Back to Jobs

Director – Information & Security

Pakistan Digital Authority

Government of Pakistan

Grade

Grade-11

Job Type

Regular

Vacancies

1 vacancy

Login to Apply

Job Description

Purpose of the Position The Director – Information & Security shall provide strategic leadership for the Authority's information security, cybersecurity, and data protection functions by establishing enterprise-wide security strategies, governance frameworks, and risk management practices. The director shall oversee the protection of the Authority's information assets, digital platforms, and critical infrastructure while ensuring compliance with applicable laws, regulations, and national cybersecurity standards in support of secure digital governance and the Authority's statutory mandate. Key Responsibilities Information Security Strategy & Governance • Develop and implement the Authority's information security and cybersecurity strategy aligned with organizational objectives, national cybersecurity policies, and digital governance frameworks. • Establish and maintain enterprise information security policies, standards, procedures, and governance frameworks to safeguard information assets and digital services. • Provide strategic advice to senior management on cybersecurity risks, emerging threats, and information security priorities. Cybersecurity & Risk Management • Lead the identification, assessment, and management of cybersecurity, information security, and technology risks across the Authority. • Oversee the implementation of security controls to protect digital platforms, cloud environments, networks, applications, and data assets. • Ensure effective security monitoring, incident response, business continuity, and cyber resilience capabilities. Compliance & Assurance • Ensure compliance with applicable laws, regulations, cybersecurity standards, and data governance requirements. • Oversee security audits, vulnerability assessments, penetration testing, and compliance reviews, ensuring timely implementation of corrective actions. • Establish mechanisms for continuous monitoring, risk reporting, and security performance measurement. Digital Trust & Data Protection • Lead the implementation of data protection, privacy, identity and access management, and secure information-sharing frameworks across the Authority. • Ensure security and privacy requirements are embedded throughout the lifecycle of digital products, systems, and technology initiatives. • Promote secure adoption of emerging technologies, including cloud computing, artificial intelligence, and Digital Public Infrastructure (DPI). Stakeholder Management & Capacity Building • Coordinate with government ministries, regulators, national cybersecurity agencies, development partners, vendors, and other stakeholders on matters relating to information security and cyber resilience. • Lead the development of organization-wide cybersecurity awareness and capacity-building initiatives to strengthen security culture. • Build, mentor, and lead high-performing information security teams while fostering continuous improvement and innovation. Qualifications • Minimum Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Technology, or a related discipline from an HEC-recognized institution. • A Master's degree in Information Security, Cybersecurity, Information Technology, Computer Science, or a related field shall be preferred. • Professional certifications such as CISSP, CISM, CISA, ISO 27001 Lead Implementer/Auditor, CCSP, CEH, or equivalent will be an added advantage. Experience • Minimum 10 years of progressively responsible professional experience in information security, cybersecurity, IT risk management, or enterprise security governance, consistent with Director-level positions under the PDA grading framework. • Demonstrated experience developing enterprise information security strategies, governance frameworks, and cybersecurity programs. • Experience managing security operations, cyber risk, regulatory compliance, audits, and incident response within government organizations, regulatory authorities, critical infrastructure, or large complex organizations. • Proven experience leading multidisciplinary teams and managing enterprise-wide information security initiatives. • Experience implementing internationally recognized security frameworks and standards will be preferred. Key Competencies • Enterprise information security strategy • Cybersecurity governance and risk management • Information assurance and data protection • Security architecture and secure digital infrastructure • Regulatory compliance and audit management • Incident response and cyber resilience • Cloud security and emerging technologies • Leadership and people management • Stakeholder engagement and strategic advisory • Policy development and implementation

Eligibility Criteria

Experience

10 Years

Age Limit

Max: 65 years

Application Deadline

13 Aug 2026
14 days left

Don't miss this opportunity! Submit your application before the deadline.

Quick Overview

Posted: 30 Jul 2026
Deadline: 13 Aug 2026
Vacancies: 1
Experience: 10+ years
Age Limit: Max: 65

About Employer

Pakistan Digital Authority

Pakistan Digital Authority

Share This Job