The Manager GRC at Mobilink Microfinance Bank Ltd. (MMBL) is responsible for managing and executing Information Security Governance, Risk, and Compliance (GRC) activities. This role ensures that the organization’s information security, cybersecurity, privacy, technology risk, and AI governance practices align with regulatory requirements, international standards, organizational policies, and enterprise risk appetite. Reporting to the Head of GRC, the Manager will coordinate with business, technology, and control functions to identify, assess, track, and remediate information security risks and compliance gaps while supporting governance, risk assessments, audit, assurance, third-party risk, and emerging technology governance.
Key Responsibilities
Information Security Governance:
Lead the implementation and continuous improvement of the Information Security Governance framework. Develop, review, and maintain security policies, standards, procedures, and control frameworks. Translate regulatory and organizational requirements into actionable security controls and governance processes. Collaborate with stakeholders to ensure governance requirements are met and maintain governance trackers for initiatives, decisions, risk acceptances, and actions. Support preparation of management and executive security governance reports and monitor progress against security objectives and maturity plans.
Information Security Risk Management:
Coordinate risk assessments across applications, infrastructure, data, third parties, and business processes. Maintain and update the Information Security Risk Register, ensuring risks are assessed, documented, treated, monitored, and escalated appropriately. Facilitate risk acceptance processes and monitor remediation efforts, escalating overdue or material risks. Align risk management activities with the organization’s Risk Appetite Framework and prepare periodic risk reports and dashboards.
Regulatory Compliance:
Manage compliance activities against applicable regulatory requirements, including those from the State Bank of Pakistan and Group/VEON security standards. Maintain compliance trackers and coordinate the identification and assessment of regulatory obligations. Track regulatory observations, compliance gaps, and remediation plans, coordinating responses for regulatory reviews and audits. Ensure compliance documentation is audit-ready and provide regular updates to management on compliance status and risk exposure.
ISO 27001 & Security Frameworks:
Coordinate ISO/IEC 27001 ISMS activities, including certification, surveillance audits, internal audits, and continuous improvement. Manage periodic reviews of the Statement of Applicability, risk assessments, and controls. Track ISMS findings and corrective actions. Support maturity assessments against frameworks such as NIST Cybersecurity Framework and maintain ISMS documentation and records.
PCI DSS Compliance:
Oversee PCI DSS compliance efforts, including assessments and remediation initiatives. Liaise with technology and business teams to gather control evidence and address gaps. Coordinate with Qualified Security Assessors and maintain compliance trackers, action plans, and compensating controls. Monitor remediation progress and escalate significant issues.
Security Control Governance & Assurance:
Oversee GRC activities related to key security controls such as Vulnerability Management, Privileged Access Management, Identity and Access Management, Endpoint Security, SIEM/SOC, Data Loss Prevention, Security Monitoring, Configuration, and Operations. Monitor control effectiveness through KRIs, KPIs, and assessments. Identify gaps, develop remediation plans with control owners, and escalate deficiencies. Support cybersecurity resilience and operational readiness assessments.
Third-Party & Technology Risk:
Coordinate governance activities related to third-party, cloud, managed service, and technology engagements to ensure security and compliance.
Required Qualifications
A Bachelor’s or Master’s degree in Information Security, Cybersecurity, Computer Science, Information Technology, or a related field is required. Candidates should have relevant professional certifications such as CISM, CISA, or ISO/IEC 27001 Lead Auditor/Implementer. Demonstrated experience in information security governance, cybersecurity risk, compliance, audit, regulatory compliance, or technology risk management is essential. Strong working knowledge of ISO/IEC 27001, NIST Cybersecurity Framework, PCI DSS, and cybersecurity governance is expected. Familiarity with information privacy, data protection, and emerging AI governance requirements is important.
Preferred Qualifications and Skills
Experience coordinating with business, technology, risk, audit, and compliance stakeholders is preferred. The ability to prepare management reports, risk dashboards, compliance assessments, and audit responses is critical. Strong analytical, documentation, communication, and stakeholder management skills are necessary. The role requires effective multitasking, prioritization of deliverables, and tracking remediation within defined timelines.
About MMBL
Mobilink Microfinance Bank Ltd. serves over 48 million registered users, including more than 20 million monthly active customers across Pakistan. Combining traditional microfinance with mobile and digital banking technologies, MMBL operates over 114 branches and 270,000 branchless banking agents. The bank offers a range of services including savings, MSME loans, housing loans, remittances, collections, mobile wallets, insurance, and various payment solutions, playing a vital role in promoting financial inclusion. MMBL values innovation, teamwork, and a customer-centric approach, fostering a positive and productive workplace.
Why Join MMBL?
This position offers the opportunity to make a significant impact by driving transformative change and empowering millions in the digital age. The team is dedicated to innovation and growth, seeking a talented individual passionate about advancing information security governance within a dynamic and forward-thinking organization.