Our client Confidential is hiring a Head of Information Security in Lahore.
Role Purpose
Set and independently assure company’s information security, risk and compliance posture as a business enabler — protecting the bureau’s data and the trust of ~42 million borrowers and 174 member institutions, while finding the safe, defensible path to “yes” so the business can innovate and grow. The role owns the relationship with the State Bank of Pakistan on security and risk audits, and is deliberately independent of IT operations.
Key Tasks and Responsibilities
Strategy & Business-Enabling Risk Posture
- Set the vision and strategic direction for the information security, risk and compliance programme, aligned to recognised standards (ISO 27001, NIST, CIS).
- Operate as a business enabler, not a blocker: take a risk‑based, pragmatic stance that supports product innovation and speed‑to‑market. Where a request carries risk, propose the controlled path to proceed rather than defaulting to “no.”
- Own and maintain the enterprise risk register and key risk indicators; make risk visible and decision‑ready for management and the Board.
Regulatory Audit & Compliance
- Own the State Bank of Pakistan relationship for security and risk: lead SBP inspections and risk audits end‑to‑end — preparation, evidence, response, and timely closure of findings.
- Lead broader compliance activities and external audits.
- Ensure compliance with the Credit Bureaus Act 2015, applicable SBP prudential and IT regulations, and data‑protection obligations for borrower PII.
Governance, Framework & Controls
- Design and maintain the information security policy, framework, standards and controls; govern their implementation and independently assure their effectiveness.
- Drive relevant certifications (e.g. ISO 27001) as a mark of best‑in‑class posture and an asset to the IPO story.
Threat, Incident & Resilience
- Plan and manage cyber‑threat and incident response to minimise business impact; run monitoring / SIEM / SOAR, breach investigation and breach reporting.
- Assure business continuity and disaster recovery from a risk and resilience lens, in partnership with the Head of IT & Infrastructure.
- Own the security tooling strategy (SIEM, SOAR, firewalls, encryption, DLP) — specifying what the business needs, with IT implementing.
Assurance, Third Parties & Culture
- Run VAPT of company's infrastructure and the mobile app; track remediation through to closure.
- Manage third‑party and vendor security risk across member institutions, fintech partners and cloud / technology vendors.
- Work with system owners to keep all systems compliant with security requirements; build an enterprise‑wide security awareness culture, including staff training.
- Report the security and risk posture to the CEO, Management, Board and Board Committees.
Key Performance Indicators
- SBP audit outcomes: findings raised, and percentage closed within agreed timelines.
- Risk register health: KRIs within tolerance and open high risks trending down.
- Security incident performance: number and severity of incidents, mean time to detect and respond, and breaches.
- VAPT remediation: percentage closed within SLA by severity.
- Certification progress and maintenance (e.g. ISO 27001).
- Control effectiveness and assurance / audit pass rate.
- Third‑party security risk assessments completed.
- Security awareness: training completion rate and phishing‑simulation results.
- Enablement: turnaround time on security reviews and requests — so the “business enabler” mandate is measured, not just stated.
Person Specification
- 15+ years in information security, risk and compliance — the depth that comes at senior level — with experience in a regulated financial‑services or data‑sensitive environment.
- Demonstrated track record managing regulator audits — SBP experience strongly preferred (or a comparable central‑bank / financial regulator).
- A pragmatic, business‑minded security leader who enables innovation while managing risk — evidence of saying “here’s how we do this safely,” not just “no.”
- Not a push‑over: able to hold the line on genuine, material risk and stand behind it with management, the Board and regulators.
- Certifications such as CISSP, CISM, CRISC and / or ISO 27001 Lead Auditor / Implementer.
- Strong command of security frameworks (ISO 27001, NIST, CIS) and incident response; working knowledge of the Credit Bureaus Act 2015 and SBP regulations an advantage