DCMS consultants working together around a table

Careers.

Do work that has to hold up in the real world.

See how we work ↘

Work at DCMS

Build systems that keep working.

The work is exacting because the outcome matters.

DCMS brings GRC, audit, and security testing into one operating model. That means our people see the full security programme, not one isolated task passed down a delivery line.

You will work alongside practitioners who test the evidence, challenge assumptions, and stay accountable for what happens after the recommendation is made.

The experience

Work with range.
Learn with depth.

A varied caseload, close collaboration, and standards that remain high when the work gets complicated.

01

Cross-regional context

Work across Pakistan, North America, and Africa, learning how international frameworks meet local regulation.

02

Practitioner proximity

Learn beside people who have led audits, implemented controls, and tested systems from the inside.

03

Real ownership

Follow the work from first evidence through to a result the client can operate and defend.

Security professional reviewing a live control environment
Defensible by design

Our standard

Stand behind the work.

We don't sign what we haven't seen. Every recommendation begins with evidence, fits the organisation operating it, and is built to last beyond the immediate audit.

  • 01Evidence over assumptionsKnow what supports the conclusion.
  • 02Systems over shelfwareBuild controls people can keep running.
  • 03Clarity over theatreSay what matters and make the next action clear.

Areas of practice

Where you might fit.

Tell us where your experience is strongest and what kind of work you want to do more of.

01

GRC & compliance

Framework readiness, governance, risk management, policy, and evidence.

Open application
02

Audit & assurance

Control reviews, gap assessments, internal audit, and defensible reporting.

Open application
03

Security testing

Technical testing and reviews that find what documentation cannot see.

Open application

Before you apply

A few useful answers.

Will I work across different regions?

Yes. Our team works across Pakistan, North America, and Africa, with a genuinely varied caseload spanning SBP technology governance reviews, POPIA readiness, and international certifications — often within the same month, giving staff broad cross-regional exposure.

How do I apply to DCMS?

Apply directly through the Careers page with your background and the kind of GRC, audit, or security testing work you want to do more of. DCMS reviews applications directly rather than through an automated portal.

Open application

Bring us the work you want to do more of.

Share your background, your strongest area of practice, and the direction you want your career to take.

Apply directly ↗