AM IT Security

ibex

Lahore

On-site

PKR 3,000,000 - 6,000,000

Full time

7 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Ibex in Lahore seeks a senior Information Security professional to lead risk management across IT, cloud, and supplier ecosystems. You will coordinate IT security roadmaps and drive control implementation to protect IBEX Global assets.

Responsibilities include conducting risk assessments, overseeing third-party IT risk, and mentoring the security team while reporting to IT leadership.

Qualifications

  • 8-12 years of IT/Information Security experience.
  • Strong understanding of ITRM concepts, methodologies, controls and architectures.
  • Knowledge of risk frameworks such as ISO 27005, NIST CSF.
  • Excellent presentation and communication skills.

Responsibilities

  • Lead and perform end-to-end IT Risk Assessments across Infrastructure, Applications, data security and IAM.
  • Develop and maintain risk registers, risk heatmaps, and executive risk reporting.
  • Support internal and external audits with risk documentation and remediation evidence.
  • Conduct Supply Chain / Third-Party IT Risk Assessments and review vendor security responses.
  • Lead and mentor the risk team; ensure timely delivery and quality of risk deliverables.
  • Present risk findings to IT leadership and risk committees; guide policy development.

Job description

About the Company

To protect IBEX infrastructure from emerging threats and help organization in achieving business objectives. This position acts as senior level IS resource having strong background of Network and Cyber Security functions. This position will coordinate & will help implementing IT Security Roadmap and security processes for the protection of IBEX Global assets.

About the Role

This position acts as senior level IS resource having strong background of Network and Cyber Security functions. This position will coordinate & will help implementing IT Security Roadmap and security processes for the protection of IBEX Global assets.

Responsibilities
A. Information Security Risk Management & Assessments (Hands-On)
  • Lead and perform end-to-end IT Risk Assessments, including inherent risk identification, control design and evaluation of operating effectivness, residual risk rating and risk treament recommendations.
  • Assess risks across Infrastructure (on-prem, cloud, hybrid), Applications and Systems, data security and privacy, identity and access management, change and configuration management etc.
  • Develop and maintain risk registers, risk heatmaps, and executive-level risk reporting.
  • Support internal and external audits by providing risk documentation and remediation evidence.
B. Supply Chain & Third-Party Risk Management
  • Conduct Supply Chain / Third-Party IT Risk Assessments for vendors, partners, and service providers.
  • Evaluate vendor risks related to Information Security, Data Protection & Privacy, Business Continuity and resilience, sub-contractor and fourth party risks.
  • Review and assess Vendor security questionnaires, independent audit reports such as SOC2, ISO 27001, PCI DSS, Penetration Test Summaries, ISO 42001 for AI Service Providers etc.
  • Collaborate with Procurement, Legal, and Compliance teams to define risk-based onboarding criteria, support contract security clauses, track vendor risk remediation activities etc.
C. AI Risk Assessments & AI System Impact Assessments
  • Lead and perform AI Risk Assessments across AI/ML systems, including but not limited to model risks, data quality and bias risks, secuirty and adversarial risks, privacy and data protection risks, ethical and responsible AI risks etc.
  • Conduct AI System Impact Assessments (AISIAs) to evaluate impact on individuals and customers, regulatory and compliance implications, business and reputational risks etc.
  • Align AI risk activities with relevant frameworks and regulations, such as ISO/IEC 42001 (AI Management Systems), NIST AI Risk Management Framework, Applicable data protection and AI regulations etc.
  • Partner with AI, Data Science, Legal, and Product teams to embed risk controls into AI system lifecycles.
D. Team Leadership & Management
  • Manage, coach, and mentor team members.
  • Review and approve risk assessment deliverables to ensure quality and consistency.
  • Allocate work, set priorities, and track progress against agreed timelines.
  • Provide performance feedback, skill development guidance, and technical direction.
  • Promote standardization of risk assessment methodologies, templates, and reporting.
E. Stakeholder Engagement & Reporting
  • Act as a trusted risk advisor to technology, business, and senior leadership stakeholders.
  • Present risk findings and recommendations to IT leadership, Risk committee, Senior management etc.
  • Support the development of risk policies, standards, and procedures.
  • Drive a culture of risk awareness and accountability across the organization.
Qualifications
  • Education
  • Bachelors/Masters Degree in IT/CS/Software Eng./Telecom
  • Experience
  • 8 - 12 years
Required Skills
  • 5+ years of hands on experience in IT/Information Security Risk Management
  • Strong understanding of ITRM concepts, methodologies, controls and architectures. Cloud.
  • Hands-on experience with Third-Party/Supply Chain Risk Assessments
  • Knowledge of risk frameworks such as ISO 27005, NIST CSF etc.
  • Strong presentation and communication skills
  • Reporting Time 5pm to 2am (PKST)
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior IT Security & Risk Manager
Senior IT Security & Risk Manager

ibex • Lahore

On-site
PKR 3,000,000 - 6,000,000
AM Information Security - Risk Management & Compliance
AM Information Security - Risk Management & Compliance

Zong 5G • Islamabad

On-site
PKR 1,800,000 - 2,400,000
Senior Enterprise Network Security Specialist
Senior Enterprise Network Security Specialist

HBL • Karachi Division

On-site
PKR 1,800,000 - 2,400,000
Enterprise Application Security and Risk Specialist
Enterprise Application Security and Risk Specialist

HBL • Karachi Division

On-site
PKR 1,200,000 - 2,000,000
Enterprise Application Security and Risk Specialist
Enterprise Application Security and Risk Specialist

HBL People • Pakistan

On-site
PKR 90,000 - 130,000
Cyber Security Engineer - Islamabad
Cyber Security Engineer - Islamabad

Yeah! Global • Islamabad

On-site
PKR 1,116,000 - 1,674,000
Cyber Security Technical Consultant / Security Specialist
Cyber Security Technical Consultant / Security Specialist

AURMAK LIMITED • Pakistan

On-site
PKR 2,000,000 - 4,000,000
Assistant Manager Information Security
Assistant Manager Information Security

Master Group • Islamabad

On-site
PKR 1,000,000 - 1,600,000
Lead Manager – IT and Operational Risks
Lead Manager – IT and Operational Risks

SSGC LPG Limited • Karachi Division

On-site
PKR 2,500,000 - 6,000,000
Head of Information Security - Confidential
Head of Information Security - Confidential

Brickstech • Lahore

On-site
PKR 3,000,000 - 6,000,000