Head of Information Security - TPL Insurance

PMCL-JAZZ

Karachi Division

On-site

PKR 6,000,000 - 10,000,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

TPL Insurance is seeking a VP-level Head of Information Security to lead risk management, governance, and security controls across networks, apps, and infrastructure in Karachi. You will drive ISO 27001 certification, policy design, and incident response, coordinating with developers and admins to remediate findings.

The role demands 10+ years for Information Security, strong certifications, and hands-on leadership in security architecture and operations.

Qualifications

  • Bachelor's degree in computer science, information security, or related field.
  • At least 10 years of experience in information security, technology governance, VAPT or IT Security.
  • Certifications or training in CISM, CGEIT, ISO 27001 LI/LA, CEH, OSCP, CoBIT, NIST cyber security framework.
  • Knowledgeable about information security management, IS governance, compliance principles, laws, rules and regulations, architecture, design, operations, controls, solutions, and service orchestration.
  • Strong problem-solving and analytical skills, with the ability to work independently and effectively meet deadlines.
  • Collaborative team player with the ability to investigate and resolve security incidents effectively.

Responsibilities

  • Evaluates risks and develops security standards, procedures, and controls to manage risks.
  • Improves security positioning through process improvement, policy, automation, and the continuous evolution of capabilities.
  • Implements processes such as GRC (Governance Risk & Compliance) to automate and continuously monitor Information Security controls, exceptions, risk, testing. Develops reporting metrics, dashboards and evidence artifacts.
  • Lead the end-to-end implementation and certification process for ISO 27001.
  • Conduct regular risk assessments and treat identified information security risk, manage internal and external ISO 27001 audits, addressing findings and non-conformities.
  • Develop, maintain security testing plans automate penetration and other security testing on networks, systems and applications.
  • Assist with third-party IT vulnerability assessments and Penetration testing and also remediate the vulnerabilities with the communication to concern departments and their owners.
  • Act as a source of direction, training, and guidance for less experienced staff.
  • Documents and reports control failures and gaps to stakeholders.
  • Provides remediation guidance and prepares management reports to track remediation activities.
  • Consult with application developers, systems administrators, and management to demonstrate security testing results, explain the threat presented by the results, and consult on remediation.
  • Deliver the annual penetration testing schedule and conducting awareness campaigns to ensure proper budgeting by business lines for annual tests.
  • Performs other related duties as assigned

Skills

Information security
Risk management
GRC
Security governance

Education

Bachelor's degree in CS/Information Security

Tools

ISO 27001
Penetration testing

Job description

Position Title: Head of Information Security - TPL Insurance

Grade: VP

Location: Karachi

Last date to apply: 18th September, 2026

What is Head of Information Security ?

The purpose of the role is to collaborate on designing network and infrastructure security and monitor for effective security control in place. This includes managing the IT process for effectiveness and efficiency on addressing security risks. The incumbent would be accountable for risk management and mitigation related to information security, physical security, business continuity planning, crisis management, integrity and compliance.

What does “Head of Information Security do ?

  • Evaluates risks and develops security standards, procedures, and controls to manage risks.
  • Improves security positioning through process improvement, policy, automation, and the continuous evolution of capabilities.
  • Implements processes such as GRC (Governance Risk & Compliance) to automate and continuously monitor Information Security controls, exceptions, risk, testing. Develops reporting metrics, dashboards and evidence artifacts.
  • Lead the end-to-end implementation and certification process for ISO 27001.
  • Conduct regular risk assessments and treat identified information security risk, manage internal and external ISO 27001 audits, addressing findings and non-conformities.
  • Develop, maintain security testing plans automate penetration and other security testing on networks, systems and applications.
  • Assist with third-party IT vulnerability assessments and Penetration testing and also remediate the vulnerabilities with the communication to concern departments and their owners.
  • Act as a source of direction, training, and guidance for less experienced staff.
  • Documents and reports control failures and gaps to stakeholders.
  • Provides remediation guidance and prepares management reports to track remediation activities.
  • Consult with application developers, systems administrators, and management to demonstrate security testing results, explain the threat presented by the results, and consult on remediation.
  • Deliver the annual penetration testing schedule and conducting awareness campaigns to ensure proper budgeting by business lines for annual tests.
  • Performs other related duties as assignedRequirement.

What are we looking for and what does it require to be Head of Information Security ?

  • Bachelors in computer science, information security, or related field.
  • At least 10 years of Experience in information security, technology governance, VAPT or IT Security.
  • Certifications or acquired training in CISM, CGEIT, ISO 27001 LI/LA, CEH, OSCP, CoBIT, NIST cyber security framework.
  • Knowledgeable about information security management, IS governance, compliance principles, practices, laws, rules and regulations, architecture, design, operations, controls, solutions, and service orchestration.
  • Strong problem-solving and analytical skills, with the ability to work independently and effectively meet deadlines.
  • Collaborative team player with the ability to investigate and resolve security incidents effectively.

Why Join TPL Insurance ?

TPL Insurance is an AA-rated insurer and one of Pakistan’s leading InsurTech companies, combining digital innovation with a strong retail, dealership, B2B and B2B2C network to make insurance simpler and more accessible. With a diverse portfolio spanning Motor, Health, Property, Travel, Marine and other general insurance solutions, TPL Insurance continues to challenge traditional insurance through customer-centric products, technology and strategic partnerships. Our inclusion in Jazz World gives our teams the opportunity to build innovative insurance solutions that reach millions of customers at scale. At TPL Insurance, we foster an agile, collaborative and growth-oriented culture where people are encouraged to take ownership, bring new ideas to the table and create meaningful impact.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Head of IT PMO - TPL Insurance
Head of IT PMO - TPL Insurance

PMCL-JAZZ • Karachi Division

On-site
PKR 5,000,000 - 9,000,000
Penetration Tester - TPL Insurance
Penetration Tester - TPL Insurance

PMCL-JAZZ • Karachi Division

On-site
PKR 2,000,000 - 3,500,000
VP, Information Security & Risk Leadership
VP, Information Security & Risk Leadership

PMCL-JAZZ • Karachi Division

On-site
PKR 6,000,000 - 10,000,000
Head of IT PMO - Drive InsurTech Delivery
Head of IT PMO - Drive InsurTech Delivery

PMCL-JAZZ • Karachi Division

On-site
PKR 5,000,000 - 9,000,000
Business Manager - Cybersecurity Solutions
Business Manager - Cybersecurity Solutions

Trilliuminfosec • Karachi Division

On-site
PKR 1,800,000 - 3,600,000
Head of International IS Privacy Research and Innovation
Head of International IS Privacy Research and Innovation

Hblpeople • Karachi Division

On-site
PKR 6,000,000 - 12,000,000
Cybersecurity Support Engineer
Cybersecurity Support Engineer

TISS • Saddar

On-site
PKR 1,339,000 - 2,009,000
Senior Penetration Tester – Offensive Security Specialist
Senior Penetration Tester – Offensive Security Specialist

JazzWorld • Karachi Division

On-site
PKR 1,800,000 - 3,200,000
Information Security Officer
Information Security Officer

Translation Empire PK • Saddar

On-site
PKR 1,004,000 - 1,674,000
Information Security Officer
Information Security Officer

Translation Empire • Saddar

On-site
PKR 1,200,000 - 2,400,000