Lead Manager – IT and Operational Risks

SSGC LPG Limited

Karachi Division

On-site

PKR 2,500,000 - 6,000,000

Full time

24 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Sui Southern Gas Company Limited is seeking an Engineering candidate with strong risk management and information security experience to implement the Enterprise Risk Management framework across IT and Operations/Technical departments.

Requirements include an engineering degree or equivalent, PEC registration, and experience with ISO 2700X. Certifications like CISA/CRISC/CISSP are preferred; ISO 31000 training is a plus.

Qualifications

  • Engineering degree in Mechanical or Electrical with 9+ years of relevant experience, or BCS with 10+ years of relevant experience.
  • Registration with PEC is mandatory for Engineers.
  • Preferred certifications: CISA, CRISC, CISSP, etc.
  • Training in ISO 31000 on risk management will be a plus.

Responsibilities

  • Establishes and communicates the organization’s Enterprise Risk Management Framework and guidance for ERM maturity.
  • Implements ERM Framework, risk culture and policies; advises Executive Management on risk appetite and limits.
  • Designs and facilitates Enterprise Risk Management methodologies, tools, and techniques across the organization.
  • Monitors enterprise-wide risk assessments and priority risks.
  • Leads system-wide information security risk management and ISO 2700X compliance initiatives.
  • Develops IT risk metrics, BIA, and risk management framework governance.
  • Assesses security controls and risk for IT systems; advises on risk treatment.
  • Leads IT risk compliance programs and regulatory alignment across departments.
  • Coordinates and tracks operational, IT risks and security assessments; maintains documentation.

Skills

Information security
Audit
Risk management
Compliance
Risk consulting
ISO 2700X
ISO 31000

Education

Engineering degree (Mech/Elec)
BCS or equivalent

Job description

Engineering Graduate (Mechanical / Electrical) with at least 9 years of relevant experience.

Or

BCS or equivalent with at least 10 years of relevant experience. Candidate must have at least 04 years of relevant experience as a Functional / Team Lead. Registration with PEC is mandatory for Engineers. Preferred Certifications in CISA, CRISC, CISSP, etc. Training in ISO 31000 on risk management will be a plus.

Responsibilities:
JOB SUMMARY

The purpose of this position is to ensure implementation of the risk management framework at SSGC’s IT and Operational/Technical departments.

JOB RESPONSIBILITIES
  • Establishes and communicates the organization’s Enterprise Risk Management Framework, objectives and direction and provide guidance to achieve the ERM maturity model developed by the company
  • Implements ERM Framework, Risk Culture and Recommends risk management policies, risk appetite and risk limits to Executive Management.
  • Designs, communicates and facilitates the use of appropriate Enterprise Risk Management methodologies, tools and techniques across the organization.
  • Controls enterprise-wide risk assessments and monitors priority risks across the organization.
  • Lead the development / implementation of system-wide risk management function of the information security program to ensure information security risks are identified & monitored
  • Must have knowledge and experience of implementation of Information Security Management Systems based on ISO 2700X
  • Advance the design, delivery, and performance of lT risk metrics and reports including the Business Impact Assessment, lT Risk Management Framework, and the management of configurations and standards
  • Assess, evaluate and make recommendations to management regarding the adequacy of the security controls, risks involved for the organization's information and technology systems
  • Lead the system-wide information security compliance program, ensuring lT activities, processes, and procedures to meet defined requirements, policies and regulations
  • Lead enterprise, network, application, and cloud infrastructure risk assessments while maintaining process and procedural documentation
  • Coordinate and track all Operational, lT Risks, information technology and security related assessments including scope of assessment, parties involved, timelines, and outcomes
  • Provides insight and guidance to IT processes and projects to ensure best practices and security standards are maintained
  • Operate with a high degree of independence with regard to project management activities, including development of project plans and budget/resource estimates
  • Excellent knowledge and experience of information security, audit, risk management, compliance or risk consulting experience
  • Arranges and conducts Risk Workshops for confirmation of the Risk Registers and for identifying risks and mitigation controls of Risks
  • Provides guidance, coordination and subject matter expertise to business functions to ensure the implementation of the agreed risk management strategy.
  • Works with all functional groups to establish, maintains and continuously improve risk management capabilities.
  • Manage relationships with external consultants and supervise work programs.
  • Plan the risk management related awareness amongst SSGC IT and Operation / Technical departments regarding the need and importance of this exercise as well as correct implementation of the program through guided training sessions and/or e-learning modules.
  • Guide the IT function to undertake a thorough information systems risk assessment in order to obtain an understanding of the risks to the availability, integrity and confidentiality of data and systems.
  • Ensure that such risk assessment encompasses all systems, including hardware, software, data, networks and any business processes to identify threats, vulnerabilities, probabilities of occurrence and potential impact.

Ensure that such risk assessment encompasses all systems, including hardware, software, data, networks and any business processes to identify threats, vulnerabilities, probabilities of occurrence and potential impact.

