The Assistant Vice President (AVP) will manage and execute Information Security Governance, Risk, and Compliance (GRC) activities to ensure that the organization’s information security, cybersecurity, privacy, technology risk, and AI governance practices align with regulatory requirements, international standards, organizational policies, and enterprise risk appetite. Reporting to the Head of IS Governance, this role supports the management of governance, risk assessments, regulatory compliance, audit and assurance, security control monitoring, third-party risk, privacy, and emerging technology governance. The AVP will collaborate closely with business, technology, and control functions to identify, assess, track, and remediate information security risks and compliance gaps at the Head Office in Islamabad.

Key Responsibilities

- Manage and continuously enhance the Information Security Governance, Risk & Compliance (GRC) framework to ensure its effectiveness and relevance.
- Develop, review, and maintain information security policies, standards, procedures, and control frameworks.
- Coordinate information security and cybersecurity risk assessments, maintain the risk register, and monitor risk treatment, acceptance, and remediation efforts.
- Oversee regulatory and security compliance activities, including compliance with SBP, Group/VEON, ISO 27001, and PCI DSS requirements.
- Lead ISO 27001 ISMS activities, including audits, certification, surveillance, and continual improvement initiatives.
- Monitor key security controls across areas such as Identity and Access Management (IAM), Privileged Access Management (PAM), Vulnerability Management, SIEM/SOC, Endpoint Security, Data Loss Prevention (DLP), and Security Monitoring.
- Coordinate third-party, cloud, and technology security risk assessments and track remediation of identified risks and exceptions.
- Manage internal and external security audits, including evidence collection, management responses, and closure of audit findings.
- Maintain governance trackers for risks, compliance gaps, audit findings, exceptions, initiatives, and remediation actions.
- Prepare management dashboards and reports covering security risks, compliance status, control effectiveness, KPIs/KRIs, and remediation progress.
- Support security governance forums and ensure timely escalation of significant risks, compliance issues, and overdue actions.

Required Qualifications

- Bachelor’s or Master’s degree in Information Security, Cybersecurity, Computer Science, Information Technology, or a related discipline.
- Relevant professional certifications such as CISM, CISA, ISO/IEC 27001 Lead Auditor or Implementer are highly desirable.
- Proven experience in information security governance, cybersecurity risk management, compliance, audit, regulatory compliance, or technology risk management.
- Working knowledge of ISO/IEC 27001, NIST Cybersecurity Framework, PCI DSS, information security risk management, and cybersecurity governance.
- Understanding of information privacy, data protection, and emerging AI governance requirements.
- Experience collaborating with business, technology, risk, audit, and compliance stakeholders.
- Skilled in preparing management reports, risk dashboards, compliance assessments, and audit responses.
- Strong analytical, documentation, communication, and stakeholder management skills.
- Ability to manage multiple GRC activities simultaneously, prioritize deliverables, and track remediation within defined timelines.

Preferred Qualifications and Benefits

Mobilink Bank serves over 64 million registered users, including 21 million monthly active customers, through a hybrid model combining traditional microfinance with mobile and digital banking technologies. With more than 132 branches and 324,000 branchless banking agents, the bank offers a wide range of services such as savings, MSME loans, housing loans, remittances, bill collection, mobile wallets, insurance, and various payment solutions. This positions Mobilink Bank as a key player in promoting financial inclusion across Pakistan.

The organization fosters a positive and productive workplace culture grounded in innovation, entrepreneurship, teamwork, collaboration, and a customer-centric approach. Joining Mobilink Bank offers the opportunity to contribute meaningfully to transformative change and empower millions with digital tools for success in today’s evolving financial landscape. This role is ideal for a passionate professional eager to make a significant impact in information security governance and risk management.

Job Details

Total Positions:
1 Post
Job Shift:
First Shift (Day)
Job Type:
Job Location:
Gender:
No Preference
Age:
18 - 65 Years
Minimum Education:
Master
Degree Title:
bachelor degree
Career Level:
Manager
Maximum Experience:
5 Years
Apply Before:
Oct 01, 2026
Posting Date:
Sep 25, 2026

Mobilink Bank

· 11-50 employees - Islamabad

What is your Competitive Advantage?

Get quick competitive analysis and professional insights about yourself
Talk to our expert team of counsellors to improve your CV!
Try Rozee Premium

Similar Job Titles

Manager (GRC)

COMSATS Internet Services, Islamabad, Pakistan
Posted Sep 16, 2026

GRC & Compliance Specialist

Naseeb Enterprise Inc, Lahore, Pakistan
Posted Sep 25, 2026
View All
I found a job on Rozee!