Tkxel

Information Security Engineer

Tkxel Punjab, Pakistan

IT Services and IT Consulting · 501-1,000 employees

19 h ago
security Mid (2-5 yrs) Full-time Pakistan
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Information Security Engineer will maintain and improve the organization's Information Security Management System in alignment with ISO 27001 and ISO 42001. They will also support compliance efforts for HIPAA and SOC 2, conduct risk assessments, and assist in audit preparations.

What they look for

ISO 27001 HIPAA SOC 2 Risk Assessment Governance Compliance ISMS ISO 42001 Audit Preparation Security Awareness Training Incident Investigation Root Cause Analysis NIST CIS Controls GDPR Report Writing

Requirements

Candidates must hold a Bachelor's degree in Information Security, Computer Science, or a related field and possess an ISO 27001 Lead Implementer certification. Additionally, 2–3 years of experience in information security roles with a focus on GRC, HIPAA, and SOC 2 is required.

Full description

About the Role:

We are seeking a motivated Information Security Engineer with a strong foundation in compliance frameworks. The ideal candidate will have hands-on experience with ISO 27001, HIPAA, SOC 2 and conducting risk assessments.

Key Responsibilities:

● Governance, Risk & Compliance

○ Maintain and improve the organization’s Information Security Management System (ISMS) in alignment with ISO 27001 and AIMS in alignment to ISO 42001.

○ Support compliance efforts for HIPAA and SOC 2 frameworks.

○ Conduct risk assessments, document findings, and recommend remediation strategies.

○ Assist in preparing for internal and external audits.

○ Work with cross-functional teams to improve security posture.

○ Contribute to security awareness training programs.

○ Assist in security incident investigations and root cause analysis.

Requirements

Required Qualifications

● Education: Bachelor’s degree in Information Security, Computer Science, or related field (or equivalent experience).

● Certifications:

○ Mandatory: ISO 27001 Lead Implementer (LI)

● Experience:

○ 2–3 years in information security roles covering GRC domain

○ Hands-on involvement in ISO 27001 implementation/maintenance, HIPAA, and SOC 2 compliance projects.

Desired Skills:

● Knowledge of security standards such as NIST, CIS Controls, and GDPR.

● Strong report writing and communication skills for both technical and non-technical audiences.

Similar roles