Head of Information Security - Confidential

Brickstech

Lahore

On-site

PKR 3,000,000 - 6,000,000

Full time

28 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

HOF Global in Lahore (On-site, Full-time) seeks a Senior Application Security Engineer to set and independently assure the company’s information security, risk and compliance posture while enabling business growth for millions of borrowers and member institutions.

You will own the enterprise risk posture, lead SBP inspections, drive ISO 27001 certifications, oversee SIEM/SOAR, and manage third-party security risk, reporting to the CEO and Board.

Qualifications

  • 15+ years in information security, risk and compliance in regulated environments.
  • Demonstrated track record managing regulator audits (SBP preferred).
  • Pragmatic security leader who enables innovation while managing risk.

Responsibilities

  • Set and govern the information security, risk and compliance strategy aligned to ISO 27001, NIST, CIS.
  • Lead SBP inspections and risk audits end-to-end; ensure regulatory compliance.
  • Design and maintain security policy, controls, and assurance program; drive certifications such as ISO 27001.

Skills

Information security
Risk management
Regulatory compliance
Leadership

Tools

SIEM
SOAR
ISO 27001

Job description

Senior Application Security Engineer
  • On-site
  • Full-time
  • 6–10 Years
  • HOF Global
Job Description

Role Purpose Set and independently assure company’s information security, risk and compliance posture as a business enabler — protecting the bureau’s data and the trust of ~42 million borrowers and 174 member institutions, while finding the safe, defensible path to “yes” so the business can innovate and grow.

Key Tasks and Responsibilities:

Strategy & Business-Enabling Risk Posture

  • Set the vision and strategic direction for the information security, risk and compliance programme, aligned to recognised standards (ISO 27001, NIST, CIS).
  • Operate as a business enabler, not a blocker: take a risk-based, pragmatic stance that supports product innovation and speed-to-market. Where a request carries risk, propose the controlled path to proceed rather than defaulting to “no.”
  • Own and maintain the enterprise risk register and key risk indicators; make risk visible and decision-ready for management and the Board.

Regulatory Audit & Compliance

  • Own the State Bank of Pakistan relationship for security and risk: lead SBP inspections and risk audits end-to-end — preparation, evidence, response, and timely closure of findings.
  • Lead broader compliance activities and external audits.
  • Ensure compliance with the Credit Bureaus Act 2015, applicable SBP prudential and IT regulations, and data-protection obligations for borrower PII.

Governance, Framework & Controls

  • Design and maintain the information security policy, framework, standards and controls; govern their implementation and independently assure their effectiveness.
  • Drive relevant certifications (e.g. ISO 27001) as a mark of best-in-class posture and an asset to the IPO story.

Threat, Incident & Resilience

  • Plan and manage cyber-threat and incident response to minimise business impact; run monitoring / SIEM / SOAR, breach investigation and breach reporting.
  • Assure business continuity and disaster recovery from a risk and resilience lens, in partnership with the Head of IT & Infrastructure.
  • Own the security tooling strategy (SIEM, SOAR, firewalls, encryption, DLP) — specifying what the business needs, with IT implementing.

Assurance, Third Parties & Culture

  • Run VAPT of company's infrastructure and the mobile app; track remediation through to closure.
  • Manage third-party and vendor security risk across member institutions, fintech partners and cloud / technology vendors.
  • Work with system owners to keep all systems compliant with security requirements; build an enterprise-wide security awareness culture, including staff training.
  • Report the security and risk posture to the CEO, Management, Board and Board Committees.

Key Performance Indicators

  • SBP audit outcomes: findings raised, and percentage closed within agreed timelines.
  • Risk register health: KRIs within tolerance and open high risks trending down.
  • Security incident performance: number and severity of incidents, mean time to detect and respond, and breaches.
  • VAPT remediation: percentage closed within SLA by severity.
  • Certification progress and maintenance (e.g. ISO 27001).
  • Control effectiveness and assurance / audit pass rate.
  • Third-party security risk assessments completed.
  • Security awareness: training completion rate and phishing-simulation results.
  • Enablement: turnaround time on security reviews and requests — so the “business enabler” mandate is measured, not just stated.

Person Specification

  • 15+ years in information security, risk and compliance — the depth that comes at senior level — with experience in a regulated financial-services or data-sensitive environment.
  • Demonstrated track record managing regulator audits — SBP experience strongly preferred (or a comparable central-bank / financial regulator).
  • A pragmatic, business-minded security leader who enables innovation while managing risk — evidence of saying “here’s how we do this safely,” not just “no.”
  • Not a push-over: able to hold the line on genuine, material risk and stand behind it with management, the Board and regulators.
  • Certifications such as CISSP, CISM, CRISC and / or ISO 27001 Lead Auditor / Implementer.
  • Strong command of security frameworks (ISO 27001, NIST, CIS) and incident response; working knowledge of the Credit Bureaus Act 2015 and SBP regulations an advantage
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Chief Information Security & Risk Leader
Chief Information Security & Risk Leader

Brickstech • Lahore

On-site
PKR 3,000,000 - 6,000,000
SOC Manager
SOC Manager

Mobilink Microfinance Bank Ltd • Gadap Town

On-site
PKR 2,500,000 - 3,500,000
Head of International IS Privacy Research and Innovation
Head of International IS Privacy Research and Innovation

HBL People • Pakistan

On-site
PKR 9,000,000 - 15,000,000
Head of International IS Privacy Research and Innovation
Head of International IS Privacy Research and Innovation

Hblpeople • Karachi Division

On-site
PKR 6,000,000 - 12,000,000
Head of Cyber Security Research and Innovation
Head of Cyber Security Research and Innovation

Hblpeople • Karachi Division

On-site
PKR 19,482,000 - 25,049,000
Head Information Security Risk Management
Head Information Security Risk Management

ThePakEdu • Karachi Division

On-site
PKR 2,031,000 - 2,433,000
AM Information Security - Risk Management & Compliance
AM Information Security - Risk Management & Compliance

Zong 5G • Islamabad

On-site
PKR 1,800,000 - 2,400,000
Head IS Risk Management
Head IS Risk Management

ThePakEdu • Karachi Division

On-site
PKR 1,674,000 - 2,232,000
JUNIOR MANAGEMENT POSITION - DATA PRIVACY & PROTECTION
JUNIOR MANAGEMENT POSITION - DATA PRIVACY & PROTECTION

hrsi • Karachi Division

On-site
PKR 2,000,000 - 3,000,000
Head of Cyber Security Research and Innovation
Head of Cyber Security Research and Innovation

HBL People • Pakistan

On-site
PKR 6,000,000 - 9,000,000