GRC Manager – Information Security Governance
Mobilink Bank · Territoire de la Capitale fédérale
Job description
About the role
The GRC Manager will lead the Information Security Governance, Risk & Compliance function, ensuring that Mobilink Bank’s security, privacy, technology risk and AI governance align with regulatory requirements, international standards and the bank’s risk appetite. The role supports the Head of GRC in overseeing risk assessments, regulatory compliance, audit activities and third‑party security oversight.
Key responsibilities
- Develop, maintain and continuously improve the GRC framework, policies, standards and control libraries.
- Coordinate security risk assessments, maintain the risk register and monitor treatment, acceptance and remediation actions.
- Manage compliance with SBP, Group/VEON, ISO 27001, PCI DSS and other regulatory mandates.
- Lead ISO 27001 ISMS activities, audits, certification and continual improvement initiatives.
- Monitor critical security controls such as IAM, PAM, vulnerability management, SIEM/SOC, endpoint security, DLP and security monitoring.
- Oversee third‑party, cloud and emerging‑technology risk assessments and track remediation of identified gaps.
- Facilitate internal and external audit processes, collect evidence and ensure timely closure of findings.
- Prepare dashboards and reports on security risks, compliance status, KPI/KRI performance and remediation progress.
Required profile
- Bachelor’s or Master’s degree in Information Security, Cybersecurity, Computer Science or related field.
- Professional certifications such as CISM, CISA or ISO/IEC 27001 Lead Auditor/Implementer are desirable.
- Proven experience in information security governance, risk management, compliance or audit within a regulated environment.
- Strong knowledge of ISO/IEC 27001, NIST Cybersecurity Framework, PCI DSS and data‑privacy regulations.
- Excellent analytical, documentation and stakeholder‑management skills.
Required skills
- ISO/IEC 27001 implementation and audit
- NIST Cybersecurity Framework
- PCI DSS compliance
- Identity and Access Management (IAM) and Privileged Access Management (PAM)
- Vulnerability Management and Patch Management
- SIEM/SOC operations
- Endpoint Security solutions
- Data Loss Prevention (DLP) and security monitoring tools
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Pakistan.
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
A question about this job?
Ask it here: you will get the full job summary by e-mail, right away.
Published 2 hours ago
Expires 1 month from now
1 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Mobilink Bank
Territoire de la Capitale fédérale
Related job offers
-
Senior DevOps Engineer – Cloud Infrastructure & Automation
Edge Territoire de la Capitale fédérale -
Senior Linux Engineer
Systems Limited Territoire de la Capitale fédérale -
Quality Assurance Manager
Nysonian Inc. Territoire de la Capitale fédérale -
Customer Success Manager
Mammoth-AI Lahore -
Senior Cloud Engineer – Cloud Specialist
Mashreq Division de Karachi