easypaisa, Pakistan’s first digital bank, has been a pioneer in advancing the country’s digital finance landscape. Supported by prominent shareholders including Telenor Group, a leading telecom operator in Asia and the Nordics, and Ant Group, the force behind Alipay, easypaisa provides secure and convenient financial solutions to millions across Pakistan.
The Head of Security Operations Center (SOC) is a vital leadership role responsible for protecting the organization’s digital assets against cyber threats. This position involves managing the SOC team, overseeing continuous monitoring of security systems, leading incident response efforts from detection through resolution, and enhancing the overall cybersecurity posture. The role requires adherence to standard operating procedures for incident detection, classification, and reporting under the supervision of the Head of Information Security (IS). Additionally, the incumbent supports activities related to threat identification, protection, detection, response, and recovery, including managing SOC and SIEM configurations, communicating threat alerts, and performing other duties as assigned by the Head of IS.
Key Responsibilities:
- Develop and execute strategic plans for the SOC aligned with the organization’s security objectives.
- Lead, motivate, and develop the SOC team to ensure high performance and job satisfaction.
- Collaborate with department heads and senior management to establish security policies and procedures.
- Monitor the organization’s cybersecurity posture and generate actionable reports.
- Oversee incident handling and reporting to senior management and coordinate extensively with group stakeholders, including crisis management teams.
- Ensure robust detection and response capabilities by deploying and optimizing security tools and processes to investigate attacks and cyber fraud.
- Provide guidance on organizational, technical, and operational challenges arising from security incidents.
- Manage multiple priorities in a high-pressure environment while innovating reporting and presentation methods for business stakeholders.
- Analyze and trend security log data from diverse IT security devices.
- Provide Incident Response support for confirmed actionable incidents.
- Prepare daily, weekly, and monthly security reports punctually.
- Conduct gap analysis of SIEM and integrate missing infrastructure components.
- Enhance threat intelligence by identifying Indicators of Compromise (IOCs) from internal and external sources and initiate mitigation actions.
- Monitor for attacks, intrusions, and unauthorized activities.
- Investigate and resolve security breaches and cyber incidents, providing effective incident response.
- Develop incident handling playbooks in line with NIST and other industry standards.
- Support IS team operations including access management governance and security audits.
- Recommend improvements to SOC processes, procedures, and policies.
- Collaborate with teams to safeguard corporate data and technology platforms from known threats.
- Communicate effectively with customers, teammates, and management.
- Follow ITIL best practices for incident, problem, and change management.
- Document and maintain security procedures, processes, and customer build documents.
- Stay updated on emerging security threats and relevant regulatory requirements.
- Perform other responsibilities as assigned by the Chief Information Security Officer (CISO).
Required Qualifications:
- Bachelor’s or Master’s degree in Computer Science, Information Security, or related fields (BS/MS/BE).
- Extensive experience in multiple information security domains including security investigations, SIEM tuning, log management, configuration, analysis, alert configuration, and SOAR implementation.
- Minimum of 7 years of hands-on experience with server, database, and application vulnerability scanning and penetration testing is advantageous.
- Strong understanding of network and application security, systems administration, programming, data networks, security operations, and incident management.
Preferred Qualifications:
- Professional certifications and vendor-specific training related to SOC operations, incident handling, computer forensics, and log investigations.
- Proven expertise in managing SOC teams and incident response in complex environments.
This role offers the opportunity to lead a critical cybersecurity function within a dynamic digital banking environment, contributing significantly to the protection and resilience of Pakistan’s pioneering digital financial platform.