Latest UpdatesPrivate Jobs

PSX Jobs 2026: Manager IT GRC at Pakistan Stock Exchange – Apply Online

PSX Jobs 2026 are open at Pakistan Stock Exchange Limited for the position of Manager / Team Lead – IT Governance, Risk and Compliance (IT GRC). This is a senior specialist role at the institution that operates the country capital market infrastructure.

PSX Jobs 2026 Manager IT GRC vacancy at Pakistan Stock Exchange

IT GRC roles are among the most in-demand specialisations in Pakistan technology job market, and the exchange is a particularly interesting employer for one specific reason: the systems you would be governing carry systemic importance. Failure here is not an inconvenience, it affects market integrity.

This guide covers the role, eligibility, certifications that matter, salary expectations, the application process for PSX Jobs 2026, and how to prepare for a genuinely technical selection process.

PSX Jobs 2026 Overview

DetailInformation
OrganisationPakistan Stock Exchange Limited (PSX)
PositionManager / Team Lead – IT GRC
FunctionInformation Technology, Governance Risk and Compliance
LocationKarachi, Sindh
Job TypeFull time, permanent
EducationBachelors or Masters in Computer Science, IT or related field
CertificationsCISA, CISM, CRISC, ISO 27001 LA strongly preferred
ApplyOnline through the official PSX careers portal

About Pakistan Stock Exchange

Pakistan Stock Exchange Limited was formed through the integration of the Karachi, Lahore and Islamabad stock exchanges. It operates the trading, clearing and settlement infrastructure through which listed securities are bought and sold in Pakistan, and it functions under the regulatory oversight of the Securities and Exchange Commission of Pakistan.

The technology environment at an exchange is unusual. Trading systems must process orders with extremely low latency, maintain complete auditability, and remain available throughout market hours without exception. That combination is exactly why PSX Jobs 2026 in governance, risk and compliance carry real weight.

What IT GRC Means in Practice

IT Governance, Risk and Compliance is often misunderstood as a documentation function. In a regulated financial market institution it is considerably more than that.

Governance establishes how technology decisions are made, who is accountable, and how IT investment aligns with organisational objectives. Risk identifies what could go wrong across technology and information security, assesses likelihood and impact, and drives mitigation. Compliance ensures the organisation meets regulatory requirements, internal policy and applicable international standards.

For PSX Jobs 2026 at this level, the role is the bridge between technical teams who build and operate systems, and the board, regulators and auditors who need assurance that those systems are controlled.

Key Responsibilities

1. IT Governance

  • Develop, maintain and enforce IT policies, standards and procedures
  • Implement governance frameworks such as COBIT and align IT with business objectives
  • Support IT steering committees with reporting and recommendations
  • Define roles, responsibilities and accountability across the technology function
  • Oversee IT policy exception management

2. Risk Management

  • Maintain the IT and information security risk register
  • Conduct technology risk assessments across systems, processes and projects
  • Evaluate third party and vendor risk, including cloud and outsourced services
  • Track remediation of identified risks to closure
  • Support business continuity and disaster recovery planning and testing

3. Compliance and Audit

  • Ensure compliance with SECP regulatory requirements applicable to market infrastructure
  • Manage compliance with ISO 27001 and other applicable standards
  • Coordinate internal and external IT audits and manage the audit lifecycle
  • Track and close audit observations within agreed timelines
  • Prepare compliance reporting for management, board and regulators

4. Team Leadership

  • Lead and develop the IT GRC team
  • Build awareness of security and compliance obligations across the wider organisation
  • Deliver training on IT policy and information security responsibilities
  • Represent the GRC function in projects from initiation onwards

Eligibility Criteria for PSX Jobs 2026

Education

Candidates for PSX Jobs 2026 at this level are normally expected to hold at least sixteen years of education from an HEC recognised institution, in Computer Science, Software Engineering, Information Technology, Information Security or a closely related discipline.

Certifications

Professional certification carries unusual weight in GRC hiring, because it demonstrates standardised knowledge of frameworks that the role applies daily. The most relevant are:

  • CISA (Certified Information Systems Auditor) — the most directly relevant qualification for IT audit and compliance
  • CISM (Certified Information Security Manager) — for the security governance dimension
  • CRISC (Certified in Risk and Information Systems Control) — for technology risk management
  • ISO 27001 Lead Auditor or Lead Implementer — for information security management systems
  • CISSP — broader information security credential, widely recognised
  • COBIT certification — for the governance framework specifically

Candidates holding CISA or CISM alongside relevant experience are typically the strongest applicants for positions of this type.

