Xendit logo
XenditPosted 2 months ago

IT GRC

On-siteJakarta, Jakarta, Indonesia

Full TimeMid LevelMediumFintech Services

Job Summary

IT GRC Analyst needed to sit at the intersection of technology, compliance, and risk across multiple markets. You will own and drive the full lifecycle of IT certifications (e.g., PCI-DSS, ISO 27001), coordinate with regulatory bodies (BI, OJK, BSP/ BOT/MAS/BNM where applicable), and partner with engineering, product, and legal teams to embed compliance-by-design. Responsibilities include conducting IT risk assessments, control testing, gap analyses, developing and maintaining IT policies and procedures, coordinating audits and evidence packages, monitoring regulatory changes, producing dashboards and status reports, and ensuring timely renewals and surveillance across markets.

Required Qualifications

  • 3–5 years of hands-on experience in IT GRC, IT Risk Management, or IT Compliance roles
  • Solid working knowledge of PCI-DSS, ISO 27001 frameworks, including implementation, certification, and audit readiness
  • Familiarity with Bank Indonesia (BI) and OJK IT governance regulations applicable to payment service providers in Indonesia
  • Exposure to or willingness to take regulatory requirements in at least one other Southeast Asian or international market (e.g., BSP, BOT, MAS, BNM, or equivalent)
  • Proven experience conducting IT risk assessments, control testing, and gap analyses
  • Demonstrated ability to develop, review, and maintain IT policies, standards, and procedures
  • Strong analytical skills with the ability to translate diverse regulatory requirements into technical and operational controls
  • Effective communicator who can engage both technical and non-technical stakeholders across multiple countries and time zones

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce