The Information Security GRC Manager plays a critical role in overseeing and coordinating the Bank’s Information Security Governance, Risk, and Compliance activities across all group entities and subsidiaries. This position supports the implementation of the Group’s Information Security strategy by ensuring robust governance processes, effective cyber risk management, regulatory compliance, control assurance, and security awareness programs are consistently applied throughout the organization. Acting as a key liaison among Information Security, Technology, Risk Management, Internal Audit, Compliance, and business stakeholders, the manager ensures that information security risks are properly managed and regulatory obligations are fulfilled.

Key Responsibilities

- Lead the development, implementation, and maintenance of Information Security policies, standards, procedures, and control frameworks, ensuring consistent governance across all countries and subsidiaries.
- Manage the lifecycle of security policies, including periodic reviews, stakeholder consultations, approvals, publication, and compliance monitoring.
- Oversee the Information Security Risk Management process, conducting risk assessments for projects, systems, applications, and third-party services while maintaining the Group Risk Register.
- Monitor risk treatment plans, remediation activities, and emerging cyber threats, facilitating risk acceptance reviews and reporting to management and governance forums.
- Administer Information Security controls within the Internal Control System (ICS), maintaining accurate documentation, coordinating periodic reviews, performing quality assurance, and tracking control performance and remediation.
- Support internal and external audits, regulatory examinations, and assurance reviews related to Information Security controls, facilitating control owner attestations and escalating issues as necessary.
- Coordinate compliance assessments, monitor adherence to regulatory and internal requirements, assist with regulatory audits, and maintain registers of compliance obligations.
- Manage security control assessments, validate remediation evidence, track audit findings, and support security maturity assessments using recognized frameworks.
- Develop and maintain security dashboards, Key Risk Indicators (KRIs), Key Performance Indicators (KPIs), and management reports for timely escalation and informed decision-making.
- Coordinate third-party security risk management, including due diligence assessments, onboarding reviews, remediation monitoring, and supplier risk governance.
- Support the Group’s Information Security Awareness Program by coordinating training, phishing simulations, and awareness campaigns to promote a strong cybersecurity culture.
- Act as a primary point of contact between Information Security and other key departments, supporting group-wide GRC initiatives, facilitating risk discussions, and fostering stakeholder relationships.

Required Qualifications

- Bachelor’s degree in Information Security, Computer Science, Information Technology, Risk Management, Business Administration, or a related field.
- 8-10 years of experience in Information Security, Cyber Risk, IT Risk, Governance, Compliance, or Security Assurance.
- Minimum 3-5 years in a leadership, management, or senior specialist role within Governance, Risk, and Compliance.
- Proven experience in banking, financial services, fintech, or other regulated industries.
- Strong background in conducting risk assessments, compliance reviews, security governance, and working with regulatory frameworks.
- Experience coordinating audits, regulatory reviews, and remediation efforts.
- Ability to work effectively in multinational, matrixed environments with exposure to group-level governance and reporting structures.
- Fluent English communication skills, both written and spoken.

Preferred Qualifications

- Professional certifications such as CISM, CISSP, CRISC, CISA, ISO 27001 Lead Auditor/Implementer, COBIT Foundation or Design & Implementation, and PCI DSS Professional are highly desirable.
- Additional language skills relevant to the Bank’s operating regions are advantageous.
- Expertise in enterprise information security governance, cyber risk management, regulatory compliance, security assurance, and control testing.
- Strong skills in executive and board-level reporting, strategic leadership, stakeholder management, remote team leadership, and program management.
- Deep knowledge of banking regulations, technology risk management, data protection, outsourcing risks, and cybersecurity governance within financial services.

This role offers the opportunity to contribute significantly to the Bank’s security posture by driving governance, risk, and compliance excellence across a complex multinational organization.

Job Details

Total Positions:
1 Post
Job Shift:
First Shift (Day)
Job Type:
Job Location:
Gender:
No Preference
Age:
18 - 65 Years
Minimum Education:
Master
Degree Title:
bachelor degree
Career Level:
Manager
Experience:
6 Years - 10 Years
Apply Before:
Oct 08, 2026
Posting Date:
Oct 02, 2026

Habib Bank AG Zurich

· 11-50 employees - Karachi

What is your Competitive Advantage?

Get quick competitive analysis and professional insights about yourself
Talk to our expert team of counsellors to improve your CV!
Try Rozee Premium

Similar Job Titles

I found a job on Rozee!