Employer: Sui Southern Gas Company Limited (SSGC)
Job Code: 8513-01
Position: Engineer / Deputy Manager – IT Risk Management
Department: Not specified
Campus: SSGC
Job Type: Not specified (assumed full-time)
Location: Karachi
Deadline: 2026-01-12
Job Summary: Coordinate with the IT department to prepare and update departmental risk registers and provide periodic progress reports to management.
Eligibility / Qualification Required:
- Bachelor’s in Computer Science / Information Technology or related field with at least 4 years of relevant experience; OR Bachelor’s in Computer Engineering with at least 2 years of relevant experience.
- In-depth knowledge of IT Risk Management, Cyber Security, Information security standards and regulations (e.g., NIST 800-53, ISO-2700X, COBIT, ITIL).
- Preferred certifications: CISA, CRISC, CISSP.
- Training in ISO 31000 on risk management will be a plus.
- PEC registration is mandatory for engineers only.
Responsibilities:
- Identify controls based on risks for compliance areas of IT business processes.
- Support design, implementation and amendment of controls.
- Enable continuous improvement and provide guidance for maintaining relevant controls catalogue.
- Monitor performance of IT controls for timely and effective execution.
- Report on risks and control effectiveness to Risk Management Committee and Risk & Litigation Committee.
- Set standards, operating procedures, templates and tooling.
- Maintain risk register and track exposures against risk appetite.
- Escalate challenges in executing change (stakeholder commitment, technical complexity, resource limitations) timely.
- Embed ownership and awareness via training and communication to control owners (first line of defense).
- Foster an intelligent risk culture across SSGC through communication and training.
- Implement SSGC-wide Information Security risk management function.
- Participate in establishing and quantifying IT department’s risk appetite.
- Provide inputs to maintain enterprise risk management system up-to-date.
- Coordinate with department to finalize entries in risk registers.
- Assist IT department in information systems risk assessment for availability, integrity and confidentiality of data and systems.
- Contact departments to check progress of mitigation actions.
- Assist in training and awareness sessions on risk management.
- Prepare monthly reporting for management on risks and mitigation actions.
- Highlight risks needing acceptance where no appropriate action exists.
- Assist in reducing, accepting, transferring or avoiding IT risks as appropriate.
- Contribute risk awareness articles for company magazines.
- Ensure compliance with Enterprise Risk Management Framework in assigned role.
- Ensure compliance with Business Principles and Ethics Policy / Code of Conduct.
- Perform any other task assigned by superiors.
How to Apply:
- Apply online through the official SSGC Careers portal.
- Careers page: https://www.ssgc.com.pk/careers/
- Login: https://www.ssgc.com.pk/careers/hr_login.php
- New users can register here: https://www.ssgc.com.pk/careers/hr_register.php
- Submit your application before the deadline listed above.