"The Nation's Bank", National Bank of Pakistan aims to support the financial well-being of the Nation along with enabling sustainable growth and inclusive development through its wide local and international network of branches. Being one of the leading and largest banks of Pakistan, National Bank of Pakistan is contributing significantly towards socioeconomic growth in the country with an objective to transform the institution into a future-fit, agile and sustainable Bank.
In line with our strategy, the Bank is looking for talented, dedicated and experienced professional(s) for the following position inthe area of Risk Management.
The individuals who fulfill the below basic-eligibility criteria may apply for the following position:
Position / Job Title:
Unit Head - Monitoring and Incident (AVP / VP)
Reporting to:
Wing Head - Information Security Operations and Threat Management
Educational /Professional Qualification:
- Minimum Graduation in Computer Science and / or Computer Engineering and / or Cybersecurity and / or Information Technology from a local or international university / college / institute recognized by the HEC of Pakistan
- Candidates having relevant professional certification(s) will be preferred
Experience:
- Minimum 06 years of experience in Information Technology and / or Information Security Operations and / or Monitoring and / or Incident Management
- Candidates having relevant working experience in banking sector(s) will be
preferred
Other Skills / Expertise / Knowledge Required:
- Good knowledge of Information Security function
- Well versed with SBP guidelines regarding Information Security
- Good interpersonal and people management skills
- Understanding of incident management, cyber security monitoring and detection
tools
Outline of Main Duties / Responsibilities:
- To lead SOC / security monitoring and incident response operations
- To oversee monitoring of SIEM, EDR / XDR, SOAR, firewalls, cloud, network and application security events
- To manage security incidents through detection, triage, containment, eradication, recovery and post-incident review
- To establish and maintain incident response plans, playbooks, escalation procedures and communication protocols
- To oversee threat hunting, IOC analysis, detection use cases and correlation rules
- To coordinate major incidents with IT, Infrastructure, Applications, Digital Security, Forensics, Risk, Compliance and Business Teams
- To ensure timely escalation and reporting of critical incidents to senior
management and relevant stakeholders - To track SOC / incident KPIs and KRIs, including MTTD, MTTR, incident trends and SLA compliance
- To conduct post-incident reviews and ensure corrective and preventive actions are implemented
- To ensure compliance with applicable regulatory requirements, ISO 27001, NIST and organizational security standards
- To lead, mentor and develop the Security Monitoring and Incident Management team
- To maintain MIS of Information Security incidents along with root cause analysis details
- To implement Information Security Awareness Program as per approved Annual Plan
- To ensure all emerging Information Security threats are communicated proactively to all relevant stakeholders within organization
- To ensure execution of scenario based testing, tabletop exercises to validate organizational readiness to handle Information Security incidents
- To ensure root cause analysis is performed for Information Security incidents in coordination with Manager Forensics and Internet Security within IS Division
- To ensure submission of approved incident report to regulatory authority as per
defined timeline - To perform any other assignment as assigned by the supervisor(s)
Place of Posting:
Karachi
Assessment Interview(s)
Only shortlisted candidates strictly meeting the above-mentioned basic eligibility criteriawill be invited for panel interview(s).
Employment Type:
The employment will be on contractual basis for three years which may be renewed ondiscretion of the Management. Selected candidates will be offered compensationpackage and other benefits as per Banks Policy / rules.
Apply within 10 working days from the date of this job posting.
Applications received after due date will not be considered in any case. No TA / DA will be admissible for interview.
National Bank of Pakistan is an equal opportunity employer and welcomes applications from all qualified individuals, regardless of gender, religion, or disability.
Responsibilities