Experience

This is a management or team lead position, so meaningful prior experience in IT audit, information security, technology risk or compliance is expected. Experience within a regulated environment such as banking, financial services, telecom or a Big Four advisory practice is particularly valued.

Skills Required

  • Working knowledge of frameworks including ISO 27001, COBIT and NIST
  • Understanding of IT general controls and application controls
  • Ability to write clear policy and audit documentation
  • Stakeholder management across technical and non-technical audiences
  • Analytical rigour and comfort challenging established practice
  • Understanding of financial market infrastructure is an advantage

Salary and Benefits

Pakistan Stock Exchange does not publish salary bands, and packages for PSX Jobs 2026 at manager level are set against qualifications, certifications and experience. GRC and information security roles command a premium in the Pakistani market because qualified professionals are genuinely scarce relative to demand.

  • Competitive market-based salary reflecting specialist scarcity
  • Annual performance bonus
  • Comprehensive medical coverage for employee and dependents
  • Provident fund and gratuity
  • Support for professional certification and renewal fees
  • Training and conference exposure in information security
  • Leave entitlement as per policy
  • Exposure to nationally significant technology infrastructure

How to Apply for PSX Jobs 2026

  1. Visit the official PSX website at psx.com.pk and open the careers section
  2. Locate the Manager / Team Lead – IT GRC position
  3. Prepare a CV that leads with certifications, frameworks and audit experience
  4. Complete the online application form accurately
  5. Upload your CV, degree documents and certification credentials
  6. Submit the application and retain the confirmation reference
  7. Ensure your certification registry details are current, as these are verified

Note: PSX recruitment is free of cost. No legitimate recruiter will request payment at any stage.

Selection Process

  1. CV and credential screening, with particular attention to certifications
  2. HR screening covering background and expectations
  3. Technical interview on frameworks, risk methodology and audit practice
  4. Panel interview with IT and possibly compliance leadership
  5. Scenario assessment in some cases, such as responding to a described control failure
  6. Verification of certifications, references and background
  7. Offer to the successful candidate

How to Prepare for the Technical Interview

Technical rounds for PSX Jobs 2026 in GRC are precise. Panels test whether you have applied frameworks rather than simply read about them.

  • Know ISO 27001 structure properly. Be able to discuss Annex A control domains and how a management system is actually implemented.
  • Prepare a risk assessment example. Walk through a real risk you identified, how you assessed it and what mitigation was implemented.
  • Understand IT general controls. Access management, change management, and backup and recovery are the recurring examination areas.
  • Be ready on third party risk. Vendor and cloud risk assessment is increasingly central to GRC roles.
  • Prepare an audit closure story. Describe a significant observation and how you drove it to resolution against resistance.
  • Read on market infrastructure. Understanding why availability and integrity matter at an exchange demonstrates genuine interest.

Why This Role Is Worth Applying For

  • GRC and information security skills are among the most transferable and in-demand in the market
  • A regulated market infrastructure environment is a distinctive addition to a CV
  • Direct exposure to board and regulator reporting builds seniority quickly
  • Certification support reduces the personal cost of maintaining credentials
  • The function is growing rather than shrinking as regulatory expectations increase
  • Skills transfer readily into banking, fintech, telecom and consulting

Career Growth Path

Progression from a Manager or Team Lead GRC position typically runs towards Head of IT GRC, Chief Information Security Officer, Head of Internal Audit for technology, or senior advisory roles in consulting. Because the function combines technical understanding with governance and communication skills, it is also a recognised route towards broader risk and compliance leadership outside technology.

Frequently Asked Questions

Is CISA mandatory for PSX Jobs 2026 in this role?

Certifications such as CISA, CISM or CRISC are strongly preferred and significantly strengthen an application, though the advertisement should be checked for whether any is strictly mandatory.

Can candidates from banking apply?

Yes. Banking IT audit and information security experience is directly relevant, because both environments are regulated and control-heavy.

Is this a hands-on technical role?

It is technical but governance focused. You will not be configuring systems, but you must understand them well enough to evaluate their controls credibly.

What is the location?

The position is based in Karachi, where the exchange head office is located.

Is there an application fee?

No. The recruitment process is entirely free of cost.

Final Words

PSX Jobs 2026 for the IT GRC Manager position offer a specialist career step inside an institution of genuine national importance, with certification support, regulatory exposure and skills that remain in demand across the market.

