Job Search and Career Advice Platform

Enable job alerts via email!

ID - GRC Specialist

Zoho APAC

Jawa Barat

On-site

IDR 750.125.000 - 1.000.167.000

Full time

4 days ago
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading technology firm located in Indonesia seeks a Governance, Risk, and Compliance (GRC) Specialist. This role focuses on ensuring compliance with local regulations, managing risk registers, and supporting audits. The ideal candidate holds a Bachelor’s degree and has at least 3 years of experience in governance within a technology environment. Important skills include analytical thinking, strong communication abilities, and familiarity with ISO standards. The position supports professional growth through collaboration and training opportunities.

Qualifications

  • Minimum of 3 years’ experience in governance, risk, or compliance within a technology or IT services industry.
  • Fluency in English and Bahasa Indonesia for effective communication.

Responsibilities

  • Provide guidance on Indonesian regulations impacting digital operations.
  • Develop and maintain a comprehensive risk register.
  • Drive implementation of effective internal controls across departments.

Skills

Analytical skills
Communication skills
Risk assessment methodologies
Understanding of ISO 27001
Compliance management tools
Detail-oriented

Education

Bachelor’s degree in Law, Finance, Accounting, Information Technology, Business
Job description

The Governance, Risk, and Compliance (GRC) Specialist will play a key role in strengthening our overall compliance posture by implementing, maintaining, and improving our internal governance frameworks. This role requires learning the local laws and regulations in addition to assessing business processes, managing risk registers, supporting both internal and external audits, and ensuring alignment with relevant compliance frameworks. The ideal candidate should have experience in IT governance, data privacy, and operational risk management, preferably within a technology or SaaS environment.

Roles and Responsibilities
  • Provide guidance on and interpretation of key Indonesian regulations impacting our digital operations, including but not limited to PSE, PSRE, and the Personal Data Protection Law (UU PDP), ensuring compliance with data privacy and security requirements.
  • Keep track of relevant local laws and regulations related to technology, telecommunications, data localization, and cross-border data transfers.
  • Develop and maintain a comprehensive risk register for all Indonesian operations, focusing on regulatory, operational, and reputational risks in alignment with ISO 27001 and other standards as required.
  • Drive the implementation of effective internal controls across various departments to mitigate identified risks.
  • Prepare and present periodic reports to senior management on compliance status, risk posture, and governance effectiveness.
  • Collaborate closely with the HR team to monitor updates to Indonesian labor laws and regulations (e.g. Omnibus Law/Cipta Kerja, ministerial decrees).
  • Serve as a point of contact for external audits.
  • Proactively learn and understand business processes and Zoho’s products, including attending events for learning products, to ensure understanding of the impact of regulations and to provide contextually accurate regulatory guidance.
  • Conduct internal audits for different offices as needed.
  • Travel to corporate headquarters in India for training and collaboration.
Requirements
  • Bachelor’s degree in Law, Finance, Accounting, Information Technology, Business, or a relevant field of studies.
  • Minimum of 3 years’ experience in governance, risk, or compliance within a technology or IT services industry.
  • Good understanding of ISO 27001, ISO 27701, SOC 2 and PDPA (Indonesia and/or other regional privacy laws).
  • Experience with risk assessment methodologies and compliance management tools.
  • Strong analytical and documentation skills with high attention to detail.
  • Excellent communication and interpersonal skills for engaging with cross-functional teams.
  • Professional certifications such as ISO 27001 Lead Implementer/Auditor, CISA, CRISC or similar are an advantage.
  • Fluency in English and Bahasa Indonesia is required for communicating with stakeholders.
Competencies
  • Decisiveness: Able to provide clear compliance guidance, even in ambiguous regulatory situations.
  • Analytical Thinking: Strong ability at analyzing complex legal texts and translating them into practical business requirements.
  • Integrity: Demonstrates highest level of professionalism and ethical standards.
  • Proactive Monitoring: Committed to continuously tracking new and emerging legislation.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.