Unit Head - IS GRC International (AVP / VP)
National Bank of Pakistan
Published Date: • Karachi, Pakistan (On-Site)
Description
"The Nation's Bank", National Bank of Pakistan aims to support the financial well-being of the Nation along with enabling sustainable growth and inclusive development through its wide local and international network of branches. Being one of the leading and largest banks of Pakistan, National Bank of Pakistan is contributing significantly towards socioeconomic growth in the country with an objective to transform the institution into a future-fit, agile and sustainable Bank.
In line with our strategy, the Bank is looking for talented, dedicated, and experienced professional(s) for the following position in the area of Risk Management based in Karachi.
The individuals who fulfill the below basic-eligibility criteria may apply for the following position:
Position / Job Title:
Unit Head - IS GRC International (AVP / VP)
Reporting to:
Wing Head - IS Governance & Compliance
Educational /Professional Qualification:
Minimum Graduation in Computer Science and / or Computer Engineering and / or Cybersecurity and / or Information Technology from a local or international university / college / institute recognized by the HEC of Pakistan
Candidates having Master’s or any other relevant professional certification(s) such as CISSP, CCSP / CCSK, CISM, ISO / IEC 27001 Lead Implementer or Lead Auditor, CGEIT, PCI DSS, Professional related training, will be preferred
Experience:
Minimum 06 years of experience in Information Security and / or Cybersecurity and / or Risk Management and / or Information Technology Risk and / or IT Governance and /or Compliance and / or relevant disciplines
Candidates who have worked at a managerial or supervisory level covering international security frameworks & data protection will be preferred
Other Skills / Expertise / Knowledge Required:
Strong knowledge of regulatory requirements and international information security standards, frameworks and best practices including ISO 27001, NIST, COBIT, PCI DSS SWIFT CSP
Strong knowledge of banking regulations and international supervisory expectations
Experience in third party assessments, cloud security and cybersecurity compliance requirements applicable to international banking operations
Good communication skills
Ability to work effectively as a team player and manage stakeholder relationships
Ability to work in a competitive environment and prioritize deadlines
Outline of Main Duties / Responsibilities:
To lead and manage the Information Security Governance, Risk & Compliance (IS GRC) and Data Protection function for the Bank's international operations, ensuring alignment with the Bank's Information Security Strategy, International Standards and regulatory requirements
To develop, implement and maintain information security governance frameworks, policies, standards, procedures and guidelines in accordance with Bank's international operations
To conduct and oversee information security risk assessments, control reviews, and compliance assessments relating to international operations and data protection initiatives
To prepare and present governance dashboards, risk reports, compliance status, Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs) to senior management and relevant governance committees
To oversee continuous improvement initiatives of the Bank's Information Security Programs, including DLP, Vulnerability Assessment, Penetration Testing, Infrastructure and Application Security controls across international branches and representative offices
To coordinate international certifications and attestations (e.g., ISO / IEC 27001, SWIFT CSP, PCI DSS, where applicable)
To oversee remediation of information security internal and external audits, regulatory inspections, and compliance reviews across international branches
To monitor third party and outsourcing security governance for international operations, where applicable
To lead awareness and training initiatives on information security, privacy and data protection requirements across international branches and representative offices
To represent the Information Security Division in meetings with regulators, external auditors, international branches, business units, and other stakeholders on Bank's overall information security governance and control environment
To perform any other assignment as assigned by the supervisor(s)
Place of Posting:
Karachi
Assessment Interview(s)
Only shortlisted candidates strictly meeting the above-mentioned basic eligibility criteria will be invited for panel interview(s).
Employment Type:
The employment will be on contractual basis for three years which may be renewed on discretion of the Management. Selected candidates will be offered compensation package and other benefits as per Bank’s Policy / rules.
Apply within 10 working days from the date of this job posting.
Applications received after due date will not be considered in any case. No TA / DA will be admissible for interview.
National Bank of Pakistan is an equal opportunity employer and welcomes applications from all qualified individuals, regardless of gender, religion, or disability.