Protego, a prominent information security services firm specializing in infosec, compliance, and governance for regulated sectors such as financial services, fintech, and RegTech, is looking to hire a Senior Information Security Manager based in Pakistan. This full-time leadership position reports directly to the CTO and focuses on building and managing a client-facing security practice. The role demands a combination of hands-on technical expertise, client relationship management, and team leadership. The successful candidate will oversee strategy, certification services, and client delivery across multiple service lines, supported by a junior analyst.

Key Responsibilities

Governance, Risk & Compliance (GRC): Lead ISO 27001 gap assessments, ISMS implementation, and certification readiness for clients. Manage risk registers, third-party/vendor risk assessments, and provide regulatory advisory services covering SOC 2, ISO 27701, PCI DSS, GDPR, and local data protection compliance. Act as a virtual Chief Information Security Officer (vCISO), offering outsourced security leadership. Maintain policy and documentation templates and manage client relationships with certification bodies and security due diligence processes.

Technical Assurance: Develop and execute penetration testing strategies across web, API, mobile, infrastructure, and cloud environments. Oversee secure code reviews (both manual and automated), cloud security posture assessments on AWS and Azure, architecture reviews, and ongoing vulnerability management. Manage third-party penetration testing vendors, ensuring quality and remediation tracking.

Managed Security & IT Governance: Establish IT governance policies including access control, multi-factor authentication (MFA), patch management, and backup verification. Oversee outsourced IT governance services such as license and asset lifecycle management, endpoint security monitoring, and access/identity governance. Lead incident response planning, conduct tabletop exercises, and serve as incident commander when needed.

Advisory: Provide virtual CISO retainer services and design customized security awareness training programs tailored to client needs.

Client & Engagement Management: Scope, price, and manage security engagements across all service lines. Own client relationships from project kickoff through delivery, reporting, and renewal discussions. Ensure service quality and adherence to service level agreements (SLAs). Contribute to proposals, RFP responses, and sales support activities.

Leadership: Mentor and manage the Junior Information Security Analyst by delegating governance and administrative tasks appropriately. Report on security posture, risk, engagement pipeline, and delivery quality to Protego’s leadership team.

Required Qualifications

A minimum of six years’ experience in information security with strong hands-on expertise in at least three of the following areas: compliance/ISMS/GRC, penetration testing, secure code review, and IT governance. Proven success in implementing and maintaining ISO 27001 ISMS, with Lead Implementer or Lead Auditor certification preferred. Working knowledge of GDPR and data protection regulations sufficient to advise clients and scope engagements. Solid penetration testing background supported by certifications such as OSCP or CEH is preferred. Familiarity with secure code review tools and practices, including OWASP Top 10 and SAST/DAST methodologies. Experience operating as a vCISO or outsourced security leader, advising client executives directly. Strong communication skills with the ability to brief executives and mentor junior staff. Experience in regulated industries such as fintech, RegTech, or banking is highly desirable. Demonstrated ability to deliver security consulting services to external clients, including scoping, managing expectations, and producing client-ready deliverables.

Preferred Qualifications and Benefits

Prior experience in security consultancy, managed security service providers (MSSP), or professional services environments is advantageous. Cloud security expertise, especially in AWS and Azure, including cloud security posture assessments, is preferred. Familiarity with SOC 2, ISO 27701, or PCI DSS scoping is a plus. Scripting and automation skills in languages such as Python or Bash are beneficial. Experience with proposal writing, statement of work drafting, or pre-sales technical support is valued. Protego offers a competitive market salary along with the option to participate in an Employee Stock Ownership Plan (ESOP).

Protego is an equal opportunity employer and encourages applications from candidates of diverse backgrounds. This role provides a significant opportunity to lead Protego’s security service delivery across governance, technical assurance, managed security, and advisory services, contributing to the company’s growth and client success within the first 6 to 12 months.

Job Details

Total Positions:
1 Post
Job Shift:
First Shift (Day)
Job Type:
Job Location:
Gender:
No Preference
Age:
18 - 65 Years
Minimum Education:
Bachelors
Career Level:
Manager
Experience:
6 Years - 10 Years
Apply Before:
Aug 20, 2026
Posting Date:
Aug 14, 2026

Idenfo

· 11-50 employees - Karachi

What is your Competitive Advantage?

Get quick competitive analysis and professional insights about yourself
Talk to our expert team of counsellors to improve your CV!
Try Rozee Premium

Similar Job Titles

Security Engineer

Dime Republic, Lahore, Pakistan
Posted Jul 27, 2026

Soc Analyst

Kidan, , Pakistan
Posted Jul 22, 2026
View All
I found a job on Rozee!