An application made for this job — a tailored resume and cover letter that speak straight to the posting.
PT Media Indonusa (Jakarta) seeks a Head of IT Security to lead the information security function across GRC, Security Engineering, and MIS, shaping policies and controls. You will drive PCI-DSS compliance, ISO/IEC 27001 alignment, risk management, and incident governance while integrating security into IT operations and payments environment.
This leadership role demands a decade in security with at least 3 years in a head role, plus strong communication with management and hands-on
Head of IT Security will lead the company's information security function comprehensively. This position oversees 3 functions: IT Governance, Risk & Compliance (GRC), IT Security Engineering, and Management Information System (MIS). The role is responsible for establishing security policies, ensuring compliance with industry standards, overseeing implementation of technical controls, and managing the company's internal information technology operations. The selected Head of IT Security will lead the company's security and compliance strengthening program to completion, building a solid and structured information security function for the company going forward.
Lead, develop, and manage IT GRC, IT Security Engineering, and MIS teams as an integrated information security function
Establish, set, and update company information security policies, including standards for secrets management, access control, and configuration baseline (CIS Benchmarks, ISO/IEC 27001)
Maintain and regularly review a technology risk register
Ensure and monitor company compliance with PCI-DSS and applicable regulatory requirements for payment service providers
Conduct and coordinate security audits and compliance testing by independent third parties on a regular basis
Design and oversee implementation of technical security controls across the company environment, including secrets management systems, multi-factor authentication, and access segmentation
Build and manage capabilities for monitoring, detection, and alerting on unusual activity on company systems, including fund transfer transactions
Conduct continuous vulnerability management, including regular scanning and coordination of penetration testing
Manage the entire company's internal information technology services, including user support (helpdesk), employee devices, office networks, and email and collaboration systems
Establish and enforce procedures for granting, changing, and revoking employee access rights at onboarding, role changes, and employment termination
Minimum 10 years of experience in information security or information technology, with at least 3 years in a security leadership role (Head of Security, CISO, IT Security Manager, or equivalent)
Experience leading multiple functions simultaneously (multi-team leadership), ideally including a combination of GRC, security engineering, and/or IT operations
Direct experience in the financial services, banking, or payment service provider industry regulated by Bank Indonesia and/or the Financial Services Authority
Proven experience leading and maintaining PCI-DSS compliance, including audit preparation and support
Experience developing information security policies and implementing recognized frameworks (CIS Benchmarks, ISO/IEC 27001, NIST)
Experience leading real security investigations and incident governance
Adequate technical understanding of cloud, containers/Kubernetes, and payment application architecture to oversee technical control implementation by the Security Engineering team
Ability to communicate technical risks to management clearly and firmly