risk arising from adversaries
  14. Ensure incident identification & response mechanism to ensure prevention, detection, containment and correction of security breaches.
  15. Support in managing business continuity and disaster recovery plans to ensure critical operations can withstand and quickly recover from cyber incidents.
  16. Suggest, review and verify Information/Cyber security requirement for any new/update needs of software/hardware/network or related processes thereby providing assistance to EDB on technology procurement/outsourcing from information/cyber security perspective.
  17. Develop, implement, and maintain a comprehensive information security vision and strategy aligned with the bank's business objectives and digital transformation efforts
  18. Develop and execute the Bank's Information/Cyber Security Risk Management Program and activities to identify, prioritize and protect Bank's Information and IT Assets against Cyber and physical Security threats.
  19. Establish and oversee the information security governance framework, policies, standards, and procedures. Design, recommend & Implement IS Policies & Procedures aligned to SBP guidelines and best practices.
  20. Ensure compliance with relevant Banking financial industry laws, regulations and best practices / standards e.g., ISO 27001, PCI DSS, Data Privacy, NIST, local central bank guidelines like those from the SBP.
  21. Oversee and manage periodic IT security risk assessments and vulnerability analyses, communicating potential impacts to senior management and the board. Coordinate with IT and other functions to fix the issues.
  22. Oversee the design, implementation, and maintenance of security controls and technologies (e.g., firewalls, intrusion detection/prevention systems, SIEM solutions, encryption etc) across cloud-native environments and IT infrastructure.
  23. Manage security incident detection, response, and recovery, including leading investigations into breaches to minimize damage and ensure rapid restoration of services.
  24. Serve as a primary liaison with internal/external stakeholders, auditors, inspectors, regulators, and effectively translate complex technical risks into business language for executive leadership and the board.
  25. Improve Banks Administrative, technical and process Controls Maturity around Information & IT Assets including Applications, Databases, Endpoints, Network & Infrastructure, Access, Policies and Procedures and stakeholders and employee Awareness & Training etc.
  26. Maintain information security risk management register and coordinate with FLOD/SLOD functions and advise them on the management of Key Information Security & Cyber Security Risks and implementation of corresponding controls.
  27. Develop the Information Security/Cyber Security action Plan and roadmap and periodically inform the Senior Management & BITC on the progress of the Plan and its implementation status.
  28. Drive/oversee and Coordinate Risk based internal and external Vulnerability Assessment Program for EasyPaisa Digital Bank (EDB) Information Assets and supporting infrastructure aligned with Bank's strategy and growth plans. Perform Risk Assessment & Management actions to secure against the identified threats & vulnerabilities to support in meeting business objectives.
  29. Ensure that information assets are protected from unauthorized use, systems are available, and the continued integrity of information and processes is assured. Ensure Threat Intel Monitoring is carried out to mitigate risk arising from adversaries
  30. Ensure incident identification & response mechanism to ensure prevention, detection, containment and correction of security breaches.
  31. Support in managing business continuity and disaster recovery plans to ensure critical operations can withstand and quickly recover from cyber incidents.
  32. Suggest, review and verify Information/Cyber security requirement for any new/update needs of software/hardware/network or related processes thereby providing assistance to EDB on technology procurement/outsourcing from information/cyber security perspective.
  33. Periodic review of configurations, identities, logical and physical access to IT assets, put up reports, work for corrective measures and improved controls.
  34. Support stakeholders in Regulatory Compliance and Gap Assessments to ensure SBP guidelines are adhered.
  35. Plan, devise, implement and manage IS controls as per the Bank's IS/IT policies in coordination with stakeholders, best Information Security practice standards and in compliance with SBP regulatory requirements.
  36. Coordinate and assist both internal and external audits relating to information security as well as performing independent reviews to validate completeness and accuracy of the information security.
  37. Develop and implement a robust information/cyber security awareness program as per SBP guidelines. Lead security awareness training programs for employees to promote a "security-first" culture across the organization.
  38. Report the EDB Information/Cyber security posture and high severity incidents to the senior management and the BITC.
  39. Gather and interpret cyber threats arising out from the bank's participants, services and utility providers and other Banks. Ensure cyber threat intelligence is shared with relevant staff for mitigation of cyber risks at the strategic, tactical and operational levels.
  40. Represent the Bank at Security and other forums like Pakistan Banker's Association (PBA), Cyber Security, CERT and other relevant IS Forums
  41. Develop, supervise and manage Information security team and their day-to-day activities at the Bank.
  42. Incumbent shall be responsible to adhere by Bank Behaviours & Values in all aspects of his/her work conduct.

