
Deputy Director (Governance, Risk Assessment & Compliance)
National Database and Registration Authority (NADRA)
- Last date to apply
- 20 Sept 2026
- Published on
- 6 Sept 2026
- Total posts
- 1
- Employment type
- Full Time
- Job nature
- Contract
- Shift
- Morning
- Category
- Information Technology
- Region
- Federal
Location
- Islamabad, Federal
About this vacancy
NADRA requires a Deputy Director (Governance, Risk Assessment & Compliance) on a contractual basis at Islamabad to lead information security governance, AI governance and compliance with international standards. National Database and Registration Authority (NADRA) has advertised a post of Deputy Director (Governance, Risk Assessment & Compliance) in Federal. Place of posting: Islamabad, Federal.
- Post
- Deputy Director (Governance, Risk Assessment & Compliance)
- Department
- National Database and Registration Authority (NADRA)
- Total posts
- 1
- Employment type
- Full Time
- Job nature
- Contract
- Category
- Information Technology
- Region
- Federal
- Last date to apply
- 20 Sept 2026
Duties and responsibilities
- Lead compliance with ISO 27001, ISO 27701, ISO 22301, ISO 31000, NIST SP 800/37, NIST CSF, NIST RMF, NIST AI RMF, PCI DSS and PKI/WebTrust controls
- Establish AI governance frameworks for AI/ML/Gen AI systems
- Develop controls for responsible AI, explainability, model risk management, bias detection and privacy preservation
- Manage AI risks including prompt injection, LLM data leakage, shadow AI and AI supply chain risk
- Scope and conduct information security audits and formulate audit reports
- Apply risk assessment methodologies covering risk identification, analysis and mitigation
- Formulate IS policies, SOPs and instructions
- Act as a technical resource for security assessment and compliance
- Communicate information security and compliance matters to senior management and technical teams
Eligibility criteria
- Bachelor - B.S COMPUTER SCIENCE, Bachelor of Information Technology, B.S(Software Engineering), BS (Computer Engineering), BS (Information Security), BS (Cyber Security), BS (Data Science), BS (Artificial Intelligence), in Computer Science, Information Technology, Cyber Security, Data Science, recognised by HEC
- Bachelors (4 years) in Computer Science/Information Technology/Cyber Security/Information Security/Data Science/Artificial Intelligence or equivalent from an HEC recognized university
- Degrees must be attested by HEC
- Minimum 6 to 10 years post-graduation experience with at least 3 years in GRC roles
- Solid understanding of ISO 27001, NIST and CIS controls
- Hands-on experience in scoping and conducting information security audits
Experience required
- Required experience: 6 – 10 years
- Minimum 6 to 10 years post-graduation experience with at least 3 years in Governance, Risk Management and Compliance roles. Certification in ISO-27001, CISM, CISA or CISSP preferred.
Age limit
- Male: 18 – 44 years
- Female: 18 – 44 years
- Transgender: 18 – 44 years
Age is normally counted as at the closing date given in the official advertisement. Any relaxation shown above applies only where the advertisement allows it - it is never automatic.
Selection process and test pattern
- Written or screening test
- Interview
- Medical examination
- Paper type: Mcqs
Only shortlisted candidates will be called for test/interview. Electronic gadgets such as mobile phones and smart watches are not allowed during test/interview.
Required documents
- CNIC
- HEC Attested Degrees/Certificates
- Experience Certificates
- Educational Documents
- Medical Fitness Certificate
- Character Certificate
- NOC (for government employees)
How to apply
- Sign in with PAKID on the NADRA careers portal
- Complete the online application form
- Upload required documents
- Submit application online before the deadline
