- Location
- Karachi
- Workplace
- Hybrid
- Type
- Full-time
- Department
- Operations
- Seniority
- Manager
- Experience
- 5+ years
- Closing date
- Today
- Source
- CareersPage
Description
Hiring a IT operations & Security Manager |Karachi (Hybrid)
About the Company:
Our client is an enterprise SaaS platform that helps OEMs, equipment rental companies, and resellers efficiently remarket and sell used heavy equipment. It is trusted by some of the world's leading heavy equipment manufacturers to streamline the used equipment marketplace.
Role Overview:
We are looking for an experienced IT Operations, Security, Compliance & AI Enablement Lead to own the company's internal technology operations, information security, compliance, and AI-driven business enablement. This role is responsible for ensuring our systems remain secure, reliable and compliant while continuously improving how the business operates through technology and AI.
This is a hands-on leadership role for someone who takes ownership, drives initiatives independently, and enjoys improving both technology and business processes.
Key Responsibilities:
IT Operations:
Manage the company's internal IT infrastructure, including laptops, identity management, endpoint management (MDM), networking and internal systems.
Own the complete employee onboarding, offboarding and device lifecycle.
Administer Microsoft 365, Slack, Jira, GitHub, AWS IAM, VPNs and other business-critical SaaS platforms.
Maintain hardware and software asset inventory, licensing and lifecycle management.
Provide timely technical support to employees and coordinate hardware procurement and replacements.
Develop, maintain and continuously improve IT policies, procedures and operational documentation.
Ensure business continuity through effective backup, recovery and disaster recovery processes.
Information Security:
Own and continuously improve the Information Security Management System (ISMS).
Lead ISO 27001 compliance activities and continual improvement initiatives.
Coordinate penetration testing, vulnerability assessments and remediation programmes.
Work closely with engineering teams to resolve security findings within agreed timelines.
Manage security awareness training across the organisation.
Coordinate security incident response, investigations and post-incident reviews.
Maintain security policies, standards, risk registers and security documentation.
Governance, Risk & Compliance:
Own ISO 27001 surveillance audits and future recertification activities.
Manage compliance platforms such as Sprinto (or equivalent).
Support future compliance initiatives including SOC 2 and CSA STAR.
Coordinate customer security questionnaires and due diligence requests.
Conduct internal audits and supplier security assessments.
Track compliance KPIs and regularly report progress to leadership.
Ensure company policies remain current with industry standards and regulatory requirements.
Identity & Access Management:
Manage user provisioning and deprovisioning across company systems.
Perform regular access reviews and least-privilege assessments.
Manage privileged accounts and administrative permissions.
Maintain identity governance and access control documentation.
AI Enablement & Internal Automation:
Lead the adoption of AI tools across the business to improve productivity, collaboration and operational efficiency.
Identify opportunities to automate internal business processes using AI and low-code/no-code platforms.
Evaluate, implement and optimise AI solutions for IT operations, security, compliance and employee support.
Establish governance and best practices for the secure and responsible use of AI across the organisation.
Partner with department heads to identify high-impact AI use cases and oversee successful implementation.
Stay current with emerging AI technologies and proactively recommend improvements that increase efficiency and reduce manual effort.
Vendor & Technology Management:
Manage relationships with IT, security and compliance vendors.
Evaluate and recommend new technologies that improve security, efficiency and scalability.
Ensure endpoint protection, monitoring, patch management and backup systems remain operational.
Manage software subscriptions and optimise technology costs where appropriate.
Requirements:
5+ years of experience in IT Operations, Information Security, GRC or a similar role.
Proven experience managing ISO 27001 compliance and audits.
Strong understanding of cloud security principles (AWS preferred).
Experience with Microsoft 365 administration, endpoint management (MDM), identity and access management.
Knowledge of vulnerability management, endpoint security and incident response.
Experience administering business SaaS platforms such as Slack, Jira and GitHub.
Strong documentation, organisational and project management skills.
Excellent problem-solving and communication abilities.
Ability to independently drive initiatives with minimal supervision.
Nice to Have
Experience with SOC 2, CSA STAR or similar security frameworks.
CISSP, CISM, ISO 27001 Lead Implementer or Lead Auditor certification.
Experience supporting distributed engineering and product teams.
Familiarity with DevSecOps practices and cloud-native security.
Experience implementing AI tools or workflow automation within organisations.
Success Metrics:
Within the first six months, the successful candidate should:
Successfully own all IT onboarding, offboarding and asset management processes.
Maintain ISO 27001 compliance with no major non-conformities.
Complete all scheduled access reviews and compliance activities on time.
Reduce outstanding security vulnerabilities within agreed SLAs.
Improve internal IT service responsiveness and employee satisfaction.
Deliver measurable productivity improvements through AI-driven automation.
Maintain accurate documentation and audit evidence with minimal management oversight.
Proactively identify and implement improvements across IT, security and business operations.
Other Details:
Experience: 5+ years
Location: karachi, Pakistan
Working Days: Monday to Friday
About HR Ways:
HR Ways is an Award winning Technical Recruitment Firm helping software houses and IT Product companies internationally and locally to find IT Talent. HR Ways is engaged by 300+ Employers worldwide ranging from worlds biggest SaaS Companies to most competitive Startups. We have entities in Dubai, Canada, US, UK, Pakistan, India, Saudi Arabia, Portugal, Brazil and other parts of the world. Join our Whatsapp Channelhttps://whatsapp.com/channel/0029VamSiLr5fM5fMtAdCS2M to stay updated or visit www.hrways.co to know more."