QUALIFICATION & EXPERIENCE
(Essential for the job holder):

  • Minimum Bachelor's in computer science (CS/IS or Engineering) from a reputable institute.
  • Relevant certifications in the field of Information Security are an added advantage e.g. CISSP, ISO27001, CRISC, CISA, CISM, CEH, COBIT etc.
  • 10 -15 years of experience with minimum 8-10 years of relevant experience in the same role.


  • Islamabad, Islamabad, Pakistan PakCredit Full time 1,200,000 - 3,600,000 per year

    Company DescriptionPakCredit Loan is a leading digital finance platform revolutionizing access to nano-lending solutions across Pakistan. Focused on empowering underserved communities, PakCredit leverages cutting-edge technology and data analytics to provide fast, secure, and reliable financial support to individuals and small businesses. Known for its...


  • Islamabad, Islamabad, Pakistan Airbornic In'l Full time

    Chief Technology Officer (CTO) – Airbornic InternationalLocation:Remote / Pakistan (Hybrid)Position Type:Full-Time – Executive LeadershipReports To:CEO & FounderDepartment:Technology & Digital TransformationAbout Airbornic InternationalAirbornic International is a rapidly expanding global HR services provider specializing in end-to-end workforce...

  • Security Officer,

    3 days ago


    Islamabad, Islamabad, Pakistan UNICEF Full time

    UNICEF works in over 190 countries and territories to save children's lives, defend their rights, and help them fulfill their potential, from early childhood through adolescence.At UNICEF, we are committed, passionate, and proud of what we do for as long as we are needed. Promoting the rights of every child is not just a job – it is a calling.UNICEF is a...


  • Islamabad, Islamabad, Pakistan Menzies Aviation Full time $60,000 - $180,000 per year

    OverviewPeople. Passion. Pride. This is what has driven our teams since 1833.Since that time, we have developed to become a critical partner in the global aviation industry, delivering time-critical logistics services at 350 locations in more than 65 countries, across six continents.But at the heart of our business is our people.Role PurposeAs the...


  • Islamabad, Islamabad, Pakistan ISMMART Group of Industries (Pvt) Ltd Full time 2,000,000 - 5,000,000 per year

    ISMMART Estates and Builders (Pvt.) Ltd – Pakistan ChapterLocation:Islamabad, PakistanEmployment Type:Full-TimeAbout ISMMART GroupISMMART Group is a diversified multinational conglomerate with a strong presence across multiple sectors, including Energy, Real Estate, E-Commerce, and Hospitality. Driven by innovation and a commitment to sustainable growth,...


  • Islamabad, Islamabad, Pakistan Motive Full time 1,200,000 - 3,600,000 per year

    Who we are:Motive empowers the people who run physical operations with tools to make their work safer, more productive, and more profitable. For the first time ever, safety, operations and finance teams can manage their drivers, vehicles, equipment, and fleet related spend in a single system. Combined with industry leading AI, the Motive platform gives you...


  • Islamabad, Islamabad, Pakistan beneeful Full time $480,000 - $1,440,000 per year

    We're Hiring: Chief Financial Officer (CFO) — BeneefulBeneeful is transforming mental health in Pakistan by making therapy accessible, affordable, and stigma-free. We're seeking a CFO to drive our financial strategy and help scale our impact.Key ResponsibilitiesLead financial planning, budgeting, and forecastingBuild financial systems, reporting, and...


  • Islamabad, Islamabad, Pakistan Ghoomana Inc. Full time 9,000,000 - 12,000,000 per year

    Company DescriptionGhoomana Inc., established in 2023, offers transformative travel experiences for individuals aged 18-40 and beyond. Our group tours provide opportunities to connect, explore, taste diverse cultures, and contribute positively to the world while fostering lasting friendships. At Ghoomana, we believe that travel is not just an adventure but a...


  • Islamabad, Islamabad, Pakistan Jinglecred Digital Finance Limited Full time

    Job description:About JDFL:JDFL is a pioneering fintech company dedicated to revolutionizing financial services through cutting-edge technology and innovative solutions. Our mission is to provide secure, efficient, and accessible financial services to a broad range of customers, fostering financial inclusion and empowerment.Job Summary:We are seeking a...


  • Islamabad, Islamabad, Pakistan Premier Security Services Pvt Ltd Full time 300,000 - 600,000 per year

    We are seeking a highly trained and professional Close Protection Officer (CPO) to ensure the safety and security of our client(s). The ideal candidate will have a strong background in personal security, excellent situational awareness, and the ability to remain calm under pressure.Job Type: Full-timeWork Location: In person