The ideal candidate for this role will support the global Information Security function and assist the Global CISO in delivering cybersecurity risk management aligned with the organization’s business strategy.
Location:
Karachi, Lahore, Islamabad, Multan, Faislabad.
Responsibilities:
-
Conduct information security risk assessments and related analysis across systems, projects, and third-party engagements.
-
Maintain and update the Information Security Risk Register, ensuring risks are accurately documented and tracked.
-
Monitor and report Key Risk Indicators (KRIs), ensuring timely escalation when thresholds are exceeded.
-
Support the management of exceptions to Information Security policies, including assessment, documentation, and tracking.
-
Assist in managing the cybersecurity risk lifecycle, from identification and assessment to mitigation and reporting.
-
Provide risk reporting and insights to stakeholders and senior security leadership.
-
Ensure security risk practices align with regulatory requirements, security frameworks, and internal risk appetite.
-
Work closely with security teams, business units, and technology teams to promote risk awareness and improve risk management processes.
Requirements:
-
3–5 years of experience in Information Security, Cyber Risk, or IT Risk Management.
-
Experience conducting information security risk assessments and maintaining risk registers.
-
Familiarity with cybersecurity frameworks and standards such as ISO 27001, NIST, or similar.
-
Understanding of cybersecurity risk lifecycle, governance, and compliance practices.
-
Strong analytical, documentation, and reporting skills.
-
Ability to communicate risk concepts clearly to technical and non-technical stakeholders.
-
Relevant certifications such as CISM, CRISC, CISSP, or ISO 27001 are a plus.