Key Responsibilities
- Conduct cyber and information security assessments across IT infrastructure, cloud, applications, identity, endpoint, network, and third-party environments.
- Identify security risks, control weaknesses, gaps, and practical mitigation options.
- Support ISO 27001, NIST CSF, CIS Controls, PCI DSS, and local regulatory readiness activities.
- Help clients understand what security controls mean in practice and how to implement them proportionately.
- Review existing technical architectures and recommend secure design improvements.
- Support solution design for security technologies such as IAM, MFA, firewalls, EDR, SIEM, vulnerability management, backup/recovery, DLP, email security, and cloud security controls.
- Produce clear risk reports, gap assessments, control recommendations, and implementation roadmaps.
- Run client workshops to gather requirements, explain findings, and agree remediation priorities.
- Support incident response preparation, security policies, risk registers, asset classification, and control mapping.
- Work with sales and pre-sales colleagues to scope technical work realistically and avoid delivery overcommitment.
- Stay current with cyber threats, attack methods, security tooling, and regulatory or framework changes.
Required Experience
- 4 to 8 years of experience in cyber security, information security, IT infrastructure, cloud, network engineering, security engineering, SOC, GRC, or technical consulting.
- Strong understanding of IT stacks, including networks, servers, endpoints, cloud platforms, identity systems, databases, and business applications.
- Experience assessing risk and recommending mitigation controls.
- Experience with security frameworks such as ISO 27001, NIST CSF, CIS Controls, PCI DSS, or equivalent.
- Experience with technical security solution design, security architecture review, or security implementation.
- Client-facing consulting experience is preferred.
Technical Knowledge Required
- Network security: firewalls, segmentation, VPNs, IDS/IPS, and secure remote access.
- Identity and access management: MFA, privileged access, role-based access, and joiner/mover/leaver processes.
- Cloud security: shared responsibility, secure configuration, logging, access control, encryption, backup, and monitoring.
- Endpoint and server security: EDR, patching, hardening, malware protection, and vulnerability management.
- Security monitoring: SIEM, logging, alerting, incident triage, and SOC processes.
- Data protection: encryption, data classification, backup, DLP, and privacy-by-design.
- Risk and controls: inherent risk, residual risk, likelihood, impact, control design, control effectiveness, and remediation planning.
- Secure-by-design: security requirements, architecture review, threat modelling basics, and early control integration into projects.
Framework Knowledge
- ISO 27001: ISMS, risk assessment, Statement of Applicability, policies, controls, and internal audit readiness.
- NIST Cybersecurity Framework: Identify, Protect, Detect, Respond, and Recover.
- CIS Controls: practical technical safeguards and prioritised control implementation.
- PCI DSS: useful where clients handle payment card data.
- NIS CAF / NCSC-style principles: governance, risk management, asset management, supply chain, incident response, and resilience.
- Information Security Framework or local regulatory knowledge.
Skills and Behaviours
- Strong analytical thinking with the ability to separate symptoms from root causes.
- Able to explain technical risk in plain English to non-technical stakeholders.
- Practical mindset, recommending controls that fit the client's size, budget, maturity, and risk exposure.
- Good documentation and report-writing discipline.
- Comfortable running workshops, technical interviews, and findings readouts.
- Able to balance security ideals with business reality.
- Trustworthy, calm, and credible with client stakeholders.
Pay: From Rs500,000.00 per month
Work Location: Hybrid remote in Lahore