Navbar Example Job Listings
Senior Information Security Engineer - GRC
← BACK

Senior Information Security Engineer - GRC

DESCRIPTION:

Role 

We are looking for a Senior Information Security/ GRC Consultant to support and independently deliver cybersecurity Governance, Risk, Compliance, audit, and related advisory engagements. The candidate should have strong consulting experience and the ability to manage client assignments, assessments, and deliverables with limited supervision. 

Key Responsibilities 

Lead and deliver GRC, cybersecurity risk, compliance, and audit engagements. 

Conduct assessments against ISO 27001, NCA ECC, SAMA CSF, PDPL, SOC 2, NIST/ COBIT and other relevant frameworks. 

Perform cybersecurity risk assessments, control assessments, gap assessments, and maturity assessments. 

Support Business Continuity Management (BCM) assessments, including BIA, risk assessment, and review of continuity and recovery arrangements. 

Develop and review information security policies, procedures, standards, and supporting documentation. 

Prepare risk registers, compliance matrices, findings, remediation plans, and professional assessment reports. 

Support ISO 27001 implementation, internal audits, and certification/surveillance audits. 

Review audit evidence and assess the effectiveness of implemented controls. 

Conduct client workshops and coordinate with business and technical stakeholders. 

Present assessment findings, risks, and recommendations to clients and management. 

Support and review the work of junior GRC consultants. 

Requirements 

Bachelor’s degree in Cybersecurity, Computer Science, IT, or a related field. 

5–6 years of relevant experience in GRC, cybersecurity, IT audit, risk, compliance, or information security consulting. 

Strong practical experience with ISO 27001 and cybersecurity risk management. 

Good understanding of NCA ECC, SAMA CSF, SAMA BCM, PDPL, SOC 2, and other relevant frameworks. 

Experience in policy and procedure development, control assessment, audit, and compliance reporting. 

Understanding of risk management, Business Continuity, Disaster Recovery, and related controls. 

Experience with GRC platforms such as RSA Archer, ServiceNow GRC, MetricStream, Riskonnect, or similar platforms. 

Experience developing GRC dashboards, risk reporting, KRIs, and management-level metrics. 

Experience in third-party/vendor risk management. 

Experience with cloud security risk assessments. 

Strong analytical, documentation, report-writing, presentation, and client-facing skills. 

Ability to independently manage assigned consulting activities and meet project timelines. 

Preferred Certifications 

CISA, CRISC, CISSP, ISO 27001 Lead Auditor/Lead Implementer, ISO 22301, or equivalent certifications. 

Candidate Profile 

The preferred candidate should be able to independently lead GRC assignments, understand both business and technical cybersecurity requirements, engage confidently with clients, and convert regulatory/framework requirements into practical controls, risks, findings, and remediation actions. 

The role is intended for a consultant who can contribute immediately to client delivery, assessment execution, report development, and GRC advisory activities, while also supporting and mentoring junior team members. 

 

Lahore

  • Location: Lahore
  • Openings: 1
  • Salary Range: