- Location
- Gulberg, Lahore
- Type
- Full-time
- Closing date
- Today
- Source
- ApplyToJob
Description
Sukuk Technologies is looking for an IT Governance, Risk & Compliance (IT GRC) Specialist with around 03-05 years of relevant experience.
Key Responsibilities
Qualifications & Preferred Certifications
Role Focus: This is an IT Governance, Risk & Compliance role, not a Cybersecurity GRC role. Cybersecurity-specific activities such as SOC operations, vulnerability management, penetration testing, SIEM, security architecture, threat management, and ownership of cybersecurity controls remain with the Cybersecurity function.
Key Responsibilities
- Implement, and continuously improve the IT Governance Framework,
- Establish and maintain the IT Risk Management Framework and IT Risk Register; identify, assess, monitor, and report technology risks across applications, infrastructure, cloud, databases, third parties, availability, capacity, and technology lifecycle.
- Develop, review, and maintain IT policies, standards, SOPs, and controls covering areas such as change/release management, incident/problem management, SDLC, access governance, backup and recovery, asset management, vendor management, and IT operations.
- Establish and assess IT General Controls (ITGC), identify control gaps, coordinate remediation with IT teams, maintain supporting evidence, and ensure appropriate segregation of duties.
- Coordinate internal and external IT audits, including evidence collection, audit readiness, management responses, tracking of findings, remediation actions, ownership, and closure deadlines.
- Govern and monitor IT Service Management (ITSM) processes based on ITIL/ISO 20000 principles, including incident, problem, change, service request, SLA, capacity, availability, and continual service improvement.
- Oversee governance of third-party technology vendors, business continuity and disaster recovery.
- Develop and report IT governance KPIs/KRIs and management dashboards covering technology risks, audit findings, controls, SLA performance, system availability, major incidents, changes, vendor performance, and BCP/DR readiness to the CTO and relevant governance committees.
Qualifications & Preferred Certifications
- Bachelor’s degree in Information Technology, Computer Science, Information Systems, or a related discipline, with 3–5 years of relevant experience in IT Governance, IT Risk, IT Audit, IT Controls, or IT Service Management.
- Preferred certifications knowledge: SAMA, ISO/IEC 38500, and ISO/IEC 20000.
Role Focus: This is an IT Governance, Risk & Compliance role, not a Cybersecurity GRC role. Cybersecurity-specific activities such as SOC operations, vulnerability management, penetration testing, SIEM, security architecture, threat management, and ownership of cybersecurity controls remain with the Cybersecurity function.
What we offer:
- Annual Increment
- Annual Performance Bonus
- Provident Fund
- Medical OPD/IPD/Maternity
- Social Insurance
- Paid Leaves
- Leave Encashment
- Paid Certifications
- Engagement Activities
- Reward & Recognition
- Corporate Gifts
- Annual Tour
- Team Hangouts
- Collaborative & Fostering Culture
Skills
CybersecurityPenetration TestingSIEMSOCRisk ManagementComplianceITIL