Governance, Risk, and Compliance (GRC) Specialist

NETSOL Technologies Inc.

Lahore

On-site

PKR 1,800,000 - 3,000,000

Full time

24 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

NETSOL Technologies Inc. in Lahore, Pakistan, seeks an experienced information security professional to lead risk management, develop security testing plans, and drive compliance with ISO standards and SOC2.

You will develop metrics, support security awareness training, and perform risk assessments to monitor controls against KPI objectives. The role requires 5+ years of documentation experience, strong communication skills, and the ability to craft and update security policies and procedures in

Qualifications

  • In-depth knowledge of ISO 27001, ISO 27005, ISO 27701, ISO 20000, ISO 22301 and SOC2 standards.
  • In-depth knowledge of Information Security Risk Management lifecycle.
  • B.S. in Computer Science or Information Systems.
  • Minimum 5+ years of process documentation experience.
  • CISA, CISM, or CISSP certified.
  • Strong knowledge of IT systems, IT technologies, etc.
  • Excellent verbal and written communication skills.

Responsibilities

  • Develop and maintain security testing plans.
  • Develop meaningful metrics to reflect the true posture of the information security to make educated decisions based on risk.
  • Assist with development and delivery of security awareness training.
  • Carry out risk assessments, identifying controls and monitoring controls against objectives and KPI metrics.
  • Document, update, and implement security policies, procedures, and other related documents.
  • Inform and advise team members about obligations to comply with the GDPR and other data protection laws.

Skills

ISO 27001
ISO 27005
ISO 27701
ISO 20000
ISO 22301
SOC2
Risk management lifecycle
CISA
CISM
CISSP
IT systems knowledge
Communication skills

Education

B.S. in Computer Science or Information Systems
5+ years process documentation experience

Job description

  • Develop and maintain security testing plans
  • Develop meaningful metrics to reflect the true posture of the information security to make educated decisions based on risk
  • Assist with development and delivery of security awareness training
  • Carry out risk assessments, identifying controls and monitoring controls against objectives and KPI metrics
  • Document, update, and implement security policies, procedures, and other related documents
  • Inform and advise team members about obligations to comply with the GDPR and other data protection laws
Required skills and qualifications:
  • In-depth knowledge of ISO 27001, ISO 27005, ISO 27701, ISO 20000, ISO 22301 and SOC2 standards
  • In-depth knowledge of Information Security Risk Management lifecycle
  • B.S. in Computer Science or Information Systems
  • Minimum 5+ years of process documentation experience
  • CISA, CISM, or CISSP certified
  • Strong knowledge of IT systems, IT technologies, etc.
  • Excellent verbal and written communication skills
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Analyst
GRC Analyst

TheGlobalCB • Karachi Division

On-site
Competitive salary
Performance bonuses
Sponsored trainings & international certifications
+1
Senior Consultant - GRC
Senior Consultant - GRC

Risk Associates Pvt. Ltd. • Karachi Division

On-site
PKR 1,116,000 - 1,674,000
Assistant Manager: GRC & Compliance
Assistant Manager: GRC & Compliance

Arpatech (Pvt) Ltd • Karachi Division

On-site
AM Information Security - Risk Management & Compliance
AM Information Security - Risk Management & Compliance

Zong 5G • Islamabad

On-site
PKR 1,800,000 - 2,400,000
Cyber Security Technical Consultant / Security Specialist
Cyber Security Technical Consultant / Security Specialist

AURMAK LIMITED • Pakistan

On-site
PKR 2,000,000 - 4,000,000
Risk Analyst
Risk Analyst

i2c Inc • Lahore

On-site
PKR 150,000 - 210,000
SOX ITGC Consultant
SOX ITGC Consultant

Systems Limited • Karachi Division

On-site
PKR 1,800,000 - 3,400,000
GRC & Security Operations Lead — ISO 27001, GDPR
GRC & Security Operations Lead — ISO 27001, GDPR

Arpatech (Pvt) Ltd • Karachi Division

On-site
SOX ITGC Consultant
SOX ITGC Consultant

Systems Limited • Islamabad

On-site
PKR 900,000 - 1,300,000
Deputy Manager - Information Security (GRC) - NSID
Deputy Manager - Information Security (GRC) - NSID

Szabist Isb • Karachi Division

On-site
PKR 2,500,000 - 4,200,000