Deputy Manager - Information Security (GRC) - NSID

Szabist Isb

Karachi Division

On-site

PKR 2,500,000 - 4,200,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

EFU Life Assurance Ltd. invites applications for a Deputy Manager specializing in Information Security Governance, Risk, and Compliance (GRC).

The role drives the organization’s cybersecurity framework with focus on regulatory compliance and risk management across infrastructure, data, and operations. The ideal candidate has at least eight years in information security and GRC, leads a team of 10, and steers audits, VAPT, and awareness programs to strengthen overall security posture and

Qualifications

  • 8+ years of information security experience and GRC leadership.
  • Experience managing a team of 10 professionals.
  • Familiarity with ISO 27001:2022, ISO 9001 and SECP standards.

Responsibilities

  • Develop and maintain Information Security Governance framework with policies, standards, and procedures.
  • Drive regulatory compliance with ISO 27001:2022, ISO 9001, SECP regulations and related frameworks.
  • Oversee internal and external audits, certifications, and regulatory reporting.
  • Lead enterprise risk assessment, vulnerability management, and VAPT across systems.
  • Manage 24/7 security monitoring and incident response via SOC/EDR/SIEM/Cyber Command teams.
  • Ensure timely incident management and root-cause analysis of security findings.
  • Oversee third-party/vendor security assessments and ensure contractual controls.
  • Support data protection, privacy, business continuity, and disaster recovery initiatives.
  • Lead security awareness programs for executives and staff; prepare risk/compliance reports for governance forums.
  • Provide leadership to a 10-person information security team to meet security objectives.

Skills

Information security
GRC
Leadership
Regulatory compliance
Audit & certification
Risk management
Cyber security monitoring

Tools

SIEM
EDR
SOC

Job description

EFU Life Assurance Ltd. seeks a Deputy Manager specializing in Information Security Governance, Risk, and Compliance (GRC) to lead and strengthen the organization’s cybersecurity framework. This role demands a seasoned professional with at least eight years of experience in information security and GRC, who will oversee a dedicated team of 10 professionals. The Deputy Manager ensures the company strictly adheres to regulatory standards such as ISO 27001:2022, ISO 9001, and SECP by managing compliance initiatives and fostering effective cyber risk management across infrastructure, applications, data, and operations.The role involves maintaining a robust Information Security Governance framework, spearheading audit and certification activities, and steering enterprise-wide risk and vulnerability management processes. The position requires leadership in 24/7 security monitoring and incident response, with responsibilities including managing SOC, EDR, SIEM, and Cyber Command functions. This leader also ensures timely incident management and thorough root cause analysis, while facilitating security awareness programs and preparing comprehensive risk and compliance reports for senior management and governance forums.

Responsibilities
  • Lead the development and maintenance of the Information Security Governance framework, including policies, standards, and procedures to ensure effective cybersecurity management.
  • Drive compliance with international standards such as ISO 27001:2022, ISO 9001, SECP cybersecurity regulations, and other applicable regulatory frameworks, ensuring EFU Life Assurance Ltd. remains aligned with evolving standards.
  • Oversee and manage internal and external audits, certifications, and regulatory reporting requirements, ensuring that organizational controls meet or exceed compliance standards.
  • Direct enterprise-wide risk assessment initiatives, including vulnerability management and Vulnerability Assessment and Penetration Testing (VAPT) activities covering internal, external, web, mobile, and infrastructure components.
  • Govern continuous 24/7 security monitoring and incident response by managing Security Operations Center (SOC), Endpoint Detection and Response (EDR), Security Information and Event Management (SIEM), and Cyber Command teams and tools.
  • Manage incident response processes, ensuring comprehensive root cause analysis and expedited closure of security findings to mitigate risks effectively.
  • Oversee third-party and vendor security assessments, evaluating contractual security controls and ensuring vendor compliance with security requirements.
  • Support initiatives related to data protection, privacy, business continuity, and disaster recovery, integrating these areas into the broader security program.
  • Lead ongoing security awareness and training programs targeted at executives and employees to cultivate a security-conscious organizational culture.
  • Prepare and deliver detailed risk, compliance, and security performance reports to senior management and governance committees, informing strategic decision-making.
  • Provide leadership and direction to a skilled team of 10 information security professionals, fostering collaboration and professional development to achieve organizational security objectives.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Information Security GRC & Compliance Lead
Senior Information Security GRC & Compliance Lead

Szabist Isb • Karachi Division

On-site
PKR 2,500,000 - 4,200,000
Senior Consultant - GRC
Senior Consultant - GRC

Risk Associates Pvt. Ltd. • Karachi Division

On-site
PKR 1,116,000 - 1,674,000
Executive Officer - Admin & IT
Executive Officer - Admin & IT

Szabist Isb • Lahore

On-site
PKR 1,200,000 - 2,400,000
Deputy Manager - Underwriting - UPID
Deputy Manager - Underwriting - UPID

Szabist Isb • Karachi Division

On-site
PKR 1,800,000 - 3,200,000
Head of Information Security - Confidential
Head of Information Security - Confidential

Brickstech • Lahore

On-site
PKR 3,000,000 - 6,000,000
Engineer / Deputy Manager – IT Risk Management
Engineer / Deputy Manager – IT Risk Management

Sui Southern Gas Company Limited • Karachi Division

On-site
PKR 1,800,000 - 3,200,000
Governance, Risk, and Compliance (GRC) Specialist
Governance, Risk, and Compliance (GRC) Specialist

NETSOL Technologies Inc. • Lahore

On-site
PKR 1,800,000 - 3,000,000
AM Information Security - Risk Management & Compliance
AM Information Security - Risk Management & Compliance

Zong 5G • Islamabad

On-site
PKR 1,800,000 - 2,400,000
Assistant Manager: GRC & Compliance
Assistant Manager: GRC & Compliance

Arpatech (Pvt) Ltd • Karachi Division

On-site
Assistant Manager - Digital Platform
Assistant Manager - Digital Platform

Szabist Isb • Karachi Division

On-site
PKR 1,800,000 - 3,400,000