Manager GRC

Job Details:

    • Manage and execute Information Security Governance, Risk & Compliance (GRC) activities to ensure that the organization’s information security, cybersecurity, privacy, technology risk and AI governance practices remain aligned with applicable regulatory requirements, international standards, organizational policies and enterprise risk appetite.
    • The role will support the Head of GRC in managing information security governance, risk assessments, regulatory compliance, audit and assurance, security control monitoring, third-party risk, privacy and emerging technology governance. The position will coordinate with business, technology and control functions to identify, assess, track and remediate information security risks and compliance gaps.
    • Information Security Governance
    • • Manage the implementation and continuous improvement of the Information Security Governance framework.
    • • Support the development, review and maintenance of information security policies, standards, procedures and control frameworks.
    • • Translate regulatory and organizational requirements into applicable security controls, processes and governance requirements.
    • • Coordinate with relevant stakeholders to ensure security governance requirements are implemented and maintained.
    • • Maintain governance trackers for security initiatives, management decisions, risk acceptances and agreed actions.
    • • Support the Head of GRC in preparing management, executive and committee-level security governance reports.
    • • Monitor progress against information security objectives, initiatives and maturity improvement plans.
    • Information Security Risk Management
    • • Coordinate information security and cybersecurity risk assessments across applications, infrastructure, technology, data, third parties and business processes.
    • • Maintain and regularly update the Information Security Risk Register.
    • • Ensure identified risks are appropriately assessed, documented, treated, monitored and escalated.
    • • Review risk treatment plans, residual risks and compensating controls in coordination with relevant stakeholders.
    • • Facilitate the risk acceptance process and ensure required management approvals are obtained and documented.
    • • Monitor remediation of information security and cybersecurity risks and escalate overdue or material risks through defined governance forums.
    • • Support alignment of information security risk management activities with the organization's Risk Appetite Framework.
    • • Prepare periodic risk reports, dashboards and management updates covering key security risks and remediation status.
    • Regulatory Compliance
    • • Manage information security compliance activities against applicable regulatory and organizational requirements, including State Bank of Pakistan (SBP) requirements and Group/VEON security requirements.
    • • Maintain regulatory compliance and obligation trackers for applicable information security requirements.
    • • Coordinate identification and assessment of regulatory requirements and their applicability to the organization.
    • • Track regulatory observations, compliance gaps, remediation plans and management commitments.
    • • Coordinate responses and supporting evidence for regulatory reviews and information security assessments.
    • • Provide regular visibility to management on compliance status, outstanding gaps and associated risk exposure.
    • • Ensure regulatory compliance evidence and documentation are maintained in an audit-ready manner.
    • ISO 27001 & Security Frameworks
    • • Coordinate activities related to the ISO/IEC 27001 Information Security Management System (ISMS).
    • • Support ISMS certification, surveillance audits, internal audits and continual improvement activities.
    • • Coordinate periodic review of the Statement of Applicability (SoA), information security risk assessments and applicable controls.
    • • Track ISMS findings, corrective actions and improvement plans.
    • • Support implementation and maturity assessments against recognized frameworks such as NIST Cybersecurity Framework and other applicable industry standards.
    • • Maintain relevant ISMS documentation, records and evidence.
    • PCI DSS Compliance
    • • Coordinate PCI DSS compliance activities, assessments and remediation initiatives.
    • • Liaise with relevant technology and business teams to obtain PCI DSS control evidence and address identified gaps.
    • • Coordinate engagement with Qualified Security Assessors (QSAs) and other relevant stakeholders.
    • • Maintain PCI DSS compliance trackers, action plans, exceptions and compensating controls.
    • • Monitor remediation of PCI DSS findings and escalate overdue or material issues.
    • • Support alignment of payment security requirements with relevant business and technology initiatives.
    • Security Control Governance & Assurance
    • • Coordinate GRC oversight of key information security controls, including:
    • o Vulnerability Management
    • o Privileged Access Management
    • o Identity and Access Management
    • o Endpoint Security
    • o SIEM/SOC
    • o Data Loss Prevention
    • o Security Monitoring
    • o Security Configuration
    • o Security Operations and Resilience Controls
    • • Monitor control effectiveness through defined KRIs, KPIs, control assessments and assurance activities.
    • • Coordinate periodic control assessments and identify control gaps and improvement opportunities.
    • • Work with control owners to develop remediation plans and track closure of identified gaps.
    • • Escalate material control deficiencies and overdue remediation activities to the appropriate management forums.
    • • Support cybersecurity resilience and operational readiness assessments.
    • Third-Party & Technology Risk
    • • Coordinate information security governance activities for third-party, cloud, managed service and technology engagements
    • • Bachelor's or Master's degree in Information Security, Cybersecurity, Computer Science, Information Technology or a related discipline.
    • • Relevant professional certifications such as CISM, CISA, ISO/IEC 27001 Lead Auditor/Implementer or equivalent are desirable.
    • • Relevant experience in information security governance, cybersecurity risk, compliance, audit, regulatory compliance or technology risk management.
    • • Working knowledge of ISO/IEC 27001, NIST Cybersecurity Framework, PCI DSS, information security risk management and cybersecurity governance.
    • • Understanding of information privacy, data protection and emerging AI governance requirements.
    • • Experience in coordinating with business, technology, risk, audit and compliance stakeholders.
    • • Experience in preparing management reports, risk dashboards, compliance assessments and audit responses.
    • • Strong analytical, documentation, communication and stakeholder management skills.
    • • Ability to manage multiple GRC activities, prioritize deliverables and track remediation within defined timelines.

Job Locations:

  • Head Office

About MMBL:

Mobilink Microfinance Bank Ltd. is providing banking services to over 48 million registered users including 20+ million monthly active customers across Pakistan. With a hybrid model that combines traditional microfinance with mobile/digital banking technologies, the bank now operates with over 114 branches and 270,000 branchless banking agents and provides a USSD (GSM) based digital channel offering savings, micro enterprise (MSME) loans, small housing loans, remittances, collection (utility bills and loan installments), mobile wallets, insurance, G2P, B2B & B2P payments; thus, playing a leading role in the promotion of financial inclusion. MMBL is committed to fostering a positive and productive workplace, and our core values reflect this focus. These values include promoting innovation and entrepreneurship, encouraging teamwork and collaboration, and prioritizing a customer-centric approach in all aspects of our business.

Why Join MMBL ?

This is an opportunity for someone who is passionate about making a difference and playing a key role in driving transformative change. Our team is committed to empowering millions with the tools necessary to succeed in the digital age, and we're looking for a talented individual to join us in this endeavor.

Short Description
  • Job Type:

    Permanent
  • Positions:

    1
  • Posted On:

    Sep 30, 2026
  • Last Date:

    Oct 02, 2026
  • Grade:

    AVP
  • Department:

    Information Security