National Bank of Pakistan Logo

National Bank of Pakistan is hiring Officer IS Applications / Cloud Security (OG-I)

Karachi, Sindh, Pakistan
Verified Status: Active
Full Time
Banking / Financial Services / FinTech
25 September, 2026

Job Description

Department: Risk Management
Reporting To: Unit Head - IS Digital Channels
Location: Karachi
Employment Type: Contractual
Contract Duration: 3 Years, extendable at Management's discretion

National Bank of Pakistan (NBP), known as “The Nation’s Bank,” is one of Pakistan’s leading and largest banks, supporting the country’s financial well-being, sustainable growth, and inclusive development through its extensive local and international branch network.

As part of its strategy to become a future-fit, agile, and sustainable institution, NBP is seeking talented, dedicated, and experienced professionals for its Risk Management function.

Educational / Professional Qualification

  • Minimum Graduation in Computer Science, Computer Engineering, Cybersecurity, or Information Technology from a local or international university, college, or institute recognized by HEC Pakistan.
  • Relevant professional certifications in Information Security or Cybersecurity will be preferred.
  • Preferred certifications may include CompTIA Security+, CompTIA Cloud+, and relevant cloud or application security certifications.

Experience

  • Minimum 4 years of relevant experience in Application Security, Cloud Security, and/or Information Security.

Other Skills / Expertise / Knowledge Required

  • Good knowledge of Information Security functions.
  • Strong interpersonal, analytical, and problem-solving skills.
  • Ability to work effectively as a team player and meet strict deadlines.
  • Knowledge of security principles, threat analysis, and risk management.

Main Duties & Responsibilities

  • Conduct security reviews of web and mobile applications, APIs, databases, middleware, SaaS solutions, and cloud-hosted workloads.
  • Perform security assessments during solution design, implementation, major changes, and production deployment.
  • Review application architecture and identify risks involving authentication, authorization, session management, encryption, data handling, APIs, and integrations.
  • Assess applications against OWASP Top 10, OWASP API Security Top 10, secure coding standards, and other security requirements.
  • Review SAST, DAST, SCA, and penetration-testing findings and validate remediation and risk closure.
  • Assess third-party and internally developed applications for security weaknesses before production deployment.
  • Conduct or coordinate threat modeling for critical applications and significant technology changes.
  • Review cloud architectures and configurations across AWS, Microsoft Azure, and/or Google Cloud Platform.
  • Assess cloud controls covering IAM, privileged access, network segmentation, security groups/firewalls, storage, databases, encryption, key management, secrets management, logging, monitoring, backup, and recovery.
  • Review cloud environments against security baselines such as CIS Benchmarks and organizational cloud-security standards.
  • Assess security risks associated with IaaS, PaaS, SaaS, containers, Kubernetes, serverless computing, and cloud-native services.
  • Review CI/CD pipelines and DevSecOps controls, including source-code security, secrets handling, dependency management, container/image scanning, and deployment controls.
  • Evaluate IAM controls based on least privilege, segregation of duties, MFA, privileged access management, and Zero Trust principles.
  • Review API security, including authentication, authorization, rate limiting, encryption, token management, and protection of sensitive information.
  • Review Infrastructure-as-Code templates and automated cloud deployments for security misconfigurations.
  • Assess security implications of application and cloud changes through the change-management process.
  • Maintain security review findings, risk ratings, remediation plans, exceptions, and closure evidence.
  • Work with application owners, developers, DevOps, and cloud teams to recommend practical remediation measures.
  • Participate in application and cloud-related security incidents and provide technical support for investigation and root-cause analysis.
  • Develop and maintain application security standards, cloud security baselines, review checklists, and security architecture requirements.
  • Perform any other assignments as directed by the supervisor(s).

Assessment Test / Interview

Only shortlisted candidates who strictly meet the stated basic eligibility criteria will be invited for the assessment test and/or panel interview.

Compensation & Benefits

Selected candidates will be offered a compensation package and other benefits according to the Bank's applicable policies and rules.

How to Apply

Interested candidates should apply online through the Sidat Hyder Careers Portal according to the instructions provided there.

Applications received after the due date will not be considered.

Important: No TA/DA will be admissible for the test/interview.

Equal Opportunity Employer

National Bank of Pakistan is an equal opportunity employer and welcomes applications from all qualified individuals regardless of gender, religion, or disability.