Job Overview
The Director – Information & Security will provide strategic leadership for the Authority's information security, cybersecurity, and data protection functions.
This role involves establishing enterprise-wide security strategies, governance frameworks, and risk management practices to protect the Authority's information assets, digital platforms, and critical infrastructure.
The director will ensure compliance with applicable laws, regulations, and national cybersecurity standards, and will work to embed security and privacy throughout the lifecycle of digital products and systems.
Day-to-day, the director will oversee security operations, incident response, and cyber resilience, while also advising senior management on emerging threats and security priorities.
The position requires coordinating with government ministries, regulators, national cybersecurity agencies, development partners, and vendors on matters of information security and cyber resilience.
Building a strong security culture through awareness initiatives and capacity building is also a key part of the role, as is leading and mentoring high-performing security teams.
Eligibility and Qualification
Candidates must meet the following eligibility criteria
- Minimum Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Technology, or a related discipline from an HEC-recognized institution.
- A Master's degree in Information Security, Cybersecurity, Information Technology, Computer Science, or a related field shall be preferred.
- Professional certifications such as CISSP, CISM, CISA, ISO 27001 Lead Implementer/Auditor, CCSP, CEH, or equivalent will be an added advantage.
- Minimum 10 years of progressively responsible professional experience in information security, cybersecurity, IT risk management, or enterprise security governance, consistent with Director-level positions under the PDA grading framework.
- Demonstrated experience developing enterprise information security strategies, governance frameworks, and cybersecurity programs.
- Experience managing security operations, cyber risk, regulatory compliance, audits, and incident response within government organizations, regulatory authorities, critical infrastructure, or large complex organizations.
- Proven experience leading multidisciplinary teams and managing enterprise-wide information security initiatives.
- Experience implementing internationally recognized security frameworks and standards will be preferred.
- Age limit: Max 65 years.
Responsibilities
- Develop and implement the Authority's information security and cybersecurity strategy aligned with organizational objectives, national cybersecurity policies, and digital governance frameworks.
- Establish and maintain enterprise information security policies, standards, procedures, and governance frameworks to safeguard information assets and digital services.
- Provide strategic advice to senior management on cybersecurity risks, emerging threats, and information security priorities.
- Lead the identification, assessment, and management of cybersecurity, information security, and technology risks across the Authority.
- Oversee the implementation of security controls to protect digital platforms, cloud environments, networks, applications, and data assets.
- Ensure effective security monitoring, incident response, business continuity, and cyber resilience capabilities.
- Ensure compliance with applicable laws, regulations, cybersecurity standards, and data governance requirements.
- Oversee security audits, vulnerability assessments, penetration testing, and compliance reviews, ensuring timely implementation of corrective actions.
- Establish mechanisms for continuous monitoring, risk reporting, and security performance measurement.
- Lead the implementation of data protection, privacy, identity and access management, and secure information-sharing frameworks across the Authority.
How to Apply
- Visit the official National Job Portal (NJP) website at to access the application page.
- Click the 'Login to Apply' button and log in with your credentials. If you do not have an account, register first on the portal.
- Complete the online application form with accurate details, ensuring all required fields are filled.
- Upload the necessary documents as specified on the portal, including your CV, educational certificates, and experience letters.
- Review your application before submitting to avoid errors, then submit.
Important Instructions
- Only shortlisted candidates will be contacted for further selection process.
- Candidates should ensure they meet all eligibility criteria before applying.
- No TA/DA will be admissible for test/interview.
- Keep a copy of your submitted application and documents for record.