Manager IS Strategy & Policies (AVP)
National Bank of Pakistan
Published Date: • Karachi, Pakistan (On-Site)
Description
"The Nation's Bank", National Bank of Pakistan aims to support the financial well-being of the Nation along with enabling sustainable growth and inclusive development through its wide local and international network of branches. Being one of the leading and largest banks of Pakistan, National Bank of Pakistan is contributing significantly towards socioeconomic growth in the country with an objective to transform the institution into a future-fit, agile and sustainable Bank.
In line with our strategy, the Bank is looking for talented, dedicated, and experienced professional(s) for the following position in the area of Risk Management based at Karachi.
The individuals who fulfill the below basic-eligibility criteria may apply for the following position:
Position / Job Title:
Manager IS Strategy & Policies (AVP)
Reporting to:
Unit Head - IS Strategy & Policies
Educational /Professional Qualification:
- Minimum Graduation in Computer Science and / or Computer Engineering and / or Cybersecurity and / or Information Technology from a local or international university / college / institute recognized by the HEC of Pakistan
- Candidates having Master’s or have any other relevant professional certification(s) such as CISM, CISA, ISO / IEC 27001 Lead Implementer or Lead Auditor, CGEIT, PCI DSS Professional related training), etc. will be preferred
Experience:
- Minimum 06 years of experience in Information Security and / or Cybersecurity and / or Information Technology Risk and / or IT Governance and / or Compliance
- Candidates having managerial or supervisory experience in Information Security Governance, Risk & Compliance (GRC), Information Security Strategy, Policy Management or a similar function will be preferred
Other Skills / Expertise / Knowledge Required:
- Strong knowledge of ISO 27001, NIST, COBIT, PCI DSS, SWIFT CSP, and regulatory requirements are required
- Good understanding of information security governance, enterprise risk management, technology risk, third party risk, cloud security and data protection principles
- Ability to work effectively as a team player, manage stakeholder relationships, and prioritize competing tasks to meet deadlines in an environment
Outline of Main Duties / Responsibilities:
- To develop, maintain and periodically review Information Security governance documentation, including policies, standards, procedures, guidelines, frameworks and related documentation
- To review new and existing bank policies, procedures, products, projects, and initiatives from an information security governance and regulatory compliance perspective
- To define, monitor and report Information Security Key Performance Indicators (KPIs), Key Risk Indicators (KRIs) and other governance metrics
- To monitor compliance with applicable information security standards, frameworks and regulatory requirements, including ISO / IEC 27001, PCI DSS, SWIFT CSP, and other applicable regulations
- To oversee third party information security governance, including security due diligence, contractual security requirements and ongoing compliance monitoring
- To identify, assess and ensure the timely implementation of applicable regulatory, legal, contractual and industry information security requirements
- To facilitate information security risk assessments, regulatory inspections, supervisory reviews, and independent security assessments
- To evaluate, implement and manage GRC tools and automation solutions to enhance governance, risk management, compliance monitoring and reporting
- To oversee and prepare governance, risk, and compliance reports for senior management and Board committees
- To perform any other assignment as assigned by the supervisor(s)
Place of Posting:
Karachi
Assessment Interview(s)
Only shortlisted candidates strictly meeting the above-mentioned basic eligibility criteria will be invited for panel interview(s).
Employment Type:
The employment will be on contractual basis for three years which may be renewed on discretion of the Management. Selected candidates will be offered compensation package and other benefits as per Bank’s Policy / rules.
Apply within 10 working days from the date of this job posting.
Applications received after due date will not be considered in any case. No TA / DA will be admissible for interview.
National Bank of Pakistan is an equal opportunity employer and welcomes applications from all qualified individuals, regardless of gender, religion, or disability.