"The Nation's Bank", National Bank of Pakistan aims to support the financial well-being of the Nation along with enabling sustainable growth and inclusive development through its wide local and international network of branches. Being one of the leading and largest banks of Pakistan, National Bank of Pakistan is contributing significantly towards socioeconomic growth in the country with an objective to transform the institution into a future-fit, agile and sustainable Bank.
In line with our strategy, the Bank is looking for talented, dedicated and experienced professional(s) for the following positions in the area of Risk Management.
The individuals who fulfill the below basic-eligibility criteria may apply for the following position:
Position / Job Title:
Wing Head - Information Security Risk Management (VP / SVP)
Reporting to:
Chief Information Security Officer
Educational /Professional Qualification:
Minimum Graduation in Computer Science and / or Computer Engineering and / or Cyber Security and / or Information Technology from a local or international university / college / institute recognized by the HEC of Pakistan
Experience:
Other Skills / Expertise / Knowledge Required:
Sound knowledge of SOC operations, SIEM, SOAR, XDR, Threat Management and Incident Management
Well versed with SBP guidelines & frameworks regarding Information Security
Excellent interpersonal and people management skills
Hands on experience in detective & preventive security controls
CISSP / CISM / CompTIA CySA+ / GIAC (GSOC) certifications will be preferred
Outline of Main Duties / Responsibilities:
To ensure continuous monitoring of security events across on-premise and cloud environments and oversee proactive threat detection and response through automated security tools
To manage the establishment, implementation and continuous improvement of the Incident Management & Response Program
To apply MITRE ATT&CK and Cyber Kill Chain frameworks across offensive and defensive security operations
To manage and optimize security automation platforms for threat detection, investigation and response
To supervise and lead SOC Monitoring, SIEM Engineering, Technology Integration, Threat Management, Incident Response, Detection Engineering and Threat Intelligence functions
To perform manual correlation and analysis of security events using strong knowledge of network engineering, infrastructure, firewalls, routers, switches and data center operations
To manage cloud-based SIEM, XDR and SOAR platforms supporting international operations
To develop security operations metrics, management information and executive dashboards for senior management
To monitor and assess emerging cyber threats, including AI-driven threats affecting the financial sector, and recommend appropriate mitigation measures
To consume and analyze commercial and open source threat intelligence to identify emerging threats and enhance security monitoring.
To validate the effectiveness of security monitoring and detection capabilities through tabletop and Purple Team exercises
To perform threat modelling using STRIDE and PASTA methodologies including risk assessment and appropriate mitigation using relevant risk-rating approaches
To perform threat modelling and attack path analysis of networks, systems & applications and recommend appropriate security mitigations
To ensure effective integration of security technologies and develop, tune and optimize detection use cases to reduce false positives and improve detection coverage
To coordinate with IT, Business, Legal, Compliance, Vendors and Executive Management on information security matters
To participate in business reviews with security technology vendors and other relevant stakeholders
To maintain effective knowledge of TCP / IP, DNS, Routing & Switching, Firewalls, VPN, Web Security, Zero Trust Architecture, Identity & Access Management, PAM, Active Directory and MFA
To perform any other assignment as assigned by the supervisor(s)
Place of Posting:
Karachi
Assessment Interview(s)
Only shortlisted candidates strictly meeting the above-mentioned basic eligibility criteriawill be invited for panel interview(s).
Employment Type:
The employment will be on contractual basis for three years which may be renewed ondiscretion of the Management. Selected candidates will be offered compensationpackage and other benefits as per Banks Policy / rules.
Apply within 10 working days from the date of this job posting.
Applications received after due date will not be considered in any case. No TA / DA will be admissible for interview.
National Bank of Pakistan is an equal opportunity employer and welcomes applications from all qualified individuals, regardless of gender, religion, or disability.
,