Navbar Example Job Listings
Information Security Engineer - GRC
← BACK

Information Security Engineer - GRC

DESCRIPTION:

We are looking for an Information Security / GRC Consultant to join our cybersecurity consulting team and support client engagements covering governance, risk, compliance, audits, and information security. 

Key Responsibilities 

Deliver ISO/IEC 27001:2022 implementation, gap assessment, internal audit, and audit readiness activities. 

Conduct cybersecurity risk, compliance, and maturity assessments. 

Assess organizations against regulatory and industry frameworks such as SAMA CSF, NCA ECC, PDPL, BCM, SOC 2, and related requirements. 

Develop and review information security policies, procedures, controls, and supporting records. 

Perform control assessments, evidence validation, findings analysis, and remediation tracking. 

Support clients during certification, surveillance, and external audits. 

Prepare professional assessment reports, findings registers, remediation roadmaps, and management presentations. 

Coordinate with client stakeholders and control owners to obtain and validate audit evidence. 

Support cybersecurity risk assessments, including cloud environments. 

Contribute to GRC platform implementation, workflow development, and compliance reporting. 

Required Skills and Experience 

Bachelor’s degree in Cybersecurity, Computer Science, Information Security, IT, or a related discipline. 

5-6+ years of experience in GRC, Information Security, IT Audit, Cybersecurity Compliance, or consulting. 

Strong hands-on experience with ISO/IEC 27001:2022

Practical experience in ISO 27001 implementation, internal audits, gap assessments, documentation, and certification support. 

Knowledge of SAMA and/or NCA cybersecurity requirements is highly desirable. 

Experience with SOC 2 and audit evidence management. 

Strong understanding of information security risk management and control frameworks. 

Excellent analytical, report-writing, documentation, and communication skills. 

Ability to work independently and interact professionally with clients. 

Preferred Certifications 

ISO 27001 Lead Auditor/Lead Implementer, ISO 22301 Lead Auditor/Lead Implementer CISA or other relevant cybersecurity/GRC certifications. 

Preferred Additional Experience 

Experience with cloud security risk assessments, cybersecurity regulatory compliance, GRC platforms, security awareness programmes, and translating technical security requirements into governance and compliance controls. 

 

Lahore

  • Location: Lahore
  • Openings: 1
  • Salary Range: