IT/IS Governance Analyst

PARCO - Pak-Arab Refinery Limited

Karachi Division

On-site

PKR 2,200,000 - 3,200,000

Part time

27 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

PARCO - Pak-Arab Refinery Limited is seeking a contractual IT/IS Governance Analyst to support the GRC framework, risk management, policy governance, and audit coordination. The role emphasizes ISO/IEC 27001:2022 compliance, cybersecurity awareness, and management reporting.

The candidate will collaborate with IT, business, and risk teams to ensure regulatory alignment, effective controls, and timely remediation.

Qualifications

  • Bachelor’s degree in Information Security, Computer Science, IT, or related field.
  • Strong analytical, documentation, and report-writing capabilities.
  • Effective communication, coordination, and stakeholder-management skills.
  • Ability to collaborate with IT, business, audit, risk, and other cross-functional stakeholders.
  • Ability to interpret regulatory, standards-based, and organizational requirements and assess their impact.
  • Relevant certifications such as ISO/IEC 27001, CISA, CRISC, CISM, or equivalent preferred.

Responsibilities

  • Monitor compliance with information security policies, ISO/IEC 27001:2022, and applicable requirements.
  • Conduct IT/IS risk assessments, maintain risk register, and monitor risk treatment plans.
  • Coordinate internal and external information security audits, including evidence collection and follow-up.
  • Track audit observations, nonconformities, corrective actions, and remediation plans through closure.
  • Develop, review, and maintain information security policies, standards, procedures, and governance docs.
  • Plan and deliver cybersecurity awareness activities, trainings, and phishing simulations.
  • Prepare information security dashboards and reports covering risks, compliance, audits, and remediation.
  • Monitor changes in cybersecurity standards, regulations, and industry best practices.

Skills

Analytical thinking
Documentation
Report writing
Communication
Stakeholder management
Stakeholder coordination
Regulatory interpretation
ISO/IEC 27001 / CISA / CRISC / CISM
GRC platforms/tools

Education

Bachelor’s degree in Information Security / CS / IT

Tools

GRC platforms/tools

Job description

Pak-Arab Refinery Limited

IT/IS Governance Analyst (Contractual)

Pak-Arab Refinery Limited (PARCO), an integrated energy conglomerate, is a Joint Venture between Pakistan and Emirate of Abu Dhabi. PARCO owns and operates Pakistan’s most modern refinery, over 2,000 kms of pipeline network, strategic storage facilities and marketing operations. The Company has Joint Ventures with renowned international companies and is continually following an aggressive growth strategy with planned expansions, acquisitions, and penetration into new markets.

PARCO is seeking applications for the position of IT/IS Governance Analyst (Contractual).

About The Role

The role is responsible for supporting organization’s IT/IS Governance, Risk and Compliance (GRC) framework. Key areas include ISO/IEC 27001:2022 compliance, IT/IS risk management, audit coordination, policy governance, cybersecurity awareness, remediation monitoring, and management reporting.

