Job Overview
EXIM Bank of Pakistan, a Government of Pakistan institution, is recruiting for the position of Manager, Information Security & BCP in Islamabad for the year 2026. This full-time regular role, graded up to M5, is central to safeguarding the bank's information assets and ensuring business continuity.
The manager will lead cybersecurity operations, including the Security Operations Center (SOC), incident response, and vulnerability assessment and penetration testing (VAPT), while also developing and enforcing security policies and standards.
This position is ideal for a seasoned information security professional looking to make a significant impact within a financial institution.
The role involves directing core cybersecurity functions, mentoring and building specialized teams, and coordinating with internal and external stakeholders, including procurement, legal, audit, and compliance.
The manager will also support the Chief Risk Officer (CRO) in reporting cyber risks and mitigation plans to executive leadership.
A key part of the job is to strengthen threat detection and response capabilities through continuous improvement, Red Team/Blue Team exercises, and the evaluation of emerging security tools.
The position also requires developing and implementing an information security awareness and training program across the organization, ensuring that all staff understand and adhere to security best practices.
Candidates with a deep understanding of security frameworks like NIST and ISO 27001, along with hands-on experience in incident handling, forensic investigation, and disaster recovery, will find this role challenging and rewarding.
This is a unique opportunity to contribute to the cybersecurity posture of a key financial institution in Pakistan, working within a dynamic and regulated environment.
Eligibility and Qualification
The educational and experience requirements are designed to ensure the candidate has a strong technical foundation and practical expertise to lead the bank's information security and business continuity functions.
- HEC recognized 16 years of education with a major in IT, Systems, Computer Engineering, Software Engineering, or Information Security from a leading international or local university recognized by the Higher Education Commission (H.E.C.) of Pakistan.
- Minimum 5 years of relevant experience, preferably with a financial institution, bank, or DFI in Pakistan.
- Maximum age limit is 55 years.
Responsibilities
- Develop, review, and revise policies, procedures, and processes, validating them against conformity objectives.
- Mentor, build, and operationalize teams responsible for SOC, IR, VAPT, and technical assessment.
- Define security baseline standards for information assets, monitor implementation, and re-validate them regularly.
- Oversee response to security incidents, orchestrate forensic analysis, root-cause investigation, and coordinate with stakeholders.
- Lead technical proof-of-concepts (POCs), evaluate emerging security tools, and recommend best-fit controls and vendors to the CRO.
- Lead vulnerability assessment and penetration testing activities, providing guidance on identification, analysis, prioritization, and remediation.
- Identify and remediate gaps in technical security controls to ensure they are effective and deliver intended protection.
How to Apply
- Visit the official National Job Portal (NJP) website at to access the application form.
- Review the detailed job description and ensure you meet the eligibility criteria before applying.
- Complete the online application form with accurate information and submit it of August 25, 2026.
Important Instructions
- The job scale is up to M5.
- Candidates should have a clear understanding of Governance Framework, Operations & BCP.
- Familiarity with security regulations, data privacy laws, and cyber risk frameworks (e.g., NIST, ISO 27001) is required.
- The application must be submitted through the National Job Portal; applications submitted through other means may not be considered.