Idenfo

Senior Information Security Manager

Idenfo  •  Karachi, PK (Onsite)  •  2 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Senior Information Security Manager - Hiring for Protego

Company: Protego (Information Security Services)
Location: Pakistan
Reports to: CTO, Protego
Employment Type: Full-time

ABOUT PROTEGO

Protego is an information security services company providing infosec, compliance, and governance services to clients across regulated industries — including financial services, fintech, banking technology, and RegTech.

As Protego scales its service delivery capability, you will lead the technical and compliance security practice — owning strategy, certification services, and client delivery, with a junior team member supporting day-to-day execution and IT governance tasks.

This is a leadership role for someone who wants to build and run a client-facing security practice, balancing hands-on technical delivery with account ownership and service quality.

You will own Protego's security service delivery end-to-end across four service lines, focused on:

  1. Governance, Risk & Compliance (GRC) — ISO 27001 certification & ISMS implementation, vCISO/Information Security Office as a Service, risk assessment & risk register management, third-party/vendor risk management, and regulatory advisory (SOC 2, ISO 27701, PCI DSS, GDPR and local data protection).
  2. Technical Assurance — penetration testing, secure code review, cloud security posture assessment, architecture & configuration review, and vulnerability management.
  3. Managed Security & IT Governance — outsourced IT governance (license/asset lifecycle), endpoint security monitoring, access & identity governance, and incident response planning.
  4. Advisory — virtual CISO retainers and security awareness training.
  5. Client & Engagement Management — scoping, delivery quality, reporting, relationship ownership across all of the above.

You will also mentor and direct the Junior Information Security Analyst, and contribute to Protego's service offering and proposal/scoping work as the client base grows.

KEY RESPONSIBILITIES

1. Governance, Risk & Compliance (Primary Owner)

  • Lead ISO 27001 gap assessments, ISMS implementation, and certification-readiness consulting for Protego's clients — owning the Statement of Applicability, risk register, and control framework on their behalf.
  • Deliver Information Security Office as a Service (vCISO) engagements — acting as outsourced security leadership for clients who need the function without a full-time hire.
  • Own risk assessment and risk register management for client engagements, keeping registers current as client environments change.
  • Lead third-party and vendor risk management engagements — assessing the risk clients' own suppliers introduce.
  • Deliver regulatory and framework advisory, including GDPR and other data protection regulation compliance (data mapping, DPIA support, breach-notification readiness), alongside SOC 2 readiness, ISO 27701, and PCI DSS scoping.
  • Manage relationships with certification bodies on behalf of clients — audits, surveillance visits, recertification.
  • Own the policy and documentation templates Protego uses across client engagements, and their periodic review.
  • Lead responses to client security due diligence and questionnaires on behalf of clients Protego supports.

2. Technical Assurance (Program Owner)

  • Define the pentest strategy and calendar across web, API, mobile, infrastructure, and cloud for client engagements.
  • Perform or directly oversee execution of tests; review and quality-check findings before reports go to clients.
  • Own severity rating methodology (CVSS), client-facing report standards, and remediation tracking to closure.
  • Establish the secure code review process (manual + SAST/DAST) and integrate it into client SDLCs; personally review higher-risk/complex code (auth, payments, data handling, cryptography).
  • Deliver cloud security posture assessments (AWS/Azure) and architecture/configuration reviews for client environments.
  • Own an ongoing vulnerability management service for clients — scanning, triage, and reporting on a defined cadence, not one-off point-in-time reports.
  • Manage third-party pentest vendor/subcontractor relationships where independent/certified attestation or surge capacity is required.

3. Managed Security & IT Governance (Strategic Oversight)

  • Set IT governance policy (access control, MFA, patch management, vendor risk, backup verification) and hold the junior analyst accountable for day-to-day execution, both for Protego's own IT and for clients on managed service engagements.
  • Own outsourced IT governance as a client-facing managed service — license/asset lifecycle management and endpoint security monitoring delivered on a subscription basis.
  • Own access and identity governance for client engagements — provisioning/de-provisioning and access reviews run on a fixed schedule.
  • Own incident response planning and tabletop exercise delivery for clients, and act as incident commander when needed.

