
Real job — pulled straight from Contour Software’s careers page · Verified August 13, 2026 · No reposts.
Job description
Contour Software is hiring a GRC Analyst — a full-time, based in Karachi, PK role. Apply directly on Contour Software's careers page below.
GRC Analyst
Location: PER - Karachi, PK, PER - Lahore, PK, PER - Islamabad, PK
Time Type: Full time
Job Description
About Contour
Contour Software has grown from a dozen people to over 2,000 staff across 3 cities, in less than 14 years.
As a subsidiary of Constellation Software Inc., we are proud to be part of a global enterprise software conglomerate that has grown to become one of the top 10 software companies in the world, with employees and customers in 100+ countries. With a broad-based and ever-growing portfolio of market-leading, vertical-market enterprise solutions covering more than 100 industry domains in predominantly mature markets, CSI's recipe creates the perfect environment for professionals to build fulfilling, long-term careers.
What started as an R&D & Accounting back-office, has progressed into a full-service Global Centre serving all functions and departments, at the divisional as well as operating group/corporate level. Today Contour employees, located in Karachi, Lahore & Islamabad, are serving CSI divisions located in time zones spanning the globe, from Sydney to Vancouver. With the global growth of Constellation as the wind in our sails, we are only just getting started!
Carina Overview
Carina is a global portfolio of software companies operating across multiple verticals and geographies. We have 2,500 employees working across more than 30 countries and continue to grow. Our portfolio-level Cyber Governance, Risk & Compliance (GRC) function provides Carina businesses with the governance, frameworks, assurance, tools and expertise needed to manage cyber risk, strengthen security maturity and meet Group cybersecurity requirements.
Our goal is to provide a consistent, risk-based approach to cybersecurity governance across the portfolio, while enabling businesses to retain ownership of their operational security and compliance responsibilities. Through independent assurance, risk oversight and practical guidance, the Group Cyber GRC function supports businesses in improving their cybersecurity posture, meeting Vela requirements and providing leadership with confidence in the effectiveness of cybersecurity controls across the portfolio.
Role Purpose
The Group Cyber GRC Analyst supports cybersecurity governance, risk, compliance and assurance activities across Carina's portfolio of businesses. Working within the Vela Cyber Security Framework, the role independently assesses business compliance, validates evidence, identifies cybersecurity risks and control weaknesses, and contributes to evidence-based assurance reporting.
As part of Carina's Cyber Assurance Programme, the role manages assessments for assigned businesses, engages with stakeholders, supports the Cyber Risk Register, tracks remediation activities and promotes continuous improvement in cybersecurity maturity. The role also supports the integration of newly acquired businesses into the Carina cybersecurity governance framework as the portfolio continues to grow.
Key Responsibilities
Cyber Assurance & Compliance Assessments
Conduct independent cybersecurity assessments against the Vela Cyber Security Framework.
Manage assigned business assessments from planning through to completion.
Review, validate and challenge business self-assessment responses.
Evaluate supporting evidence to determine control implementation and effectiveness.
Identify compliance gaps, control deficiencies and areas requiring improvement.
Conduct interviews and review sessions with business stakeholders.
Document assessment findings, observations and recommendations.
Produce assessment reports and remediation plans.
Perform follow-up reviews to verify remediation activities have been completed.
Escalate material findings and risks to the Senior Group Cyber Assurance & GRC Analyst.
Governance & Compliance Monitoring
Monitor compliance with Group cybersecurity requirements across assigned businesses.
Support consistent interpretation and application of the Vela Cyber Security Framework.
Track compliance trends and recurring control weaknesses.
Assist businesses in understanding cybersecurity requirements and expectations.
Maintain governance records, evidence repositories and assessment documentation.
Support the continual improvement of assessment methodologies and governance processes.
Cyber Risk Management
Identify and assess cyber risks arising from assurance reviews and assessments.
Support maintenance of the Carina Cyber Risk Register.
Review business and portfolio risk registers to identify material risks requiring escalation.
Track risk treatment plans and remediation activities.
Monitor overdue actions and engage with stakeholders to drive closure.
Contribute to portfolio-wide cyber risk analysis and reporting.
Support the application of the Carina Cyber Risk Appetite and escalation framework.
Security Awareness & Human Risk Management
Support oversight of the cybersecurity awareness programme across assigned businesses.
Review security awareness training completion rates and phishing simulation outcomes.
Verify awareness compliance against Group requirements.
Identify businesses requiring additional awareness support or intervention.
