IT GRC Specialist

Sukuk Capital | صكوك المالية

Lahore

On-site

PKR 900,000 - 1,500,000

Full time

8 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Annual Increment
Performance Bonus
Provident Fund
Medical Coverage
Social Insurance
Paid Leaves
Leave Encashment
Paid Certifications
Engagement Activities
Reward & Recognition
Corporate Gifts
Annual Tour
Team Hangouts
Collaborative Culture

Job summary

Sukuk Technologies in Lahore, Pakistan is seeking an IT Governance, Risk & Compliance (IT GRC) Specialist with around 3–5 years of experience to lead IT governance, risk management, and controls across applications, infrastructure, and vendors.

You will implement IT policies, coordinate internal and external audits, maintain ITGCs, and report KPIs to CTO and governance committees. This role focuses on IT GRC rather than cybersecurity operations.

Qualifications

  • Bachelor’s degree in IT/CS/IS; 3–5 years in IT Governance, IT Risk, IT Audit, IT Controls, or ITSM.
  • ISO/IEC 38500, ISO/IEC 20000 or SAMA knowledge preferred.

Responsibilities

  • Implement and continuously improve the IT Governance Framework.
  • Establish and maintain IT Risk Management Framework and IT Risk Register.
  • Develop, review, and maintain IT policies, standards, SOPs, and controls.
  • Establish and assess IT General Controls (ITGC) and coordinate remediation.
  • Coordinate internal and external IT audits and ensure timely closure of findings.
  • Govern ITSM processes based on ITIL/ISO 20000; monitor SLAs and capacity.
  • Oversee governance of third‑party tech vendors, BCP/DR readiness.
  • Develop and report IT governance KPIs/KRIs and dashboards to CTO and committees.

Skills

IT Governance
IT Risk
IT Audit
IT Controls
IT Service Management

Education

Bachelor's degree in IT / CS / IS

Job description

Job Description

Sukuk Technologies is looking for an IT Governance, Risk & Compliance (IT GRC) Specialist with around 03-05 years of relevant experience.

Key Responsibilities
  • Implement, and continuously improve the IT Governance Framework,
  • Establish and maintain the IT Risk Management Framework and IT Risk Register; identify, assess, monitor, and report technology risks across applications, infrastructure, cloud, databases, third parties, availability, capacity, and technology lifecycle.
  • Develop, review, and maintain IT policies, standards, SOPs, and controls covering areas such as change/release management, incident/problem management, SDLC, access governance, backup and recovery, asset management, vendor management, and IT operations.
  • Establish and assess IT General Controls (ITGC), identify control gaps, coordinate remediation with IT teams, maintain supporting evidence, and ensure appropriate segregation of duties.
  • Coordinate internal and external IT audits, including evidence collection, audit readiness, management responses, tracking of findings, remediation actions, ownership, and closure deadlines.
  • Govern and monitor IT Service Management (ITSM) processes based on ITIL/ISO 20000 principles, including incident, problem, change, service request, SLA, capacity, availability, and continual service improvement.
  • Oversee governance of third-party technology vendors, business continuity and disaster recovery.
  • Develop and report IT governance KPIs/KRIs and management dashboards covering technology risks, audit findings, controls, SLA performance, system availability, major incidents, changes, vendor performance, and BCP/DR readiness to the CTO and relevant governance committees.
Qualifications & Preferred Certifications
  • Bachelor’s degree in Information Technology, Computer Science, Information Systems, or a related discipline, with 3–5 years of relevant experience in IT Governance, IT Risk, IT Audit, IT Controls, or IT Service Management.
  • Preferred certifications knowledge: SAMA, ISO/IEC 38500, and ISO/IEC 20000.
Role Focus

This is an IT Governance, Risk & Compliance role, not a Cybersecurity GRC role. Cybersecurity-specific activities such as SOC operations, vulnerability management, penetration testing, SIEM, security architecture, threat management, and ownership of cybersecurity controls remain with the Cybersecurity function.

What we offer
  • Annual Increment
  • Annual Performance Bonus
  • Provident Fund
  • Medical OPD/IPD/Maternity
  • Social Insurance
  • Paid Leaves
  • Leave Encashment
  • Paid Certifications
  • EngagementActivities
  • Reward & Recognition
  • Corporate Gifts
  • Annual Tour
  • Team Hangouts
  • Collaborative & Fostering Culture
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT GRC Specialist
IT GRC Specialist

Sukuk Capital • Lahore Cant

On-site
PKR 1,800,000 - 3,000,000
Annual Increment
Annual Performance Bonus
Provident Fund
+11
IT GRC Specialist
IT GRC Specialist

Sukuk Technologies • Lahore

On-site
PKR 1,200,000 - 2,000,000
Annual Increment
Annual Performance Bonus
Provident Fund
+7
IT GRC Specialist
IT GRC Specialist

Sukuk Capital • Lahore

On-site
PKR 1,800,000 - 3,000,000
Annual Increment
Annual Performance Bonus
Provident Fund
+11
IT GRC Specialist: Governance, Risk & Compliance
IT GRC Specialist: Governance, Risk & Compliance

Sukuk Capital • Lahore Cant

On-site
PKR 1,800,000 - 3,000,000
Annual Increment
Annual Performance Bonus
Provident Fund
+11
IT GRC Specialist - Governance, Risk & Compliance Leader
IT GRC Specialist - Governance, Risk & Compliance Leader

Sukuk Technologies • Lahore

On-site
PKR 1,200,000 - 2,000,000
Annual Increment
Annual Performance Bonus
Provident Fund
+7
IT GRC Specialist: Drive Governance, Risk & Compliance
IT GRC Specialist: Drive Governance, Risk & Compliance

Sukuk Capital | صكوك المالية • Lahore

On-site
PKR 900,000 - 1,500,000
Annual Increment
Performance Bonus
Provident Fund
+11
GRC Analyst
GRC Analyst

TheGlobalCB • Karachi Division

On-site
Competitive salary
Performance bonuses
Sponsored trainings & international certifications
+1
GRC Analyst
GRC Analyst

Global CB - EMAP • Karachi Division

On-site
PKR 600,000 - 800,000
Competitive salary and performance bonuses
Sponsored trainings & international certifications
Travel opportunities (local & international)
Governance, Risk & Compliance (GRC) Expert
Governance, Risk & Compliance (GRC) Expert

Leading Edge • Karachi Division

On-site
SENIOR GRC LEAD | Remote
SENIOR GRC LEAD | Remote

Leading Edge • Islamabad

Remote
PKR 1,200,000 - 2,000,000