This job is no longer available
This job expired on 29/08/2026. It no longer accepts applications.
Information Security Lead – GRC (ISO 27001, SOC2, HIPAA)
Eplanet Global · Karachi
Job description
About the role
We are seeking an experienced Information Security Lead (GRC) to drive our Governance, Risk, and Compliance program. The role will work closely with Engineering, DevOps, Legal, Product and executive teams to ensure the organization meets ISO 27001, SOC 2, HIPAA and healthcare security standards.
Key responsibilities
- Lead GRC initiatives, including ISO 27001 and SOC 2 implementation, audit readiness and certification.
- Manage HIPAA compliance and ONC Health IT Certification §170.315 security criteria.
- Oversee Vulnerability Assessment & Penetration Testing (VAPT) activities and remediation tracking.
- Define, implement and maintain security policies, standards, procedures and controls.
- Coordinate audits, collect evidence, plan remediation and produce compliance reports.
- Develop and execute risk mitigation strategies across people, process and technology.
- Partner with Legal to draft, review and manage Business Associate Agreements (BAAs) with cloud vendors and AI/LLM subprocessors.
- Collaborate with Engineering and Infrastructure to improve cloud, application and network security posture.
- Monitor security compliance metrics and report regularly to leadership.
Required profile
- Proven experience as a Lead Implementer or Lead Auditor for ISO 27001 and SOC 2.
- Strong knowledge of HIPAA compliance and healthcare security requirements.
- Hands‑on experience managing VAPT activities.
- Experience with cloud, network and application security.
- Deep understanding of GRC frameworks.
- Track record handling audits, evidence collection, remediation and reporting.
- Excellent communication and stakeholder management skills.
- Ability to define and execute risk mitigation, compensating controls and residual risk acceptance.
- Working knowledge of ONC Health IT Certification §170.315 security criteria.
- Experience collaborating with Legal on BAA drafting and management.
Required skills
- ISO 27001
- SOC 2
- HIPAA
- Vulnerability Assessment & Penetration Testing (VAPT)
- Cloud security
- Network security
- Application security
- GRC frameworks
- ONC Health IT Certification §170.315
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Pakistan.
A question about this job?
Ask it here: you will get the full job summary by e-mail, right away.
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Eplanet Global
Karachi
Related job offers
-
Lead Backend Developer (SaaS Platform)
Veeam Software Karachi -
Associate Project Manager – Enterprise Platforms (Onsite, Karachi)
HR POD Careers Karachi -
iOS Software Engineer – Onsite in Karachi
HR POD Careers Karachi -
Developpeur PHP Laravel
Sufyan Iqbal Casablanca -
Odoo Technical Consultant
DWP Group Lahore