Track awareness-related remediation activities.
Contribute to awareness reporting and human risk metrics.
Reporting & Management Information
Prepare assessment reports, risk summaries and compliance updates.
Contribute to monthly and quarterly cybersecurity reporting.
Maintain assessment dashboards and reporting data.
Analyse trends, recurring findings and common control weaknesses.
Support the preparation of management information for Group leadership and Vela stakeholders.
Ensure reporting is accurate, evidence-based and timely.
Audit, Third-Party & Acquisition Support
Participate in internal and external cybersecurity audits where required.
Support supplier and third-party cyber assurance activities.
Assist with cybersecurity due diligence activities for acquisitions.
Support onboarding of newly acquired businesses into the Carina cybersecurity programme.
Track remediation activities arising from audits, assessments and acquisition reviews.
Skills & Experience
Essential
3–5 years' experience in Cybersecurity Governance, Risk & Compliance (GRC), Information Security, IT Audit, Risk Management, or a related discipline.
Experience conducting cybersecurity audits, compliance assessments or assurance reviews, including validating evidence and assessing control effectiveness.
Strong understanding of cybersecurity governance, risk management and industry control frameworks, with the ability to identify, assess and communicate risks and findings.
Excellent analytical, organisational and problem-solving skills, with the ability to manage multiple priorities and deliver high-quality outcomes.
Strong written and verbal communication skills, with the ability to build effective relationships and engage confidently with both technical and non-technical stakeholders.
Desirable
Knowledge of recognised cybersecurity frameworks and standards, including CIS Controls v8, ISO 27001 and NIST Cybersecurity Framework (CSF).
Experience working within decentralised or multi-business environments, including support for mergers and acquisitions (M&A) due diligence.
Familiarity with Microsoft 365, Azure, cloud security governance, and GRC, audit or risk management platforms.
Qualifications
Desirable
Degree or equivalent experience in Cyber Security, Information Technology, Risk Management, Audit or related discipline.
One or more relevant industry certifications (such asISC² CC, Security+, CGRC, CISA, CRISC, or ISO 27001 Foundation/Internal Auditor/Lead Auditor).
Key Success Measures
Deliver high-quality cybersecurity assessments on schedule and in line with the Carina Cyber Assurance Programme.
Accurately validate evidence, identify and escalate material cybersecurity risks and control deficiencies.
Drive timely remediation and maintain high-quality assessment reporting and documentation.
Promote consistent application of the Vela Cyber Security Framework to improve cybersecurity compliance and maturity across the portfolio.
Build trusted relationships with business stakeholders, portfolio leadership and the Senior Group Cyber Assurance & GRC Analyst.
Exciting Benefits we offer:
- Market-leading Salary
- Medical Coverage – Self & Dependents
- Parents Medical Coverage
- Provident Fund
- Employee Performance-based bonuses
- Home Internet Subsidy
- Conveyance Allowance
- Profit Sharing Plan [Tenured Employees Only]
- Life Benefit
- Child Care Facility
- Company Provided Lunch/Dinner
- Professional Development Budget
- Recreational area for in-house games
- Sporadic On-shore training opportunities
- Friendly work environment
- Leave Encashment
Disclaimer: At Contour, we attribute our success to the unique contributions of our diverse staff. We’re committed to fostering a culture of respect that thrives on the varied perspectives and experiences of all individuals we recruit, employ, promote, and compensate. Since day one, we’ve adhered to a policy that champions a work environment honoring the worth and dignity of each person while being free from all forms of employment discrimination.
In our continuous effort to promote inclusivity, we extend our commitment to individuals with special needs by providing reasonable accommodations. We actively encourage qualified individuals with special needs to apply for the various openings within our company. Should you require assistance in completing the application process or have any inquiries regarding special facilities, please do not hesitate to contact our HR team. Your unique talents and abilities are welcomed and valued here.
Get GRC Analyst jobs like this→
New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.
Email me new jobsSimilar jobs




Frequently asked questions
What skills are required for GRC Analyst at Contour Software?
The required skills for GRC Analyst at Contour Software include: Cybersecurity, ISO 27001, Microsoft 365, Azure, CompTIA Security+, CISA.
What is the seniority level for GRC Analyst at Contour Software?
GRC Analyst at Contour Software is a Mid Level level position.
How do I apply for GRC Analyst at Contour Software?
You can view the full description and apply for GRC Analyst at Contour Software on EchoJobs: https://echojobs.io/job/contour-software-grc-analyst-sb1kz.