Qureos

Find The RightJob.

Cyber Security Technical Consultant / Security Specialist

Key Responsibilities

  • Conduct cyber and information security assessments across IT infrastructure, cloud, applications, identity, endpoint, network, and third-party environments.
  • Identify security risks, control weaknesses, gaps, and practical mitigation options.
  • Support ISO 27001, NIST CSF, CIS Controls, PCI DSS, and local regulatory readiness activities.
  • Help clients understand what security controls mean in practice and how to implement them proportionately.
  • Review existing technical architectures and recommend secure design improvements.
  • Support solution design for security technologies such as IAM, MFA, firewalls, EDR, SIEM, vulnerability management, backup/recovery, DLP, email security, and cloud security controls.
  • Produce clear risk reports, gap assessments, control recommendations, and implementation roadmaps.
  • Run client workshops to gather requirements, explain findings, and agree remediation priorities.
  • Support incident response preparation, security policies, risk registers, asset classification, and control mapping.
  • Work with sales and pre-sales colleagues to scope technical work realistically and avoid delivery overcommitment.
  • Stay current with cyber threats, attack methods, security tooling, and regulatory or framework changes.

Required Experience

  • 4 to 8 years of experience in cyber security, information security, IT infrastructure, cloud, network engineering, security engineering, SOC, GRC, or technical consulting.
  • Strong understanding of IT stacks, including networks, servers, endpoints, cloud platforms, identity systems, databases, and business applications.
  • Experience assessing risk and recommending mitigation controls.
  • Experience with security frameworks such as ISO 27001, NIST CSF, CIS Controls, PCI DSS, or equivalent.
  • Experience with technical security solution design, security architecture review, or security implementation.
  • Client-facing consulting experience is preferred.

Technical Knowledge Required

  • Network security: firewalls, segmentation, VPNs, IDS/IPS, and secure remote access.
  • Identity and access management: MFA, privileged access, role-based access, and joiner/mover/leaver processes.
  • Cloud security: shared responsibility, secure configuration, logging, access control, encryption, backup, and monitoring.
  • Endpoint and server security: EDR, patching, hardening, malware protection, and vulnerability management.
  • Security monitoring: SIEM, logging, alerting, incident triage, and SOC processes.
  • Data protection: encryption, data classification, backup, DLP, and privacy-by-design.
  • Risk and controls: inherent risk, residual risk, likelihood, impact, control design, control effectiveness, and remediation planning.
  • Secure-by-design: security requirements, architecture review, threat modelling basics, and early control integration into projects.

Framework Knowledge

  • ISO 27001: ISMS, risk assessment, Statement of Applicability, policies, controls, and internal audit readiness.
  • NIST Cybersecurity Framework: Identify, Protect, Detect, Respond, and Recover.
  • CIS Controls: practical technical safeguards and prioritised control implementation.
  • PCI DSS: useful where clients handle payment card data.
  • NIS CAF / NCSC-style principles: governance, risk management, asset management, supply chain, incident response, and resilience.
  • Information Security Framework or local regulatory knowledge.

Skills and Behaviours

  • Strong analytical thinking with the ability to separate symptoms from root causes.
  • Able to explain technical risk in plain English to non-technical stakeholders.
  • Practical mindset, recommending controls that fit the client's size, budget, maturity, and risk exposure.
  • Good documentation and report-writing discipline.
  • Comfortable running workshops, technical interviews, and findings readouts.
  • Able to balance security ideals with business reality.
  • Trustworthy, calm, and credible with client stakeholders.

Pay: From Rs500,000.00 per month

Work Location: Hybrid remote in Lahore

© 2026 Qureos. All rights reserved.