IT GRC Analyst
Core
Ensuring IT systems, processes, and controls meet regulatory obligations and certification standards across Southeast Asia and other operating markets.
Role type
Mid-level/senior IT GRC Analyst
Builds
Compliance programs, certification lifecycles, and risk management frameworks for a fintech payment infrastructure company.
Domain
Fintech, digital payments, financial services, multi-jurisdictional regulatory compliance
Deliverable
dashboards & analysis
Required skills
IT GRC, IT Risk Management, IT Compliance, PCI-DSS, ISO 27001, regulatory gap analysis, control testing, policy development, multi-market coordination
Preferred skills
PJP licensing requirements, end-to-end certification management, cloud security control frameworks, compliance-by-design principles
Technologies
None explicitly stated
Responsibilities
Own and support compliance programs for certification and regulatory audits, serve as primary GRC point of contact for regional regulatory needs, manage full certification lifecycle, conduct periodic IT risk assessments, perform internal control testing, identify compliance gaps and execute remediation plans, develop and enforce IT policies, coordinate regulatory and third-party audits, monitor evolving regulatory landscape, produce compliance dashboards and reports, collaborate with engineering and product teams to embed compliance, support continuous improvement of GRC processes.
Seniority
Mid-level/senior, individual contributor