Reporting
Wing Head - Audit Entity Owner/Lead Reviewer Information & Cyber Security AuditsEducational / Professional Qualification
Minimum Graduation or equivalent from a local or international university / college / institute recognized by the HEC of Pakistan.Candidates having Master degree and / or relevant certifications such as CISM / CISA / CCSP / CISSP / ISACA would be preferred
Experience
Minimum 06 years of professional experience in Information Systems Security and / or Cyber Security and / or Information Technology Audits in Financial institutions and / or Fintech sectorsCandidates having experience in the areas of Application Security and / or Network Security, etc. will be an added advantage
Other Skills / Expertise / Knowledge Required
- Good understanding of system architecture, networks and their designs, virtualization, expertise in intrusion testing / vulnerability assessments of IT infrastructures and networks
- Knowledge / understanding of IS / Cyber security tools and techniques of Kali Linux Suite, SIEM, Security Operations Centre, Info. Sec. Tools, etc.
- Knowledge of technology infrastructure architecture and systems configurations, network designs, etc.
- Good Communication and interpersonal skills
- Ability to work in a fast-paced, deadline-driven environment that demands high quality, creative and consistent work
- Knowledge of hacking techniques and their remedies / controls to be in place
- Understanding cyber and information security related laws and regulations, best practices, etc.
- Understanding of vulnerability assessment and penetration testing reports based on automated auditing and security tools
Outline of Main Duties / Responsibilities
- To conduct audits related to Technology infrastructure, security, other IT assignments and reviews of systems, applications, etc.
- To conduct IT audit assignments as per approved IS Audit plans, perform independently or under Supervisor
- To prepare / issue draft reports, discuss with management for conclusion of draft and finalization of final audit reports
- To analyze document / report and validate the implementations of security recommendations identified during Cyber / IS / IT security audits
- To follow up the open audit issues, Management Action Plans (MAPs), etc.
- To prepare and keep updated the related audit documents such as Risks Controls Matrices (RCMs), Checklists / Audit Programs, Engagement Plans, IS / IT Manual, Guides for auditors and other pre / post audit tasks
- To prepare audit related periodical reports, MIS, etc.
- To prepare a summary of significant issues for review, compliance and reporting to senior management / BAC / etc.
- To review to ensure on the internal controls environment in the Bank for IS / IT assets and to provide assurance on integration of compliance with security best practices, frameworks, and regulations in the IT / IS projects
- To identify the vulnerabilities and flaws in related controls (design and implementation) in networks, operating systems, data centers, etc.
- To prepare information / data for SBP inspection team, external auditors and law enforcement agencies through coordinated coordinator / focal person
- To perform any other assignment as assigned by the supervisor(s)
Place of Posting
KarachiSubmit Application
Get your application noticed! Upload your CV/resume, and we'll connect you with the employer.
Submit your CV/Resume directly:
Related Jobs
Audit Team Members - Digital Banking Audits, Infrastructure & Applications
National Bank of Pakistan
Karachi, Sindh
Application Security Analyst
National Bank of Pakistan
Karachi, Sindh
Project Manager - Enterprise
National Bank of Pakistan
Karachi, Sindh
Unit Head - CBA Technology
National Bank of Pakistan
Karachi, Sindh
Database Security Analyst
National Bank of Pakistan
Karachi, Sindh