Head of Information Security - Confidential

Taraki

Lahore

On-site

PKR 8,000,000 - 16,000,000

Full time

13 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Confidential is seeking a Head of Information Security in Lahore to lead the company’s security, risk and compliance posture. The role partners with executives to enable product innovation while protecting sensitive borrower data and ensuring SBP audit readiness.

You will own enterprise risk management, drive ISO 27001 and other certifications, and oversee incident response, continuity planning and vendor security risk. This role reports to the CEO and interacts with the Board.

Qualifications

  • 15+ years in information security, risk and compliance in regulated environments.
  • Track record managing regulator audits (SBP or equivalent).
  • Ability to enable business through risk-based security decisions.
  • Must stand firm on material risk and governance.
  • Certifications and strong security framework knowledge (ISO27001/NIST/CIS).

Responsibilities

  • Lead security strategy and risk posture aligned to ISO27001/NIST/CIS.
  • Own SBP relationship for security audits and inspections.
  • Develop and maintain security policies, controls and governance.
  • Plan incident response, disaster recovery, and resilience.
  • Manage third-party security risk and enable secure innovation.

Skills

Information security leadership
Regulatory risk management
Business-minded security leadership
Threat and incident response
Communication with regulators

Education

CISSP, CISM, CRISC and ISO 27001 Lead Auditor/Implementer certifications

Tools

SIEM
SOAR
Firewalls
Encryption
DLP

Job description

Our client Confidential is hiring a Head of Information Security in Lahore.

Role Purpose

Set and independently assure company’s information security, risk and compliance posture as a business enabler — protecting the bureau’s data and the trust of ~42 million borrowers and 174 member institutions, while finding the safe, defensible path to “yes” so the business can innovate and grow. The role owns the relationship with the State Bank of Pakistan on security and risk audits, and is deliberately independent of IT operations.

Key Tasks and Responsibilities
Strategy & Business-Enabling Risk Posture
  • Set the vision and strategic direction for the information security, risk and compliance programme, aligned to recognised standards (ISO 27001, NIST, CIS).
  • Operate as a business enabler, not a blocker: take a risk‑based, pragmatic stance that supports product innovation and speed‑to‑market. Where a request carries risk, propose the controlled path to proceed rather than defaulting to “no.”
  • Own and maintain the enterprise risk register and key risk indicators; make risk visible and decision‑ready for management and the Board.
Regulatory Audit & Compliance
  • Own the State Bank of Pakistan relationship for security and risk: lead SBP inspections and risk audits end‑to‑end — preparation, evidence, response, and timely closure of findings.
  • Lead broader compliance activities and external audits.
  • Ensure compliance with the Credit Bureaus Act 2015, applicable SBP prudential and IT regulations, and data‑protection obligations for borrower PII.
Governance, Framework & Controls
  • Design and maintain the information security policy, framework, standards and controls; govern their implementation and independently assure their effectiveness.
  • Drive relevant certifications (e.g. ISO 27001) as a mark of best‑in‑class posture and an asset to the IPO story.
Threat, Incident & Resilience
  • Plan and manage cyber‑threat and incident response to minimise business impact; run monitoring / SIEM / SOAR, breach investigation and breach reporting.
  • Assure business continuity and disaster recovery from a risk and resilience lens, in partnership with the Head of IT & Infrastructure.
  • Own the security tooling strategy (SIEM, SOAR, firewalls, encryption, DLP) — specifying what the business needs, with IT implementing.
Assurance, Third Parties & Culture
  • Run VAPT of company's infrastructure and the mobile app; track remediation through to closure.
  • Manage third‑party and vendor security risk across member institutions, fintech partners and cloud / technology vendors.
  • Work with system owners to keep all systems compliant with security requirements; build an enterprise‑wide security awareness culture, including staff training.
  • Report the security and risk posture to the CEO, Management, Board and Board Committees.
Key Performance Indicators
  • SBP audit outcomes: findings raised, and percentage closed within agreed timelines.
  • Risk register health: KRIs within tolerance and open high risks trending down.
  • Security incident performance: number and severity of incidents, mean time to detect and respond, and breaches.
  • VAPT remediation: percentage closed within SLA by severity.
  • Certification progress and maintenance (e.g. ISO 27001).
  • Control effectiveness and assurance / audit pass rate.
  • Third‑party security risk assessments completed.
  • Security awareness: training completion rate and phishing‑simulation results.
  • Enablement: turnaround time on security reviews and requests — so the “business enabler” mandate is measured, not just stated.
Person Specification
  • 15+ years in information security, risk and compliance — the depth that comes at senior level — with experience in a regulated financial‑services or data‑sensitive environment.
  • Demonstrated track record managing regulator audits — SBP experience strongly preferred (or a comparable central‑bank / financial regulator).
  • A pragmatic, business‑minded security leader who enables innovation while managing risk — evidence of saying “here’s how we do this safely,” not just “no.”
  • Not a push‑over: able to hold the line on genuine, material risk and stand behind it with management, the Board and regulators.
  • Certifications such as CISSP, CISM, CRISC and / or ISO 27001 Lead Auditor / Implementer.
  • Strong command of security frameworks (ISO 27001, NIST, CIS) and incident response; working knowledge of the Credit Bureaus Act 2015 and SBP regulations an advantage
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Head of Information Security - Confidential
Head of Information Security - Confidential

Brickstech • Lahore

On-site
PKR 3,000,000 - 6,000,000
Chief Information Security & Risk Officer
Chief Information Security & Risk Officer

Taraki • Lahore

On-site
PKR 8,000,000 - 16,000,000
Chief Information Security & Risk Leader
Chief Information Security & Risk Leader

Brickstech • Lahore

On-site
PKR 3,000,000 - 6,000,000
Head of International IS Privacy Research and Innovation
Head of International IS Privacy Research and Innovation

Hblpeople • Karachi Division

On-site
PKR 6,000,000 - 12,000,000
Head of International IS Privacy Research and Innovation
Head of International IS Privacy Research and Innovation

HBL People • Pakistan

On-site
PKR 9,000,000 - 15,000,000
SOC Manager
SOC Manager

Mobilink Microfinance Bank Ltd • Gadap Town

On-site
PKR 2,500,000 - 3,500,000
Head Information Security Risk Management
Head Information Security Risk Management

ThePakEdu • Karachi Division

On-site
PKR 2,031,000 - 2,433,000
Head of Cyber Security Research and Innovation
Head of Cyber Security Research and Innovation

Hblpeople • Karachi Division

On-site
PKR 19,482,000 - 25,049,000
Manager Security
Manager Security

hrsi • Islamabad

On-site
PKR 1,800,000 - 3,200,000
Head of Cyber Security Research and Innovation
Head of Cyber Security Research and Innovation

HBL People • Pakistan

On-site
PKR 6,000,000 - 9,000,000