Head of Information Security
2 weeks ago
Job Purpose:
To lead, develop, manage, and execute the group wide Information Security Management program across Mashreq Pakistan to ensure highest standards of information security and data privacy are maintained and it's in adherence with head office standards and local regulatory requirements. The Head of Information Security will report directly to the Chief Risk Officer, Mashreq Pakistan and dotted line reporting to the Group Head of Information Security, UAE.
Key Result Areas:
• Provide strategic oversite for Mashreq Pakistan regarding compliance related to Information Security, Cyber Security, Data Privacy and other Industry and regulatory requirements.
• Oversight of Mashreq Pakistan technical and non-technical projects, systems, and contracts with respect to matter of Information and Cyber Security.
• Development and maintenance of documentation and implementation of security policies, procedures, and standards for the organization.
• Align security practices/procedures to the well-known information security standards/guidelines such as ISO27001, PCI/DSS, NIST etc.
• Partner with the Business units, legal, human resources, security personnel, internal audit, and executive management in the development of these policies to ensure information technology resources are secure.
• Monitor compliance with the organization's security policies and procedures among employees, consultants and other third parties.
• Work with various business and technology units, within the Pakistan and global team to implement and operate information security and data privacy controls and compliance reviews.
• Review and provide approvals for technology requests and changes such as architecture vetting and RFC or access control etc.
• Establish security KPIs, KRIs Metrics and periodic reporting process to measure and communicate the effectiveness of security program to local management committees.
• Liaison and at as POC for Information and Cyber security matter with local regulatory bodies.
• Reviewing the security architecture and recommending cost effective changes to the existing structure.
• Managing incident response and reporting of breach of IT/IS Security in the organization and drive for appropriate changes.
• Responsible for setting up the right practices inline with regulatory expectations for Security monitoring function.
• Initiate facilitate and foster activities to create information security awareness within the organization.
• Steering the design & implementation of security solutions addressing perimeter, end points, network and services.
• Keep abreast of security incidents at group data centers and Cloud infrastructure, act as primary control point during significant information security incidents impacting Pakistan systems. Convene a Security Incident Response Team (SIRT) as needed, or requested, in addressing and investigating such security incidents.
• Review all system–related security plans throughout the organization's network, acting as a liaison to Information Systems.
• Assist the management on Information Security Strategy, security budgeting, projects etc.
• Assist/enable business to comply with the regulatory requirements on Information Security and data privacy globally as applicable such as RBI, UAE Central Bank, UBF, SBP etc.
• Engage team members through coaching, training, and awareness programs to ensure risk methodologies communicated across the enterprise.
• Implement access authorization process for infrastructure related controls and conduct periodic reviews.
• Perform security vendor reviews and SLAs.
• Advising executive management committee on risk management matters and exposure to cyber threats, cloud risks and concerns.
Operating Environment, Framework and Boundaries, Working Relationships:
• Assist vendor relationship owners and vendor management team on matters of information Security, data privacy and cyber security requirements.
• Attending central bank and other supervisory meetings to understand the regulator's expectations and drive for implementation.
• Liaison and function as local POC or lead on global information security projects
Problem Solving:
• Ability to enable framework, technology solution and processes for proactive management of the Information Security and Data Privacy risks.
• Ability to understand regulatory language, can take decision on applicability and convert the requirements into actionable with ownership.
• Ability to consult and provide solutions to mitigate the risk to an acceptable level.
• Ability to assess compliance implications for the banking environment.
Decision Making Authority & Responsibility:
• Regulation applicability and compensating control decision.
• Consult and validate solutions to mitigate risks to the business and technology.
• Assessing the adequacy of the controls against internal information security policy, standards, data privacy and local regulatory requirements.
Knowledge, Skills, and Experience:
• A sufficiently senior level official who will have management experience to coordinate direct and in-direct reports on project and issue-based tasks.
• Strong decision making and prioritization skills.
• Strong experience and knowledge in all the Information and Cyber Security domains, areas including governance, policy procedures, security incident response, security management, etc.,
• Sound knowledge of IT environment including infrastructure, systems, database, process etc.
• Knowledge of Banking environment and international compliance including PCI DSS, SWIFT CSP, GDPR etc.
• Professional security certifications such as CISSP, CISA, CISM, CEH, SANS, PCI-QSA, CIPP/E, CIPM etc. are desirable.