  • Establishes and communicates the organization’s Enterprise Risk Management Framework, objectives and direction and provide guidance to achieve the ERM maturity model developed by the company
  • Implements ERM Framework, Risk Culture and Recommends risk management policies, risk appetite and risk limits to Executive Management.
  • Designs, communicates and facilitates the use of appropriate Enterprise Risk Management methodologies, tools and techniques across the organization.
  • Controls enterprise-wide risk assessments and monitors priority risks across the organization.
  • Lead the development / implementation of system-wide risk management function of the information security program to ensure information security risks are identified & monitored
  • Must have knowledge and experience of implementation of Information Security Management Systems based on ISO 2700X
  • Advance the design, delivery, and performance of lT risk metrics and reports including the Business Impact Assessment, lT Risk Management Framework, and the management of configurations and standards
  • Assess, evaluate and make recommendations to management regarding the adequacy of the security controls, risks involved for the organization's information and technology systems
  • Lead the system-wide information security compliance program, ensuring lT activities, processes, and procedures to meet defined requirements, policies and regulations
  • Lead enterprise, network, application, and cloud infrastructure risk assessments while maintaining process and procedural documentation
  • Coordinate and track all Operational, lT Risks, information technology and security related assessments including scope of assessment, parties involved, timelines, and outcomes
  • Provides insight and guidance to IT processes and projects to ensure best practices and security standards are maintained
  • Operate with a high degree of independence with regard to project management activities, including development of project plans and budget/resource estimates
  • Excellent knowledge and experience of information security, audit, risk management, compliance or risk consulting experience
  • Arranges and conducts Risk Workshops for confirmation of the Risk Registers and for identifying risks and mitigation controls of Risks
  • Provides guidance, coordination and subject matter expertise to business functions to ensure the implementation of the agreed risk management strategy.
  • Works with all functional groups to establish, maintains and continuously improve risk management capabilities.
  • Manage relationships with external consultants and supervise work programs.
  • Plan the risk management related awareness amongst SSGC IT and Operation / Technical departments regarding the need and importance of this exercise as well as correct implementation of the program through guided training sessions and/or e-learning modules.
  • Guide the IT function to undertake a thorough information systems risk assessment in order to obtain an understanding of the risks to the availability, integrity and confidentiality of data and systems.
  • Ensure that such risk assessment encompasses all systems, including hardware, software, data, networks and any business processes to identify threats, vulnerabilities, probabilities of occurrence and potential impact.
  • Ensure close coordination with individual technical or operational departments in proper articulation of key risks and determination of the severity of impact as well as probability of its occurrence, using a top-down as well as a bottom-up approach.
  • Develop a common set of assessment criteria that can be used across operating departments and determine how much risk the organization faces.
  • Identify and analyze risks and risk indicators pertaining to loss of critical systems, key suppliers, key employees etc.; into the risk management program along with the corresponding business continuity decisions.
  • Help the departments in categorization of the risks according to a pre-defined criterion into categories including “critical”, “catastrophic” etc.; based on level of severity and likelihood of happening (e.g. almost certain, likely, possible).
  • Assess key risk areas including operations risk, compliance risk, legal risk, liquidity risk etc.; and provide feedback to departmental heads on steps needed to mitigate these risks.

Copyright (c) 2018-2026 Sui Southern Gas Company Limited. All Rights Reserved.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Chief Manager – IT and Operational Risks
Chief Manager – IT and Operational Risks

SSGC LPG Limited • Karachi Division

On-site
PKR 2,400,000 - 4,000,000
Lead Manager – Strategic, Financial and Compliance Risks
Lead Manager – Strategic, Financial and Compliance Risks

SSGC LPG Limited • Karachi Division

On-site
PKR 2,500,000 - 4,000,000
Engineer / Deputy Manager – IT Risk Management
Engineer / Deputy Manager – IT Risk Management

Sui Southern Gas Company Limited • Karachi Division

On-site
PKR 1,800,000 - 3,200,000
Manager – Operational Risk
Manager – Operational Risk

SSGC LPG Limited • Karachi Division

On-site
PKR 1,800,000 - 3,000,000
Engineer – Operational Risk Management
Engineer – Operational Risk Management

Sui Southern Gas Company Limited • Karachi Division

On-site
PKR 2,000,000 - 3,000,000
Senior IT & Operational Risk Manager (ERM & InfoSec)
Senior IT & Operational Risk Manager (ERM & InfoSec)

SSGC LPG Limited • Karachi Division

On-site
PKR 2,500,000 - 6,000,000
Lead Manager IT Audit - Technical Operations
Lead Manager IT Audit - Technical Operations

SSGC LPG Limited • Karachi Division

On-site
PKR 2,400,000 - 3,600,000
Head of IT & Operational Risk Management
Head of IT & Operational Risk Management

SSGC LPG Limited • Karachi Division

On-site
PKR 2,400,000 - 4,000,000
Operational Risk Engineer — ERM & Asset Integrity
Operational Risk Engineer — ERM & Asset Integrity

Sui Southern Gas Company Limited • Karachi Division

On-site
PKR 2,000,000 - 3,000,000
Chief Manager IT Audit - Technical Operations
Chief Manager IT Audit - Technical Operations

SSGC LPG Limited • Karachi Division

On-site
PKR 900,000 - 1,400,000