#### Job Description**Department:** Risk Management **Reporting To:** Unit Head - IS Digital Channels **Location:** Karachi **Employment Type:** Contractual **Contract Duration:** 3 Years, extendable at Management's discretion### National Bank of Pakistan (NBP), known as “The Nation’s Bank,” is one of Pakistan’s leading and largest banks, supporting the country’s financial well-being, sustainable growth, and inclusive development through its extensive local and international branch network.As part of its strategy to become a future-fit, agile, and sustainable institution, NBP is seeking talented, dedicated, and experienced professionals for its Risk Management function.### Educational / Professional Qualification* Minimum Graduation in Computer Science, Computer Engineering, Cybersecurity, or Information Technology from a local or international university, college, or institute recognized by HEC Pakistan.* Relevant professional certifications in Information Security or Cybersecurity will be preferred.* Preferred certifications may include CompTIA Security+, CompTIA Cloud+, and relevant cloud or application security certifications.### Experience* Minimum **4 years of relevant experience** in Application Security, Cloud Security, and/or Information Security.### Other Skills / Expertise / Knowledge Required* Good knowledge of Information Security functions.* Strong interpersonal, analytical, and problem-solving skills.* Ability to work effectively as a team player and meet strict deadlines.* Knowledge of security principles, threat analysis, and risk management.### Main Duties & Responsibilities* Conduct security reviews of web and mobile applications, APIs, databases, middleware, SaaS solutions, and cloud-hosted workloads.* Perform security assessments during solution design, implementation, major changes, and production deployment.* Review application architecture and identify risks involving authentication, authorization, session management, encryption, data handling, APIs, and integrations.* Assess applications against OWASP Top 10, OWASP API Security Top 10, secure coding standards, and other security requirements.* Review SAST, DAST, SCA, and penetration-testing findings and validate remediation and risk closure.* Assess third-party and internally developed applications for security weaknesses before production deployment.* Conduct or coordinate threat modeling for critical applications and significant technology changes.* Review cloud architectures and configurations across AWS, Microsoft Azure, and/or Google Cloud Platform.* Assess cloud controls covering IAM, privileged access, network segmentation, security groups/firewalls, storage, databases, encryption, key management, secrets management, logging, monitoring, backup, and recovery.* Review cloud environments against security baselines such as CIS Benchmarks and organizational cloud-security standards.* Assess security risks associated with IaaS, PaaS, SaaS, containers, Kubernetes, serverless computing, and cloud-native services.* Review CI/CD pipelines and DevSecOps controls, including source-code security, secrets handling, dependency management, container/image scanning, and deployment controls.* Evaluate IAM controls based on least privilege, segregation of duties, MFA, privileged access management, and Zero Trust principles.* Review API security, including authentication, authorization, rate limiting, encryption, token management, and protection of sensitive information.* Review Infrastructure-as-Code templates and automated cloud deployments for security misconfigurations.* Assess security implications of application and cloud changes through the change-management process.* Maintain security review findings, risk ratings, remediation plans, exceptions, and closure evidence.* Work with application owners, developers, DevOps, and cloud teams to recommend practical remediation measures.* Participate in application and cloud-related security incidents and provide technical support for investigation and root-cause analysis.* Develop and maintain application security standards, cloud security baselines, review checklists, and security architecture requirements.* Perform any other assignments as directed by the supervisor(s).### Assessment Test / InterviewOnly shortlisted candidates who strictly meet the stated basic eligibility criteria will be invited for the assessment test and/or panel interview.### Compensation & BenefitsSelected candidates will be offered a compensation package and other benefits according to the Bank's applicable policies and rules.### How to ApplyInterested candidates should apply online through the **Sidat Hyder Careers Portal** according to the instructions provided there.Applications received after the due date will not be considered.**Important:** No TA/DA will be admissible for the test/interview.### Equal Opportunity EmployerNational Bank of Pakistan is an equal opportunity employer and welcomes applications from all qualified individuals regardless of gender, religion, or disability.