Pak-Arab Refinery Limited
IT/IS Governance Analyst (Contractual)
Pak-Arab Refinery Limited (PARCO)
Pak-Arab Refinery Limited (PARCO), an integrated energy conglomerate, is a Joint Venture between Pakistan and Emirate of Abu Dhabi. PARCO owns and operates Pakistan’s most modern refinery, over 2,000 kms of pipeline network, strategic storage facilities and marketing operations. The Company has Joint Ventures with renowned international companies and is continually following an aggressive growth strategy with planned expansions, acquisitions, and penetration into new markets.
About The Role
The role is responsible for supporting organization’s IT/IS Governance, Risk and Compliance (GRC) framework. Key areas include ISO/IEC 27001:2022 compliance, IT/IS risk management, audit coordination, policy governance, cybersecurity awareness, remediation monitoring, and management reporting.
Qualification and Competencies
- Bachelor’s degree in Information Security, Computer Science, IT, or a related field.
- Strong analytical, documentation, and report-writing capabilities.
- Effective communication, coordination, and stakeholder-management skills.
- Ability to collaborate with IT, business, audit, risk, and other cross-functional stakeholders.
- Ability to interpret regulatory, standards-based, and organizational requirements and assess their impact.
- Relevant certifications such as ISO/IEC 27001, CISA, CRISC, CISM, or equivalent will be preferred.
Experience
- 5-8 years of relevant experience in Information Security Governance, Risk and Compliance, IT Audit, or related fields.
- Hands-on experience in Information Security GRC.
- Practical experience with ISO/IEC 27001-based Information Security Management Systems.
- Experience in conducting IT/IS risk assessments, maintaining risk registers, and monitoring risk treatment plans.
- Experience in coordinating internal / external audits and managing audit observations through closure.
- Experience in developing and reviewing Information Security policies, standards, procedures, guidelines, and governance documentation.
- Experience in planning and coordinating cybersecurity awareness programs, phishing simulations, campaigns, and employee training.
- Experience in preparing information security dashboards and management-level reports.
- Experience in oil and gas, financial services, technology, telecommunications, critical infrastructure, or another regulated industry will be an advantage.
Job Responsibilities
- Monitor compliance with information security policies, ISO/IEC 27001:2022, and applicable legal, regulatory, and contractual requirements.
- Conduct IT/IS risk assessments, maintain the risk register and monitor risk treatment plans.
- Coordinate internal and external information security audits, including evidence collection, stakeholder engagement, and follow-up.
- Track audit observations, nonconformities, corrective actions, and remediation plans through timely closure.
- Develop, review, and maintain information security policies, standards, procedures, and other governance documentation.
- Plan and deliver cybersecurity awareness activities, including training sessions, communications, and phishing simulations.
- Prepare information security dashboards and reports covering risks, compliance, audits, remediation, awareness, and related performance indicators.
- Monitor changes in cybersecurity standards, regulations, and industry Blackjack good practices and assess their applicability to the organization.
Specific Skills
- Sound knowledge of Information Security Governance, Risk and Compliance principles and practices.
- Good understanding of ISO/IEC 27001:2022, including ISMS implementation, controls, risk management, and continual improvement.
- Knowledge of information security risk assessment methodologies, risk registers, and risk treatment processes.
- Understanding of audit processes, control assessments, evidence requirements, and remediation monitoring.
- Ability to develop and maintain clear, practical, and effective information security policies and procedures.
- Knowledge of cybersecurity awareness programs, phishing simulations, and related performance indicators.
- Ability to prepare and present meaningful security metrics, dashboards, and reports for management.
- Familiarity with GRC platforms/tools will be preferred.
Locations
- Corporate Headquarters – Karachi
PARCO is an equal opportunity employer. We value diversity and encourage candidates from all backgrounds to apply. Our commitment to a conducive work environment is designed to attract and nurture top talent.