If you hold a relevant certification and can evidence applied risk and audit work rather than theoretical knowledge, this is a strong application. Apply through the official careers portal with a CV built around frameworks, findings and closure outcomes.

For more opportunities, see our guides on NADRA Jobs 2026, PPSC Jobs 2026 and FPSC New Jobs 2026.

Frameworks You Will Work With Daily

Candidates evaluating PSX Jobs 2026 in the GRC function should be familiar with the frameworks that structure the work. Each serves a different purpose and panels expect you to know which applies where.

FrameworkPrimary PurposeWhere It Applies in the Role
ISO 27001Information security management systemCertification maintenance, control design, internal audit
COBITIT governance and managementAligning IT decisions with organisational objectives
NIST Cybersecurity FrameworkCybersecurity risk managementStructuring identify, protect, detect, respond and recover activity
ITILIT service managementChange, incident and problem management controls
SECP regulatory requirementsSector-specific complianceMandatory obligations for market infrastructure

The practical skill is not memorising these but knowing how to apply the relevant parts of each without drowning the organisation in process.

A Typical Quarter in IT GRC

The workload in PSX Jobs 2026 at this level follows an audit and reporting cycle rather than an even weekly pattern.

The start of a quarter usually focuses on risk assessment refresh and policy review. Registers are updated, new systems and projects are assessed, and any expired policies are revised and re-approved.

The middle period is dominated by control testing and audit coordination. Internal audit fieldwork, external certification audits or regulatory inspections typically fall here, along with evidence gathering and remediation tracking.

The quarter closes with reporting. Compliance status, open risk items, audit observation ageing and security metrics are consolidated for management and board-level review.

Alongside this cycle sits continuous work: reviewing change requests, assessing new vendors, responding to incidents and supporting projects at design stage.

Common Weaknesses in GRC Applications

Hiring managers filtering candidates for PSX Jobs 2026 in this specialism see recurring problems:

  • Listing frameworks without application. Naming ISO 27001 means little without describing controls you implemented or tested.
  • No evidence of closure. Finding issues is easy. Driving remediation against operational resistance is the actual skill.
  • Pure documentation background. Candidates who have only written policy without testing controls struggle at technical stage.
  • Weak stakeholder examples. GRC succeeds through influence, so an inability to describe persuading a reluctant team is a red flag.
  • Outdated certifications. Lapsed credentials suggest the knowledge has not been maintained.
  • No business framing. Presenting risk in technical language without translating impact for management limits seniority.

Building Towards This Role

If you are not yet ready for PSX Jobs 2026 at manager level, the route is well defined:

  • Start in IT audit, information security operations or systems administration to build technical grounding
  • Pursue CISA as the single most efficient certification for opening GRC doors
  • Seek involvement in an ISO 27001 implementation or audit, even in a supporting role
  • Volunteer for control testing and evidence collection during audits at your current employer
  • Develop writing skills, since policy and report quality is judged closely in this field
  • Build experience in a regulated sector, which is what most GRC employers screen for

Official Application Link for PSX Jobs 2026

Applications for PSX Jobs 2026 are handled through official recruitment channels only. Candidates can find and apply for the Manager IT GRC vacancy at Pakistan Stock Exchange on this official portal, or send an updated CV to the HR email address published in the advertisement. Always confirm the posting on the employer’s own website before sharing personal documents, and remember that no genuine employer charges a fee to accept an application for PSX Jobs 2026.

Frequently Asked Questions About PSX Jobs 2026

What is the last date to apply?

The closing date is stated in the official advertisement. Because PSX Jobs 2026 usually attract a very large number of applications, shortlisting often begins before the deadline, so applying in the first week gives you a clear advantage.

Can fresh graduates apply?

Yes, where the advertisement does not specify a minimum experience requirement. Fresh graduates applying for PSX Jobs 2026 should highlight internships, final year projects and any part-time work that demonstrates the skills listed in the job description.

Is there any application fee?

No. There is no fee for PSX Jobs 2026. Any person or website demanding money in exchange for an interview call or an appointment letter is running a scam and should be reported immediately.

Final Word on PSX Jobs 2026

Prepare a focused CV, match every bullet point to the requirements in the advertisement, and apply early. PSX Jobs 2026 reward candidates who show they understand the role rather than those who send a generic application to every opening.

Leave a Reply

Your email address will not be published. Required fields are marked *