4. Advisory

  • Deliver virtual CISO retainer engagements — ongoing strategic security leadership for clients on a recurring monthly basis.
  • Design and deliver security awareness training programs tailored to client organisations.

Client & Engagement Management

  • Scope and price security engagements across all four service lines in collaboration with Protego leadership.
  • Own client relationships for security engagements — kickoffs, status reporting, findings walkthroughs, and renewal/upsell conversations.
  • Ensure engagement quality and SLA adherence across concurrent client work.
  • Contribute security expertise to proposals, RFP responses, and sales support as Protego's client base and service catalogue grow.

Leadership

  • Mentor and manage the Junior Information Security Analyst; delegate governance/administrative tasks appropriately.
  • Report security posture, risk, engagement pipeline, and delivery quality to Protego leadership.

REQUIRED QUALIFICATIONS & EXPERIENCE

  • 6+ years in information security, with strong hands-on depth in at least three of: compliance/ISMS/GRC, pentesting, secure code review, IT governance.
  • Proven experience implementing/maintaining an ISO 27001 ISMS; Lead Implementer or Lead Auditor certification strongly preferred.
  • Working knowledge of GDPR and data protection regulation (data mapping, DPIA, breach notification) sufficient to advise clients and scope engagements.
  • Solid penetration testing background — OSCP, CEH, or equivalent preferred.
  • Familiarity with secure code review tooling and practices (OWASP Top 10, SAST/DAST).
  • Comfortable operating in a vCISO / outsourced security leadership capacity — advising client leadership directly, not just executing tasks.
  • Strong stakeholder communication — able to brief executives and mentor junior staff.
  • Experience in a regulated industry (fintech, RegTech, banking) is a strong plus given Protego's client base.
  • Experience delivering security services or consulting to external clients (as opposed to purely internal security work) — including scoping engagements, managing client expectations, and producing client-ready deliverables.

PREFERRED / NICE TO HAVE

  • Prior experience in a security consultancy, MSSP, or professional services environment.
  • Cloud security experience (AWS/Azure), including cloud security posture assessment.
  • Experience with SOC 2, ISO 27701, or PCI DSS scoping.
  • Scripting/automation skills (Python, Bash).
  • Exposure to proposal writing, SOW drafting, or pre-sales technical support.

WHAT SUCCESS LOOKS LIKE (FIRST 6–12 MONTHS)

  • ISMS scoping and gap assessments delivered for Protego's first client engagements, with a clear path mapped to ISO 27001 certification/recertification for each.
  • At least one vCISO or GDPR advisory engagement scoped and running.
  • Pentest and secure code review programs running on a defined cadence for client engagements, with tracked remediation.
  • IT governance and managed security policies defined, with the junior analyst operating effectively against them — both internally and on at least one client managed-service engagement.
  • Documented incident response plan tested at least once, either internally or with a client.
  • Clear service catalogue and pricing model established across all four service lines (GRC, Technical Assurance, Managed Security & IT Governance, Advisory).

COMPENSATION & BENEFITS

Market-competitive salary, with the option for ESOPs (Employee Stock Ownership Plan).

Protego is an equal opportunity employer. We welcome applications from candidates of all backgrounds.

Idenfo

About Idenfo

Idenfo provides a full suite of compliance solutions and services.

We offer 4 key services -

1.) A bespoke compliance healthcheck, where we will:

- Provide advisory to your current compliance framework

- Review your operations with a view to outsourcing AML services

- Evaluate your end-to-end AML system processes

2.) Consultancy in the following areas:

- Institutional Risk Assessment

- Risk Assessment – KYC, CDD and EDD

- AML Policies and Procedures

- Transaction Monitoring and Sanction Screening

3.) The following outsourced services:

- Refreshed customer information

- Risk based due diligence

- Transaction Monitoring alerts management

- Sanctions, PEP and adverse media screening

4.) An out of the box modular configurable AML solution:

- Digital onboarding

- Facial Recognition and Liveness Check

- Name Screening

- Risk Rating analysis

- Background Verification and Financial Crime Checks

Industry
Unknown
Company Size
51-200 employees
Headquarters
Norwich, GB
Year Founded
Unknown
Social Media