Officer IS Applications / Cloud Security (OG-I)

Khanewal

Karachi Division

On-site

PKR 1,200,000 - 1,800,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

National Bank of Pakistan (NBP) is seeking a skilled security professional to join Risk Management in Karachi on a contractual basis.Responsibilities include conducting security reviews of apps, APIs, and cloud workloads, and performing risk assessments across design, deployment, and production.

The role requires 4+ years in Application/Cloud/Information Security, with graduation in CS/CE/IT and preferred certifications.

Qualifications

  • Minimum Graduation in Computer Science, Computer Engineering, Cybersecurity, or Information Technology from a local or international university recognized by HEC Pakistan.
  • Relevant professional certifications in Information Security or Cybersecurity preferred (e.g., CompTIA Security+, CompTIA Cloud+).

Responsibilities

  • Conduct security reviews of web and mobile applications, APIs, databases, middleware, SaaS solutions, and cloud workloads.
  • Perform security assessments during solution design, implementation, changes, and production deployment.
  • Review architecture to identify risks around authentication, authorization, session management, encryption, data handling, APIs, and integrations.
  • Assess applications against OWASP Top 10 and API Security Top 10; review SAST/DAST/ SCA and remediation outcomes.
  • Evaluate third‑party and internal apps for security weaknesses before deployment.
  • Coordinate threat modeling for critical apps and changes; review cloud configurations and IAM controls.
  • Assess cloud environments against CIS Benchmarks and cloud security standards; consider IaaS/PaaS/SaaS, containers, Kubernetes, serverless.

Skills

Information Security
Threat analysis
Risk management
Problem solving
Teamwork

Education

Graduation in CS/CE/Cybersecurity/IT

Job description

#### Job Description**Department:** Risk Management **Reporting To:** Unit Head - IS Digital Channels **Location:** Karachi **Employment Type:** Contractual **Contract Duration:** 3 Years, extendable at Management's discretion### National Bank of Pakistan (NBP), known as “The Nation’s Bank,” is one of Pakistan’s leading and largest banks, supporting the country’s financial well-being, sustainable growth, and inclusive development through its extensive local and international branch network.As part of its strategy to become a future-fit, agile, and sustainable institution, NBP is seeking talented, dedicated, and experienced professionals for its Risk Management function.### Educational / Professional Qualification* Minimum Graduation in Computer Science, Computer Engineering, Cybersecurity, or Information Technology from a local or international university, college, or institute recognized by HEC Pakistan.* Relevant professional certifications in Information Security or Cybersecurity will be preferred.* Preferred certifications may include CompTIA Security+, CompTIA Cloud+, and relevant cloud or application security certifications.### Experience* Minimum **4 years of relevant experience** in Application Security, Cloud Security, and/or Information Security.### Other Skills / Expertise / Knowledge Required* Good knowledge of Information Security functions.* Strong interpersonal, analytical, and problem-solving skills.* Ability to work effectively as a team player and meet strict deadlines.* Knowledge of security principles, threat analysis, and risk management.### Main Duties & Responsibilities* Conduct security reviews of web and mobile applications, APIs, databases, middleware, SaaS solutions, and cloud-hosted workloads.* Perform security assessments during solution design, implementation, major changes, and production deployment.* Review application architecture and identify risks involving authentication, authorization, session management, encryption, data handling, APIs, and integrations.* Assess applications against OWASP Top 10, OWASP API Security Top 10, secure coding standards, and other security requirements.* Review SAST, DAST, SCA, and penetration-testing findings and validate remediation and risk closure.* Assess third-party and internally developed applications for security weaknesses before production deployment.* Conduct or coordinate threat modeling for critical applications and significant technology changes.* Review cloud architectures and configurations across AWS, Microsoft Azure, and/or Google Cloud Platform.* Assess cloud controls covering IAM, privileged access, network segmentation, security groups/firewalls, storage, databases, encryption, key management, secrets management, logging, monitoring, backup, and recovery.* Review cloud environments against security baselines such as CIS Benchmarks and organizational cloud-security standards.* Assess security risks associated with IaaS, PaaS, SaaS, containers, Kubernetes, serverless computing, and cloud-native services.* Review CI/CD pipelines and DevSecOps controls, including source-code security, secrets handling, dependency management, container/image scanning, and deployment controls.* Evaluate IAM controls based on least privilege, segregation of duties, MFA, privileged access management, and Zero Trust principles.* Review API security, including authentication, authorization, rate limiting, encryption, token management, and protection of sensitive information.* Review Infrastructure-as-Code templates and automated cloud deployments for security misconfigurations.* Assess security implications of application and cloud changes through the change-management process.* Maintain security review findings, risk ratings, remediation plans, exceptions, and closure evidence.* Work with application owners, developers, DevOps, and cloud teams to recommend practical remediation measures.* Participate in application and cloud-related security incidents and provide technical support for investigation and root-cause analysis.* Develop and maintain application security standards, cloud security baselines, review checklists, and security architecture requirements.* Perform any other assignments as directed by the supervisor(s).### Assessment Test / InterviewOnly shortlisted candidates who strictly meet the stated basic eligibility criteria will be invited for the assessment test and/or panel interview.### Compensation & BenefitsSelected candidates will be offered a compensation package and other benefits according to the Bank's applicable policies and rules.### How to ApplyInterested candidates should apply online through the **Sidat Hyder Careers Portal** according to the instructions provided there.Applications received after the due date will not be considered.**Important:** No TA/DA will be admissible for the test/interview.### Equal Opportunity EmployerNational Bank of Pakistan is an equal opportunity employer and welcomes applications from all qualified individuals regardless of gender, religion, or disability.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

CAD Officer – OG II
CAD Officer – OG II

Khanewal • Pakistan

On-site
PKR 670,000 - 1,116,000
Head Application And Database Security
Head Application And Database Security

ThePakEdu • Karachi Division

On-site
PKR 1,674,000 - 2,232,000
Head Information Security Risk Management
Head Information Security Risk Management

ThePakEdu • Karachi Division

On-site
PKR 2,031,000 - 2,433,000
AML Analyst (OG-III / OG-II)
AML Analyst (OG-III / OG-II)

Khanewal • Karachi Division

On-site
PKR 1,200,000 - 1,800,000
Cyber Security Engineer
Cyber Security Engineer

Code Ninety • Islamabad

On-site
Competitive salary
Security certifications training
Flexible working hours
Enterprise Application Security and Risk Specialist
Enterprise Application Security and Risk Specialist

HBL People • Pakistan

On-site
PKR 90,000 - 130,000
NBP Credit Officer Jobs 2026 – Apply Online OG II Risk Management
NBP Credit Officer Jobs 2026 – Apply Online OG II Risk Management

Visual Pakistan • Karachi Division

On-site
PKR 600,000 - 1,000,000
Senior Enterprise Network Security Specialist
Senior Enterprise Network Security Specialist

Khanewal • Karachi Division

On-site
PKR 1,800,000 - 3,200,000
Manager Infrastructure Security (AVP) - TJ / 1876283
Manager Infrastructure Security (AVP) - TJ / 1876283

Recruit AI • Karachi Division

On-site
PKR 9,000,000 - 13,000,000
Cyber Risk Management Department
Cyber Risk Management Department

State Bank of Pakistan • Karachi Division

On-site
PKR 1,200,000 - 2,000,000