IT GRC
On-siteJakarta, Jakarta, Indonesia
Job Summary
IT GRC Analyst needed to sit at the intersection of technology, compliance, and risk across multiple markets. You will own and drive the full lifecycle of IT certifications (e.g., PCI-DSS, ISO 27001), coordinate with regulatory bodies (BI, OJK, BSP/ BOT/MAS/BNM where applicable), and partner with engineering, product, and legal teams to embed compliance-by-design. Responsibilities include conducting IT risk assessments, control testing, gap analyses, developing and maintaining IT policies and procedures, coordinating audits and evidence packages, monitoring regulatory changes, producing dashboards and status reports, and ensuring timely renewals and surveillance across markets.
Required Qualifications
- 3–5 years of hands-on experience in IT GRC, IT Risk Management, or IT Compliance roles
- Solid working knowledge of PCI-DSS, ISO 27001 frameworks, including implementation, certification, and audit readiness
- Familiarity with Bank Indonesia (BI) and OJK IT governance regulations applicable to payment service providers in Indonesia
- Exposure to or willingness to take regulatory requirements in at least one other Southeast Asian or international market (e.g., BSP, BOT, MAS, BNM, or equivalent)
- Proven experience conducting IT risk assessments, control testing, and gap analyses
- Demonstrated ability to develop, review, and maintain IT policies, standards, and procedures
- Strong analytical skills with the ability to translate diverse regulatory requirements into technical and operational controls
- Effective communicator who can engage both technical and non-technical stakeholders across multiple countries and time zones
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.