Job / Position Details:

JOB CODE:
8513-01
JOB TITLE
LOCATION
DEADLINE
Engineer / Deputy Manager – IT Risk Management
Karachi
January 12, 2026
JOB DETAILS:
Qualification & Experience:

Bachelor’s in Computer Science / Information Technology or related field with at least 4 years of relevant experience.

Or

Bachelor’s in Computer Engineering with at least 2 years of relevant experience.

 

In-depth knowledge and understanding of IT Risk Management, Cyber Security, Information or related fields, Security Standards and Regulations (e.g., NIST 800-53, ISO-2700X, COB|T, ITIL etc.)

 

Preferred Certifications in CISA, CRISC, CISSP.

Training in ISO 31000 on risk management will be a plus.

 

PEC registration is mandatory for engineers only

Responsibilities:

    JOB SUMMARY

    The purpose of this position is to coordinate with the IT department in preparing and updating the departmental risk registers. The incumbent is also responsible to prepare periodic progress reports derived from the departmental risk registers for submission to the management.


    JOB RESPONSIBILITIES

    1. Identify controls based on risks for compliance areas of IT business processes.
    2. Provide support in the design, implementation and amendment of controls.
    3.  
    4. Enable continuous improvement, maintains Business Systems, Infrastructure, SSGC controls catalogue, by providing general and technical guidance on how to maintain relevant controls 
    5. Monitor control performance of IT controls across the business for timely and effective execution.
    6.  
    7. Report on risks and control effectiveness to Risk Management Committee and Risk & Litigation Committee 
    8. Set the standards, operating procedures, templates and tooling.
    9.  
    10. Maintains risk register and track risk exposures against risk appetite.
    11.  
    12. Escalate any challenges in executing change (e.
    13. g. stakeholder commitment, technical complexity or resource limitations) in a timely manner. 
    14. Embed ownership and awareness in first line of defense via training and communication to control owners 
    15. Foster an intelligent risk culture across SSGC through communication, training etc.
    16. Implementation of SSGC-wide Information Security risk management function.
    17.  
    18. Participate in establishing and quantifying the IT department’s “risk appetite”
    19. Provide inputs in the plan to maintain the enterprise risk management system up-to-date.
    20. Coordinate with the department as per the plan in order to finalize the entries in the risk registers.
    21. Assist the IT department in carrying out a thorough information systems risk assessment to obtain an understanding of the risks to the availability, integrity and confidentiality of data and systems.
    22. Include all systems, including hardware, software, data, networks and any business processes to identify threats, vulnerabilities, probabilities of occurrence and potential impact.
    23. Contact the departments to check the progress of the actions necessary to mitigate the risks, as specified against each risk within the respective risk register.
    24. Assist in conducting training and awareness sessions relating to risk management for the employees of the user departments with a view to create a culture where risks are timely identified and removed with appropriate actions.
    25. Prepares monthly reporting for the management on the status of the identified risks and corresponding mitigation actions.
    26.  
    27. Highlight risks which needs to be accepted and for which there may not be any appropriate action.
    28.  
    29. Assist the IT department in applying the relevant approach in taking steps to reduce IT risks for some systems, accept IT risks where the department has no viable option but to live with the risks, transfer risks where all or most of the systems/assets are insured and avoid risks where the department decides not to engage in a risky activity.
    30. Contribute in articles to create risk awareness for publication in the company’s magazines.
    31.  
    32. The individual shall ensure compliance to the Enterprise Risk Management Framework enforced in the Company while performing job responsibilities in accordance with his assigned role.
    33. The individual shall ensure compliance to the Business Principles and Ethics Policy / Code of Conduct.
    34. Perform any other task assigned by superiors.