Manager Infrastructure Security (AVP)
National Bank of Pakistan
Published Date: • Karachi, Pakistan (On-Site)
Description
"The Nation's Bank", National Bank of Pakistan aims to support the financial well-being of the Nation along with enabling sustainable growth and inclusive development through its wide local and international network of branches. Being one of the leading and largest banks of Pakistan, National Bank of Pakistan is contributing significantly towards socioeconomic growth in the country with an objective to transform the institution into a future-fit, agile and sustainable Bank.
In line with our strategy, the Bank is looking for talented, dedicated and experienced professional(s) for the following positions in the area of Risk Management based at Karachi.
The individuals who fulfill the below basic-eligibility criteria may apply for the following position:
Position / Job Title:
Manager Infrastructure Security (AVP)
Reporting to:
Unit Head - Infrastructure Security
Educational /Professional Qualification:
- Minimum Graduation in Computer Science and / or Computer Engineering and / or Cybersecurity and / or Information Technology from a local or international university / college / institute recognized by the HEC of Pakistan
- Candidates having Master’s in Information Security or any other relevant professional certification such as GSEC, SC-100, AZ-500, VMware VCP-DCV, RHCE,
CompTIA CySA+ etc. will be preferred
Experience:
- Minimum 06 years of experience in Information Technology and / or Information Security
- Candidates having experience in identifying, assessing and mitigating infrastructure security vulnerabilities across enterprise IT infrastructure working with operating systems, SAN / NAS, Containers, Identity & Access management, Data security life cycle, virtualization platforms, cloud environments and other critical infrastructure components will be preferred
Other Skills / Expertise / Knowledge Required:
- Understanding of Information Security function
- Awareness of risk frameworks and infrastructure security related policies
- Understanding of essential infrastructure security related security tools and techniques
- Good interpersonal skills and an active team player
- Ability to prioritize and meet strict deadlines
Outline of Main Duties / Responsibilities:
- To manage and continuously enhance the organization's Infrastructure Security Program, ensuring alignment with business objectives, cybersecurity strategy, regulatory requirements, and industry best practices
- To manage security architecture reviews for infrastructure projects and provide strategic guidance on secure design principles for servers, virtualization platforms, cloud services, storage systems, and enterprise network infrastructure
- To manage infrastructure security assessment activities, including Vulnerability Assessments (VA), configuration compliance reviews, penetration testing coordination, CIS benchmark assessments, operating system hardening and security validation of servers, cloud infrastructure, virtualization platforms and enterprise systems
- To prepare and maintain infrastructure vulnerability MIS, track remediation activities, and ensure timely closure of identified security findings in accordance with organizational risk management requirements
- To prepare infrastructure security assessment reports, vulnerability dashboards, compliance reports and management summaries for periodic review by senior management
- To define, implement, and maintain Infrastructure Security governance, policies, standards, procedures and security baselines for servers, operating systems, ATMs, virtualization platforms, cloud environments, storage and systems infrastructure
- To oversee infrastructure security risk assessments and ensure security risks are identified, evaluated, treated, and mitigated before deployment into production environments
- To lead the implementation and enforcement of secure infrastructure hardening standards based on recognized benchmarks (e.g., CIS Benchmarks) across the bank’s environment
- To coordinate with IT Infrastructure, Systems, Cloud, Database, System Administration and other technology teams to ensure security controls are effectively implemented and maintained across the infrastructure
- To ensure secure configuration, hardening, continuous monitoring and compliance of enterprise infrastructure, including Windows and Linux servers, databases, virtualization platforms, cloud workloads, storage systems and Active Directory
- To support internal and external audits by providing infrastructure security evidence, compliance documentation, remediation status, and technical guidance
- To perform any other assignment as assigned by the supervisor(s)
Place of Posting:
Karachi
Assessment Interview(s)
Only shortlisted candidates strictly meeting the above-mentioned basic eligibility criteria will be invited for panel interview(s).
Employment Type:
The employment will be on contractual basis for three years which may be renewed on discretion of the Management. Selected candidates will be offered compensation package and other benefits as per Bank’s Policy / rules.
Apply within 10 working days from the date of this job posting.
Applications received after due date will not be considered in any case. No TA / DA will be admissible for interview.
National Bank of Pakistan is an equal opportunity employer and welcomes applications from all qualified individuals, regardless of gender, religion, or disability.