Weโre Hiring!
MCB Islamic Bank is inviting applications for the position of โUnit Head IS Compliance / Governance & IT Security Awarenessโ.
Location : Lahore
Education : Bachelors or Masterโs degree in Computer Science, Information Security or a related field.
Experience & Competenciesย
โก๏ธ Minimum 5-8 years of progressive experience in Information Security Governance, Risk & Compliance with at least 2 years in a leadership or supervisory role within banking or financial institution.
โก๏ธ Strong background in risk assessment methodologies, compliance reporting, and regulatory liaison.
โก๏ธ Excellent leadership, analytical, and problem-solving skills, with the ability to engage with senior stakeholders, regulators, and auditors.
โก๏ธ Effective communication and presentation skills, with the ability to translate complex technical and regulatory requirements into actionable insights.
โก๏ธ Professional certifications such as CISM, CISSP, CRISC, or ISO 27001 Lead Implementer / Lead Auditor (required).
โก๏ธ Demonstrated expertise in ISO 27001 ISMS implementation, PCI DSS compliance, and SBP regulatory frameworks related to information security and risk management.
Job role & Responsibilitiesย
โก๏ธ Lead the Information Security Governance, Risk & Compliance (GRC) unit to ensure effective implementation of the bankโs ISMS and regulatory compliance programs.
โก๏ธ Develop, implement, and maintain cybersecurity policies, standards, and procedures aligned with ISO 27001, SBP IT Governance & Risk Management Framework, SBP Cybersecurity Framework, and PCI DSS.
โก๏ธ Ensure continuous compliance with SBP regulatory requirements, PCI DSS controls, and other applicable security standards.
โก๏ธ Maintain the Information Security Risk Register and prepare periodic risk dashboards and reports for the Department Head โ IS GRC and CISO.
โก๏ธ Lead incident post-analysis and ensure lessons learned are incorporated into governance and control enhancements.
โก๏ธ Collaborate with IT, Risk, Compliance, and Business units to ensure alignment of GRC activities and enterprise-wide risk governance.
โก๏ธ Supervise and mentor team members within the IS GRC unit, fostering a culture of accountability, compliance, and continuous improvement.
โก๏ธ Engage with external stakeholders, including auditors, regulators, and business partners, to address compliance requirements and maintain positive relationships.
โก๏ธ Developing and delivering cybersecurity training programs for employees to raise awareness about cybersecurity best practices and promote a culture of security within the organization.
โก๏ธ Work with IT and security teams to ensure compliance with applicable information security standards and regulations, such as ISO 27001, NIST, GDPR, etc.