Information Security Engineer
Job Description
Job Description: GRC & Information Security Specialist
Experience Required: 4–5 Years Department: Information Security / Risk & Compliance Location: Islamabad
About the Role
We are looking for a GRC & Information Security professional with 4–5 years of hands-on experience to manage governance, risk, and compliance activities while supporting the organization's broader information security posture. The ideal candidate bridges technical security knowledge with regulatory/compliance frameworks and can work independently with stakeholders across IT, audit, and business teams.
Key Responsibilities
Governance, Risk & Compliance (GRC) • Develop, implement, and maintain information security policies, standards, and procedures • Conduct periodic risk assessments and maintain the organizational risk register • Manage compliance with frameworks/standards such as ISO 27001, NIST CSF, SOC 2, PCI-DSS, GDPR, HIPAA (as applicable) • Coordinate internal and external audits; track findings through to remediation • Perform vendor/third-party risk assessments (TPRM) • Maintain evidence repositories and control documentation for audits and certifications • Support Business Continuity/Disaster Recovery (BCP/DR) planning and testing
Information Security Operations • Support vulnerability management program — coordinate scanning, tracking, and remediation with IT teams • Assist in incident response — documentation, root cause analysis, and post-incident reporting • Review security architecture/configurations for policy and compliance alignment • Monitor security controls (access management, encryption, logging, DLP) for effectiveness • Support security awareness training programs and phishing simulation campaigns • Track regulatory changes and translate them into actionable internal controls
Reporting & Stakeholder Management • Prepare risk and compliance dashboards/reports for leadership and audit committees • Liaise with internal audit, legal, and business units on security and compliance matters • Assist in maintaining metrics/KPIs for security program maturity
Required Skills & Qualifications • Bachelor's degree in Information Security, Computer Science, IT, or related field • 4–5 years of experience in GRC, Information Security, or IT Audit roles • Strong knowledge of frameworks: ISO 27001, NIST, COBIT, PCI-DSS, GDPR • Hands-on experience with risk assessment methodologies and control testing • Familiarity with GRC tools (e.g., ServiceNow GRC, Archer, MetricStream) is a plus • Understanding of network security, IAM, endpoint security, and cloud security basics • Experience with audit coordination (internal/external, ISO surveillance audits, etc.) • Excellent documentation, communication, and stakeholder management skills
Preferred Certifications • ISO 27001 Lead Implementer / Lead Auditor • CISA / CRISC / CISM • CompTIA Security+ • Certified in Risk and Information Systems Control (CRISC) — big plus
Soft Skills • Strong analytical and problem-solving mindset • Ability to communicate technical risk to non-technical stakeholders • Detail-oriented with strong documentation discipline • Comfortable working cross-functionally with IT, legal, and business teams
Job Type: Full-time
Pay: From Rs120,000.00 per month
Work Location: In person