Senior Application Security Engineer
- On-site
- Full-time
- 6–10 Years
- HOF Global
Job Description
Role Purpose Set and independently assure company’s information security, risk and compliance posture as a business enabler — protecting the bureau’s data and the trust of ~42 million borrowers and 174 member institutions, while finding the safe, defensible path to “yes” so the business can innovate and grow.
Key Tasks and Responsibilities:
Strategy & Business-Enabling Risk Posture
- Set the vision and strategic direction for the information security, risk and compliance programme, aligned to recognised standards (ISO 27001, NIST, CIS).
- Operate as a business enabler, not a blocker: take a risk-based, pragmatic stance that supports product innovation and speed-to-market. Where a request carries risk, propose the controlled path to proceed rather than defaulting to “no.”
- Own and maintain the enterprise risk register and key risk indicators; make risk visible and decision-ready for management and the Board.
Regulatory Audit & Compliance
- Own the State Bank of Pakistan relationship for security and risk: lead SBP inspections and risk audits end-to-end — preparation, evidence, response, and timely closure of findings.
- Lead broader compliance activities and external audits.
- Ensure compliance with the Credit Bureaus Act 2015, applicable SBP prudential and IT regulations, and data-protection obligations for borrower PII.
Governance, Framework & Controls
- Design and maintain the information security policy, framework, standards and controls; govern their implementation and independently assure their effectiveness.
- Drive relevant certifications (e.g. ISO 27001) as a mark of best-in-class posture and an asset to the IPO story.
Threat, Incident & Resilience
- Plan and manage cyber-threat and incident response to minimise business impact; run monitoring / SIEM / SOAR, breach investigation and breach reporting.
- Assure business continuity and disaster recovery from a risk and resilience lens, in partnership with the Head of IT & Infrastructure.
- Own the security tooling strategy (SIEM, SOAR, firewalls, encryption, DLP) — specifying what the business needs, with IT implementing.
Assurance, Third Parties & Culture
- Run VAPT of company's infrastructure and the mobile app; track remediation through to closure.
- Manage third-party and vendor security risk across member institutions, fintech partners and cloud / technology vendors.
- Work with system owners to keep all systems compliant with security requirements; build an enterprise-wide security awareness culture, including staff training.
- Report the security and risk posture to the CEO, Management, Board and Board Committees.
Key Performance Indicators
- SBP audit outcomes: findings raised, and percentage closed within agreed timelines.
- Risk register health: KRIs within tolerance and open high risks trending down.
- Security incident performance: number and severity of incidents, mean time to detect and respond, and breaches.
- VAPT remediation: percentage closed within SLA by severity.
- Certification progress and maintenance (e.g. ISO 27001).
- Control effectiveness and assurance / audit pass rate.
- Third-party security risk assessments completed.
- Security awareness: training completion rate and phishing-simulation results.
- Enablement: turnaround time on security reviews and requests — so the “business enabler” mandate is measured, not just stated.
Person Specification
- 15+ years in information security, risk and compliance — the depth that comes at senior level — with experience in a regulated financial-services or data-sensitive environment.
- Demonstrated track record managing regulator audits — SBP experience strongly preferred (or a comparable central-bank / financial regulator).
- A pragmatic, business-minded security leader who enables innovation while managing risk — evidence of saying “here’s how we do this safely,” not just “no.”
- Not a push-over: able to hold the line on genuine, material risk and stand behind it with management, the Board and regulators.
- Certifications such as CISSP, CISM, CRISC and / or ISO 27001 Lead Auditor / Implementer.
- Strong command of security frameworks (ISO 27001, NIST, CIS) and incident response; working knowledge of the Credit Bureaus Act 2015 and SBP regulations an advantage