📢 New: get today's jobs on our WhatsApp Channel
Jobiglo

No results.

Head of Information Security

JazzWorld · Karachi

Senior 🇬🇧 English
ISO 27001 GRC risk assessment penetration testing vulnerability assessment VAPT COBIT NIST CISM CGEIT CEH OSCP

Job description

About the role

The Head of Information Security will lead the design, implementation, and monitoring of security controls across TPL Insurance’s network and infrastructure. Reporting to senior management, the role ensures risk mitigation, compliance, and business continuity for the organization.

Key responsibilities

  • Evaluate risks and develop security standards, procedures, and controls.
  • Improve security posture through process automation, policy updates, and capability evolution.
  • Implement and manage GRC processes to continuously monitor controls, exceptions, and testing.
  • Lead ISO 27001 implementation, certification, and ongoing audit management.
  • Conduct regular risk assessments and remediate identified information‑security risks.
  • Develop and automate penetration‑testing and vulnerability‑assessment plans for networks, systems, and applications.
  • Coordinate third‑party vulnerability assessments and communicate remediation actions.
  • Provide guidance, training, and mentorship to junior security staff.
  • Document failures, prepare management reports, and track remediation activities.
  • Collaborate with developers and system administrators to explain test results and recommend fixes.

Required profile

  • Bachelor’s degree in Computer Science, Information Security, or a related field.
  • Minimum 10 years of experience in information security, technology governance, VAPT, or IT security.
  • Relevant certifications such as CISM, CGEIT, ISO 27001 Lead Implementer/Lead Auditor, CEH, OSCP, COBIT, or NIST Cybersecurity Framework.
  • Strong knowledge of security management, governance, compliance, architecture, and service orchestration.
  • Excellent analytical and problem‑solving abilities with a proven track record of meeting deadlines.
  • Collaborative team player capable of working independently.

Required skills

  • ISO 27001 implementation and certification
  • GRC (Governance, Risk & Compliance) tools
  • Risk assessment and management
  • Penetration testing and vulnerability assessment (VAPT)
  • Security testing automation
  • COBIT and NIST cybersecurity frameworks
  • CISM, CGEIT, CEH, OSCP certifications

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec JazzWorld.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

Apply now →

By continuing, you accept our terms of use.

Already have an account? Login

A question about this job?

Ask it here: you will get the full job summary by e-mail, right away.

💬 Chat with us on Telegram

Published 4 weeks ago

Expires 1 month from now

35 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

JazzWorld

Karachi