We are looking for a seasoned Head of Information Security to lead and shape our cybersecurity strategy, ensuring the protection of our digital assets and adherence to regulatory requirements. This leadership role is responsible for managing security operations, risk management, incident response, governance, and fostering a culture of security awareness across the organization. The ideal candidate will play a critical role in safeguarding our enterprise from evolving cyber threats while aligning security initiatives with business objectives.

Key Responsibilities

- Lead the development and execution of the enterprise Information Security strategy and governance framework.
- Ensure compliance with relevant regulations and standards including SBP regulations, ISO 27001, NIST, PCI DSS, and applicable cybersecurity laws.
- Oversee Security Operations Center (SOC) activities, including threat monitoring and incident response management.
- Conduct comprehensive security audits, risk assessments, and evaluate third-party vendors to mitigate risks.
- Enhance cybersecurity architecture across on-premises systems, cloud environments, and digital platforms to strengthen defenses.
- Lead Business Continuity Planning (BCP) and Disaster Recovery Planning (DRP), including regular testing and cyber-resilience initiatives.
- Drive organization-wide security awareness programs and employee training to promote a security-conscious culture.
- Provide regular reporting on security posture, risks, and mitigation strategies to senior leadership and Board committees.

Required Qualifications

- Bachelor’s or Master’s degree in Cybersecurity, Information Technology, Computer Science, or a related field.
- Over 10 years of experience in Information Security, with at least 3 years in a leadership or managerial role.
- Strong technical expertise in Security Information and Event Management (SIEM), Intrusion Detection/Prevention Systems (IDS/IPS), firewalls, cloud security, Identity and Access Management (IAM), and digital banking security.
- Proven track record in incident management, forensic investigations, and ensuring regulatory compliance across complex environments.

Preferred Qualifications

- Professional certifications such as CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), CISA (Certified Information Systems Auditor), and ISO 27001 Lead Implementer or Auditor are highly desirable.

This role offers the opportunity to lead a critical function within the organization, influencing security strategy at the highest level and working closely with executive leadership to protect business assets and reputation. Candidates with a strong leadership background and deep technical knowledge in cybersecurity frameworks and regulatory compliance will find this position both challenging and rewarding.

Job Details

Total Positions:
1 Post
Job Shift:
First Shift (Day)
Job Type:
Job Location:
Gender:
No Preference
Age:
18 - 65 Years
Minimum Education:
Master
Degree Title:
bachelor degree
Career Level:
Executive
Maximum Experience:
2 Years
Apply Before:
Oct 06, 2026
Posting Date:
Sep 30, 2026

ASA Microfinance Bank (Pakistan) Limited

· 11-50 employees - Karachi

What is your Competitive Advantage?

Get quick competitive analysis and professional insights about yourself
Talk to our expert team of counsellors to improve your CV!
Try Rozee Premium
I found a job on Rozee!