About the job Senior Information Security Manager
Senior Information Security Manager - Hiring for Protego
Company: Protego (Information Security Services)
Location: Pakistan
Reports to: CTO, Protego
Employment Type: Full-time
ABOUT PROTEGO
Protego is an information security services company providing infosec, compliance, and governance services to clients across regulated industries — including financial services, fintech, banking technology, and RegTech.
As Protego scales its service delivery capability, you will lead the technical and compliance security practice — owning strategy, certification services, and client delivery, with a junior team member supporting day-to-day execution and IT governance tasks.
This is a leadership role for someone who wants to build and run a client-facing security practice, balancing hands-on technical delivery with account ownership and service quality.
ROLE OVERVIEW
You will own Protego's security service delivery end-to-end across four service lines, focused on:
- Governance, Risk & Compliance (GRC) — ISO 27001 certification & ISMS implementation, vCISO/Information Security Office as a Service, risk assessment & risk register management, third-party/vendor risk management, and regulatory advisory (SOC 2, ISO 27701, PCI DSS, GDPR and local data protection).
- Technical Assurance — penetration testing, secure code review, cloud security posture assessment, architecture & configuration review, and vulnerability management.
- Managed Security & IT Governance — outsourced IT governance (license/asset lifecycle), endpoint security monitoring, access & identity governance, and incident response planning.
- Advisory — virtual CISO retainers and security awareness training.
- Client & Engagement Management — scoping, delivery quality, reporting, relationship ownership across all of the above.
You will also mentor and direct the Junior Information Security Analyst, and contribute to Protego's service offering and proposal/scoping work as the client base grows.
KEY RESPONSIBILITIES
1. Governance, Risk & Compliance (Primary Owner)
- Lead ISO 27001 gap assessments, ISMS implementation, and certification-readiness consulting for Protego's clients — owning the Statement of Applicability, risk register, and control framework on their behalf.
- Deliver Information Security Office as a Service (vCISO) engagements — acting as outsourced security leadership for clients who need the function without a full-time hire.
- Own risk assessment and risk register management for client engagements, keeping registers current as client environments change.
- Lead third-party and vendor risk management engagements — assessing the risk clients' own suppliers introduce.
- Deliver regulatory and framework advisory, including GDPR and other data protection regulation compliance (data mapping, DPIA support, breach-notification readiness), alongside SOC 2 readiness, ISO 27701, and PCI DSS scoping.
- Manage relationships with certification bodies on behalf of clients — audits, surveillance visits, recertification.
- Own the policy and documentation templates Protego uses across client engagements, and their periodic review.
- Lead responses to client security due diligence and questionnaires on behalf of clients Protego supports.
2. Technical Assurance (Program Owner)
- Define the pentest strategy and calendar across web, API, mobile, infrastructure, and cloud for client engagements.
- Perform or directly oversee execution of tests; review and quality-check findings before reports go to clients.
- Own severity rating methodology (CVSS), client-facing report standards, and remediation tracking to closure.
- Establish the secure code review process (manual + SAST/DAST) and integrate it into client SDLCs; personally review higher-risk/complex code (auth, payments, data handling, cryptography).
- Deliver cloud security posture assessments (AWS/Azure) and architecture/configuration reviews for client environments.
- Own an ongoing vulnerability management service for clients — scanning, triage, and reporting on a defined cadence, not one-off point-in-time reports.
- Manage third-party pentest vendor/subcontractor relationships where independent/certified attestation or surge capacity is required.
3. Managed Security & IT Governance (Strategic Oversight)
- Set IT governance policy (access control, MFA, patch management, vendor risk, backup verification) and hold the junior analyst accountable for day-to-day execution, both for Protego's own IT and for clients on managed service engagements.
- Own outsourced IT governance as a client-facing managed service — license/asset lifecycle management and endpoint security monitoring delivered on a subscription basis.
- Own access and identity governance for client engagements — provisioning/de-provisioning and access reviews run on a fixed schedule.
- Own incident response planning and tabletop exercise delivery for clients, and act as incident commander when needed.
4. Advisory
- Deliver virtual CISO retainer engagements — ongoing strategic security leadership for clients on a recurring monthly basis.
- Design and deliver security awareness training programs tailored to client organisations.
Client & Engagement Management
- Scope and price security engagements across all four service lines in collaboration with Protego leadership.
- Own client relationships for security engagements — kickoffs, status reporting, findings walkthroughs, and renewal/upsell conversations.
- Ensure engagement quality and SLA adherence across concurrent client work.
- Contribute security expertise to proposals, RFP responses, and sales support as Protego's client base and service catalogue grow.
Leadership
- Mentor and manage the Junior Information Security Analyst; delegate governance/administrative tasks appropriately.
- Report security posture, risk, engagement pipeline, and delivery quality to Protego leadership.
REQUIRED QUALIFICATIONS & EXPERIENCE
- 6+ years in information security, with strong hands-on depth in at least three of: compliance/ISMS/GRC, pentesting, secure code review, IT governance.
- Proven experience implementing/maintaining an ISO 27001 ISMS; Lead Implementer or Lead Auditor certification strongly preferred.
- Working knowledge of GDPR and data protection regulation (data mapping, DPIA, breach notification) sufficient to advise clients and scope engagements.
- Solid penetration testing background — OSCP, CEH, or equivalent preferred.
- Familiarity with secure code review tooling and practices (OWASP Top 10, SAST/DAST).
- Comfortable operating in a vCISO / outsourced security leadership capacity — advising client leadership directly, not just executing tasks.
- Strong stakeholder communication — able to brief executives and mentor junior staff.
- Experience in a regulated industry (fintech, RegTech, banking) is a strong plus given Protego's client base.
- Experience delivering security services or consulting to external clients (as opposed to purely internal security work) — including scoping engagements, managing client expectations, and producing client-ready deliverables.
PREFERRED / NICE TO HAVE
- Prior experience in a security consultancy, MSSP, or professional services environment.
- Cloud security experience (AWS/Azure), including cloud security posture assessment.
- Experience with SOC 2, ISO 27701, or PCI DSS scoping.
- Scripting/automation skills (Python, Bash).
- Exposure to proposal writing, SOW drafting, or pre-sales technical support.
WHAT SUCCESS LOOKS LIKE (FIRST 6–12 MONTHS)
- ISMS scoping and gap assessments delivered for Protego's first client engagements, with a clear path mapped to ISO 27001 certification/recertification for each.
- At least one vCISO or GDPR advisory engagement scoped and running.
- Pentest and secure code review programs running on a defined cadence for client engagements, with tracked remediation.
- IT governance and managed security policies defined, with the junior analyst operating effectively against them — both internally and on at least one client managed-service engagement.
- Documented incident response plan tested at least once, either internally or with a client.
- Clear service catalogue and pricing model established across all four service lines (GRC, Technical Assurance, Managed Security & IT Governance, Advisory).
COMPENSATION & BENEFITS
Market-competitive salary, with the option for ESOPs (Employee Stock Ownership Plan).
Protego is an equal opportunity employer. We welcome applications from candidates of all backgrounds.