• Strong interpersonal, analytical, and technical skills.
-
Head of Security
3 days ago
Karachi, Sindh, Pakistan jcl Full timeSeeking a highly experienced and dedicated Head of Security to lead the security operations. This is a leadership role, ideal for a retired Army professional with a proven track record of managing security in large housing societies such as Askari, DHA, Bahria Town, Saima Arabian Villas, or similar.Location: Naya NazimabadKey Requirements:Retired Army...
-
Information Security Manager
2 weeks ago
Karachi, Sindh, Pakistan Arpatech (Pvt.) Ltd Full time $40,000 - $80,000 per yearWe're looking for an experienced Information Security Manager to lead our organization's security operations, compliance efforts, and governance strategy while fostering a culture of cyber resilience across all departments. You'll be responsible for designing and implementing robust security frameworks, ensuring regulatory compliance, managing risks, and...
-
Head of Administration
7 days ago
Karachi, Sindh, Pakistan The Court Group of Companies Full time 4,200,000 - 5,400,000 per yearHead of Administration & SecurityRetired Colonel or Lt. Colonel RankA leading construction group in Karachi, Pakistan with high-rise buildings and infrastructure projects is seeking a self-motivated ex-army officer Colonel or Lt. Colonel Rank for the post of Head of Admin and Security.The candidate must be from Artillery or Infantry division in Army.· The...
-
Karachi, Sindh, Pakistan Lucky Core Industries Full timeLooking for Possibilities to Grow?Lucky Core Industries Limited is hiring an Assistant Manager – Information Security & Governance for its Corporate Function based in KarachiResponsibilities:Develop, implement, and enforce information security policies, procedures, and standards.Conduct IT risk assessments and coordinate remediation plans with...
-
DFIR Analyst
1 week ago
Karachi, Sindh, Pakistan Trillium Information Security Systems Full timeWe are looking for a Digital Forensics and Incident Response (DFIR) Analyst to join our Security Consultancy and Forensic team. The DFIR Analyst will be responsible for conducting compromise assessments, incident response investigations, and forensic analysis across Windows and Linux environments. The ideal candidate will have hands-on experience with...
-
Network And Security Administrator
5 days ago
Karachi, Sindh, Pakistan Sindh Social Protection Authority, Government of Sindh Full timeBackgroundGovernment of Sindh (GoS), through the Sindh Social Protection Authority (SSPA), is implementing the "Strengthening Social Protection Delivery (SSPDS) System in Sindh" project with the assistance of the World Bank to strengthen social protection service delivery system and enhance accessibility and utilization of mother and child health services in...
-
Application Security Engineer
2 weeks ago
Karachi, Sindh, Pakistan Paysys Labs Full time 900,000 - 1,200,000 per yearHelp the organization evolve its application security function and services.Ensure Secure Software Development Lifecycle is followed within the organization.Review security design/architecture of business applications.Perform information security risk assessments of business applications before deployment in a timely manner.Oversee and perform application...
-
Head of Data Governance
2 weeks ago
Karachi, Sindh, Pakistan Oceanic Star Line Full time 1,200,000 - 3,600,000 per yearHead of Data GovernanceRole OverviewThe Head of Data Governance is responsible for developing and enforcing the company's data governance framework — ensuring data integrity, quality, classification, accuracy, accessibility and ownership, risks, retention, consistency and compliance across all software systems (HRMS, Operational ERP, Finance, Audit,...
-
Manager Security
2 weeks ago
Karachi, Sindh, Pakistan 1 Solution Consulting Full time 3,600,000 - 4,500,000 per yearPosition: Manager SecurityJob SummaryWe are seeking an experienced Manager Security to oversee and manage security operations across all company sites. The role requires a proven background in the Pakistan Navy or Pakistan Air Force with at least 10 years of experience in security leadership. The Manager Security will be responsible for safeguarding company...
-
Information Technology Specialist
2 weeks ago
Karachi, Sindh, Pakistan Myvora Full time 600,000 - 800,000 per yearRole DescriptionThis is a full-time, on-site role in Karachi for an Information Technology Specialist. Responsibilities include managing network administration, troubleshooting technical issues, enhancing network security, and maintaining optimal IT infrastructure performance. The specialist will also provide exceptional customer service and act as a point...