IT Security & GRC (Lead/Manager)
Core
Develop and maintain IT policies, standards, and procedures to ensure compliance with internal and external regulations (POJK, PBI) and safeguard information assets.
Role type
Lead/Manager IT Security & GRC
Builds
Internal control framework, policies, and procedures aligned with IT General Control, IT Application control, ISO 27001, and PCI DSS.
Domain
Financial Technology (Fintech) / Information Security & Governance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
IT policy development, risk mitigation, RBAC implementation, audit coordination, regulatory compliance assessment, internal control framework updates
Preferred skills
CISA, CRISC, CISSP certifications, experience with OJK, BI, and Kemkominfo regulations
Technologies
ISO 27001, PCI DSS, POJK, PBI
Responsibilities
Coordinate with Compliance team for gap assessments, assess effectiveness of IT controls, implement least privilege access management, follow up on audit recommendations, socialize IT policies for day-to-day operations
Seniority
Manager, hands-on IC with strategic oversight