Information Security Governance Manager

HugoBank

Karachi Division

On-site

PKR 1,800,000 - 3,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

HugoBank seeks an experienced Information Security Governance Manager to lead the GRC function and strengthen the bank’s information security governance framework. You will drive regulatory compliance, develop security policies, and coordinate audits to ensure a robust security posture.

The role requires 4–6 years in information security/GRC, with banking/fintech experience, ISO 27001, PCI DSS familiarity, and cloud/AI governance knowledge. A strong leadership presence is essential.

Qualifications

  • Bachelor’s degree in Computer Science, Information Technology, Cyber Security, or related discipline (Master’s degree preferred).
  • 4–6 years in Information Security, Cyber Security, IT Risk, or GRC; 4+ years in governance within banking/fintech/digital bank.
  • Hands-on ISO/IEC 27001 ISMS implementation/maintenance experience.
  • Experience with PCI DSS compliance and security assessments.
  • Strong understanding of digital banking regulations, governance, and regulatory compliance.
  • Experience in Cloud Security Governance (AWS/Azure/GCP) and cloud security frameworks.
  • Knowledge of AI Security, AI governance, and risks with Generative AI.
  • Familiarity with NIST CSF, CIS Controls, Zero Trust, data protection, and third‑party risk management.
  • Experience coordinating regulatory inspections, audits, and certification assessments.
  • Certifications such as CISM, CISA, CRISC, ISO/IEC 27001 Lead Implementer/Auditor, CISSP, CCSP, PCIP, or PMP are a plus.

Responsibilities

  • Develop and continuously improve the Information Security Governance Framework.
  • Establish policies, standards, procedures, and guidelines for information security.
  • Ensure compliance with regulatory requirements and industry best practices.
  • Lead GRC activities including risk assessments and risk reporting to executives.
  • Coordinate internal, external, regulatory, and certification audits and remediation.
  • Manage third‑party security risk assessments and vendor security reviews.
  • Track security KPIs/KRIs and prepare dashboards for senior management and Board committees.
  • Promote security awareness and a strong security culture.
  • Support cloud security, AI governance, and secure adoption of emerging technologies.

Skills

Leadership
Stakeholder mgmt
Regulatory compliance
Risk assessment
GRC
ISO 27001
Cloud security governance
NIST CSF
AI governance
Audits
Vendor risk

Education

Bachelor’s in CS/IT/Cyber
Master’s degree preferred

Tools

ISO 27001 ISMS
PCI DSS

Job description

We are seeking an experienced Information Security Governance Manager to lead our Governance, Risk, and Compliance (GRC) function and strengthen the bank's Information Security Governance Framework. This role is responsible for driving regulatory compliance, developing security policies and standards, managing enterprise cyber risks, coordinating audits, and ensuring the bank maintains a robust and resilient security posture.

Key Responsibilities
  • Develop, implement, and continuously improve the Information Security Governance Framework
  • Establish and maintain information security policies, standards, procedures, and guidelines
  • Ensure compliance with applicable regulatory requirements and industry best practices
  • Lead Governance, Risk & Compliance (GRC) activities, including enterprise security risk assessments and risk reporting
  • Coordinate internal, external, regulatory, and certification audits, ensuring timely remediation of findings
  • Manage third-party security risk assessments and vendor security reviews
  • Track security KPIs, KRIs, compliance metrics, and prepare executive dashboards for senior management and Board committees
  • Promote security awareness and foster a strong security culture across the organization
  • Support enterprise initiatives involving cloud security, AI governance, and secure adoption of emerging technologies
Requirements
Qualifications & Experience
  • Bachelor's degree in Computer Science, Information Technology, Cyber Security, or a related discipline (Master's degree preferred)
  • 4-6 years of experience in Information Security, Cyber Security, IT Risk, or Governance, Risk & Compliance (GRC), including 4+ years in a governance role within banking, financial services, fintech, or a digital bank
  • Hands‑on experience implementing and maintaining ISO/IEC 27001 Information Security Management System (ISMS)
  • Experience managing or supporting PCI DSS compliance and security assessments
  • Strong understanding of Digital Banking regulations, information security governance, enterprise risk management, and regulatory compliance
  • Experience with Cloud Security Governance (AWS, Azure, or Google Cloud Platform) and cloud security frameworks
  • Knowledge of AI Security, AI governance, and managing security risks associated with Generative AI and emerging technologies
  • Familiarity with NIST Cybersecurity Framework (CSF), CIS Controls, Zero Trust Architecture, data protection, and third‑party risk management
  • Experience coordinating regulatory inspections, security audits, certification audits, and compliance assessments
  • Professional certifications such as CISM, CISA, CRISC, ISO/IEC 27001 Lead Implementer/Lead Auditor, CISSP, CCSP, PCI Professional (PCIP), or PMP will be an added advantage
What We're Looking For
  • Strong leadership, communication, and stakeholder management skills
  • Excellent analytical, problem‑solving, and decision‑making abilities
  • Experience engaging with regulators, auditors, executive management, and Board committees
  • Ability to translate regulatory and business requirements into practical, risk‑based security controls
  • Passion for driving security governance, operational resilience, and continuous improvement in a fast‑paced digital banking environment
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Governance Manager
Information Security Governance Manager

Hugo Bank • Karachi Division

On-site
PKR 1,800,000 - 3,000,000
InfoSec Governance & Risk Lead (Banking)
InfoSec Governance & Risk Lead (Banking)

HugoBank • Karachi Division

On-site
PKR 1,800,000 - 3,500,000
Governance, Risk & Compliance (GRC) Lead – Information Security & Risk
Governance, Risk & Compliance (GRC) Lead – Information Security & Risk

iCareManager • Lahore

On-site
Senior Governance, Risk, and Compliance (GRC) Analyst
Senior Governance, Risk, and Compliance (GRC) Analyst

PsychPlus • Karachi Division

On-site
PKR 1,800,000 - 2,900,000
GRC Analyst
GRC Analyst

TheGlobalCB • Karachi Division

On-site
Competitive salary
Performance bonuses
Sponsored trainings & international certifications
+1
Senior Consultant - GRC
Senior Consultant - GRC

Risk Associates Pvt. Ltd. • Karachi Division

On-site
Information Security Engineer
Information Security Engineer

Tkxel • Pakistan

On-site
PKR 2,200,000 - 3,200,000
Information Security Manager
Information Security Manager

Arpatech (Pvt) Ltd • Karachi Division

On-site
Risk Analyst
Risk Analyst

i2c Inc • Lahore

On-site
PKR 150,000 - 210,000
Information Security Strategy Lead: GRC, SOC & Risk
Information Security Strategy Lead: GRC, SOC & Risk

Arpatech (Pvt) Ltd • Karachi Division

On-site