We are looking for a seasoned Head of Information Security to lead and shape our cybersecurity strategy, ensuring the protection of our digital assets and adherence to regulatory requirements. This leadership role involves overseeing security operations, managing risks, responding to incidents, and fostering a culture of security awareness across the organization. The ideal candidate will be responsible for maintaining robust governance frameworks and driving continuous improvements in our cybersecurity posture.
Key Responsibilities
- Lead the development and execution of enterprise-wide Information Security strategy and governance frameworks.
- Ensure compliance with regulatory standards including SBP regulations, ISO 27001, NIST, PCI DSS, and applicable cybersecurity laws.
- Oversee Security Operations Center (SOC) activities, including threat monitoring and incident response management.
- Conduct comprehensive security audits, risk assessments, and vendor security evaluations to identify and mitigate vulnerabilities.
- Enhance cybersecurity architecture across all systems, cloud environments, and digital platforms to strengthen defenses.
- Lead Business Continuity Planning (BCP) and Disaster Recovery Planning (DRP), including regular testing and cyber-resilience initiatives.
- Develop and implement employee security awareness programs and training to promote a security-conscious culture.
- Provide regular reports on security posture, risks, and mitigation efforts to senior leadership and Board committees.
Required Qualifications
- Bachelor’s or Master’s degree in Cybersecurity, Information Technology, Computer Science, or a related field.
- Over 10 years of experience in Information Security, with a minimum of 3 years in a leadership role.
- Strong technical expertise in Security Information and Event Management (SIEM), Intrusion Detection/Prevention Systems (IDS/IPS), firewalls, cloud security, Identity and Access Management (IAM), and digital banking security.
- Proven track record in incident management, forensic investigations, and ensuring regulatory compliance.
Preferred Qualifications and Benefits
- Professional certifications such as CISSP, CISM, CISA, and ISO 27001 are highly preferred.
- Experience working within regulated industries and familiarity with cybersecurity frameworks and standards.
- Ability to communicate complex security concepts effectively to both technical teams and executive leadership.
- Opportunity to lead a critical function within a dynamic organization committed to cybersecurity excellence.
This role offers the chance to make a significant impact on the organization’s security landscape by driving strategic initiatives and fostering a proactive security culture.