EFU Life Assurance Ltd. seeks a Deputy Manager specializing in Information Security Governance, Risk, and Compliance (GRC) to lead and strengthen the organizations cybersecurity framework. This role demands a seasoned professional with at least eight years of experience in information security and GRC, who will oversee a dedicated team of 10 professionals. The Deputy Manager ensures the company strictly adheres to regulatory standards such as ISO 27001:2022, ISO 9001, and SECP by managing compliance initiatives and fostering effective cyber risk management across infrastructure, applications, data, and operations. The role involves maintaining a robust Information Security Governance framework, spearheading audit and certification activities, and steering enterprise-wide risk and vulnerability management processes. The position requires leadership in 24/7 security monitoring and incident response, with responsibilities including managing SOC, EDR, SIEM, and Cyber Command functions. This leader also ensures timely incident management and thorough root cause analysis, while facilitating security awareness programs and preparing comprehensive risk and compliance reports for senior management and governance forums.
Responsibilities
Lead the development and maintenance of the Information Security Governance framework, including policies, standards, and procedures to ensure effective cybersecurity management.

Drive compliance with international standards such as ISO 27001:2022, ISO 9001, SECP cybersecurity regulations, and other applicable regulatory frameworks, ensuring EFU Life Assurance Ltd. remains aligned with evolving standards.

Oversee and manage internal and external audits, certifications, and regulatory reporting requirements, ensuring that organizational controls meet or exceed compliance standards.

Direct enterprise-wide risk assessment initiatives, including vulnerability management and Vulnerability Assessment and Penetration Testing (VAPT) activities covering internal, external, web, mobile, and infrastructure components.

Govern continuous 24/7 security monitoring and incident response by managing Security Operations Center (SOC), Endpoint Detection and Response (EDR), Security Information and Event Management (SIEM), and Cyber Command teams and tools.

Manage incident response processes, ensuring comprehensive root cause analysis and expedited closure of security findings to mitigate risks effectively.

Oversee third-party and vendor security assessments, evaluating contractual security controls and ensuring vendor compliance with security requirements.

Support initiatives related to data protection, privacy, business continuity, and disaster recovery, integrating these areas into the broader security program.

Lead ongoing security awareness and training programs targeted at executives and employees to cultivate a security-conscious organizational culture.

Prepare and deliver detailed risk, compliance, and security performance reports to senior management and governance committees, informing strategic decision-making.

Provide leadership and direction to a skilled team of 10 information security professionals, fostering collaboration and professional development to achieve organizational security objectives.

Job Details

Total Positions:
1 Post
Job Type:
Job Location:
Gender:
No Preference
Minimum Experience:
8 Years
Apply Before:
Aug 31, 2026
Posting Date:
Jul 30, 2026

What is your Competitive Advantage?

Get quick competitive analysis and professional insights about yourself
Talk to our expert team of counsellors to improve your CV!
Try Rozee Premium
I found a job on Rozee!