Qualification and Competencies
  • Bachelor’s degree in Information Security, Computer Science, IT, or a related field.
  • Strong analytical, documentation, and report-writing capabilities.
  • Effective communication, coordination, and stakeholder-management skills.
  • Ability to collaborate with IT, business, audit, risk, and other cross-functional stakeholders.
  • Ability to interpret regulatory, standards-based, and organizational requirements and assess their impact.
  • Relevant certifications such as ISO/IEC 27001, CISA, CRISC, CISM, or equivalent will be preferred.
Experience
  • 5-8 years of relevant experience in Information Security Governance, Risk and Compliance, IT Audit, or related fields.
  • Hands-on experience in Information Security GRC.
  • Practical experience with ISO/IEC 27001-based Information Security Management Systems.
  • Experience in conducting IT/IS risk assessments, maintaining risk registers, and monitoring risk treatment plans.
  • Experience in coordinating internal / external audits and managing audit observations through closure.
  • Experience in developing and reviewing Information Security policies, standards, procedures, guidelines, and governance documentation.
  • Experience in planning and coordinating cybersecurity awareness programs, phishing simulations, campaigns, and employee training.
  • Experience in preparing information security dashboards and management-level reports.
  • Experience in oil and gas, financial services, technology, telecommunications, critical infrastructure, or another regulated industry will be an advantage.
Job Responsibilities
  • Monitor compliance with information security policies, ISO/IEC 27001:2022, and applicable legal, regulatory, and contractual requirements.
  • Conduct IT/IS risk assessments, maintain the risk register and monitor risk treatment plans.
  • Coordinate internal and external information security audits, including evidence collection, stakeholder engagement, and follow-up.
  • Track audit observations, nonconformities, corrective actions, and remediation plans through timely closure.
  • Develop, review, and maintain information security policies, standards, procedures, and other governance documentation.
  • Plan and deliver cybersecurity awareness activities, including training sessions, communications, and phishing simulations.
  • Prepare information security dashboards and reports covering risks, compliance, audits, remediation, and related performance indicators.
  • Monitor changes in cybersecurity standards, regulations, and industry Blackjack good practices and assess their applicability to the organization..
Specific Skills
  • Sound knowledge of Information Security Governance, Risk and Compliance principles and practices.
  • Good understanding of ISO/IEC 27001:2022, including ISMS implementation, controls, risk management, and continual improvement.
  • Knowledge of information security risk assessment methodologies, risk registers, and risk treatment processes.
  • Understanding of audit processes, control assessments, evidence requirements, and remediation monitoring.
  • Ability to develop and maintain clear, practical, and effective information security policies and procedures.
  • Knowledge of cybersecurity awareness programs, phishing simulations, and related performance indicators.
  • Ability to prepare and present meaningful security metrics, dashboards, and reports for management.
  • Familiarity with GRC platforms/tools will be preferred.
Locations:
  • Corporate Headquarters – Karachi

PARCO is an equal opportunity employer. We value diversity and encourage candidates from all backgrounds to apply. Our commitment to a conducive work environment is designed to attract and nurture top talent.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT/IS Governance Analyst
IT/IS Governance Analyst

PARCO • Karachi Division

On-site
PKR 1,800,000 - 3,200,000
IT/IS Governance & GRC Analyst (ISO 27001)
IT/IS Governance & GRC Analyst (ISO 27001)

PARCO • Karachi Division

On-site
PKR 1,800,000 - 3,200,000
IT SOC Analyst
IT SOC Analyst

PARCO - Pak-Arab Refinery Limited • Karachi Division

On-site
PKR 3,000,000 - 4,000,000
IT SOC Analyst
IT SOC Analyst

PARCO • Karachi Division

On-site
PKR 2,009,000 - 3,348,000
Group Head HR - Transformation & Projects
Group Head HR - Transformation & Projects

PARCO - Pak-Arab Refinery Limited • Karachi Division

On-site
PKR 2,400,000 - 5,400,000
Manager Information Technology (ERP, Retail Systems & Digital Transformation)
Manager Information Technology (ERP, Retail Systems & Digital Transformation)

Parco Pearl Gas • Lahore

On-site
PKR 4,000,000 - 7,000,000
IT SOC Analyst — Threat Hunting & Incident Response
IT SOC Analyst — Threat Hunting & Incident Response

PARCO - Pak-Arab Refinery Limited • Karachi Division

On-site
PKR 3,000,000 - 4,000,000
Deputy Manager Taxation
Deputy Manager Taxation

Parco Pearl Gas • Lahore

On-site
PKR 3,000,000 - 5,400,000
Assistant Maintenance - Filling Plant Adhi
Assistant Maintenance - Filling Plant Adhi

Parco Pearl Gas • Saddar

On-site
PKR 1,200,000 - 2,000,000
Governance, Risk & Compliance (GRC) Expert
Governance, Risk & Compliance (GRC) Expert

Leading Edge • Karachi Division

On-site