Role: Assistant Manager Information Security | Department: Cloud | City: Islamabad | Place of Work: Islamabad | Employment Type: Full Time
Key Responsibilities:
Job Summary:
The Assistant Manager – Information Security will be responsible for strengthening information security governance, risk management, and compliance across the organization. The role involves managing ISMS, ensuring compliance with ISO 27001, ISO 27017, and PCI DSS, conducting security risk and vendor assessments, coordinating audits, monitoring security controls, and driving awareness and continuous improvement initiatives.
Job Description:
Governance & Compliance
- Develop, review, and maintain information security policies, standards, and procedures.
- Support implementation and continuous improvement of the Information Security
Management System (ISMS).
- Ensure compliance with ISO 27001, ISO27017, PCI DSS, and applicable regulatory requirements.
- Coordinate internal and external security audits and track remediation of audit findings.
Risk Management
- Conduct information security risk assessments and maintain the risk register.
- Review security controls for new projects, systems, and cloud deployments.
- Track risk treatment plans and ensure timely mitigation of identified risks.
Security Operations Governance
- Monitor compliance with security baselines, vulnerability remediation SLAs, and access review processes.
- Review security incidents to identify control gaps and recommend corrective actions.
- Coordinate with SOC and infrastructure teams to improve operational security controls.
Security Awareness & Reporting
- Plan and deliver security awareness and phishing simulation programs.
- Prepare periodic reports on security risks, compliance status, audits, and governance metrics.
- Recommend improvements to security processes and governance practices.
Job Specification:
Education: BS / MS in Information TechnologyExperience: 4-5 years of relevant experience
Job Related Competencies:
- Information Security Operations/GovernanceRisk Assessment & Risk Management
- ISMS & ISO 27001
- Security Audits & Compliance
- Policy Development
- Third-Party Risk Management
- Security Awareness
- Strong analytical, communication, and stakeholder management skills
Personal Competencies:
- Analytical Thinking
- Attention to Detail
- Communication Skills
- Integrity & Ethical Judgment
- Problem-Solving
Eligibility / Qualification Required:
Job Summary:
The Assistant Manager – Information Security will be responsible for strengthening information security governance, risk management, and compliance across the organization. The role involves managing ISMS, ensuring compliance with ISO 27001, ISO 27017, and PCI DSS, conducting security risk and vendor assessments, coordinating audits, monitoring security controls, and driving awareness and continuous improvement initiatives.
Job Description:
Governance & Compliance
- Develop, review, and maintain information security policies, standards, and procedures.
- Support implementation and continuous improvement of the Information Security
Management System (ISMS).
- Ensure compliance with ISO 27001, ISO27017, PCI DSS, and applicable regulatory requirements.
- Coordinate internal and external security audits and track remediation of audit findings.
Risk Management
- Conduct information security risk assessments and maintain the risk register.
- Review security controls for new projects, systems, and cloud deployments.
- Track risk treatment plans and ensure timely mitigation of identified risks.
Security Operations Governance
- Monitor compliance with security baselines, vulnerability remediation SLAs, and access review processes.
- Review security incidents to identify control gaps and recommend corrective actions.
- Coordinate with SOC and infrastructure teams to improve operational security controls.
Security Awareness & Reporting
- Plan and deliver security awareness and phishing simulation programs.
- Prepare periodic reports on security risks, compliance status, audits, and governance metrics.
- Recommend improvements to security processes and governance practices.
Job Specification:
Education: BS / MS in Information TechnologyExperience: 4-5 years of relevant experience
Job Related Competencies:
- Information Security Operations/GovernanceRisk Assessment & Risk Management
- ISMS & ISO 27001
- Security Audits & Compliance
- Policy Development
- Third-Party Risk Management
- Security Awareness
- Strong analytical, communication, and stakeholder management skills
Personal Competencies:
- Analytical Thinking
- Attention to Detail
- Communication Skills
- Integrity & Ethical Judgment
- Problem-Solving
How to Apply:
Apply through the official Master Group job detail page.
Apply Now