Information Security Specialist

AIA Indonesia

Jakarta Pusat

On-site

IDR 90,000,000 - 130,000,000

Full time

13 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

AIA Indonesia is seeking a senior information security professional to lead governance, risk, and compliance across local and group standards. You will implement ISO/IEC 27001:2022 controls, align with NIST CSF 2.0, and ensure adherence to OJK regulations and PDP Law for insurance services.

Based in Jakarta, you will coordinate with Group CISO Office, manage third-party risk, and drive security-by-design in digital products while reporting to BU leadership and regulators.

Qualifications

  • Bachelor's degree required in information security or related field.
  • 5-8+ years in information security, ideally in financial services/insurance.
  • Experience implementing ISO/IEC 27001:2022 Annex A controls and NIST CSF 2.0 compatible programs.
  • Hands-on knowledge of cloud security, IAM, SIEM/EDR, and secure SDLC.

Responsibilities

  • Lead localization and enforcement of ISMS policies across the business unit.
  • Coordinate with Group CISO Office for policy interpretation and risk acceptance processes.
  • Ensure compliance with OJK Regulation No. 4/POJK.05/2021 and PDP Law; align with ISO 27001:2022 and NIST CSF 2.0.
  • Drive security governance, incident response, and business continuity planning.

Skills

Information security
Security governance
Risk management
Incident response
Cloud security

Education

Bachelor's degree in Information Security

Tools

ISO/IEC 27001:2022
NIST CSF 2.0
SIEM
EDR

Job description

At AIA we’ve started an exciting movement to create a healthier, more sustainable future for everyone.

It’s about finding new ways to not only better people's lives, but to better the communities and environments we live in. Encompassing our ambition of helping a billion people live Healthier, Longer, Better Lives by 2030.

And to get there, we need ambitious people who believe in playing an important part in shaping that future. People seeking unmatched career and personal growth opportunities, who are driven to work with, and learn from some of the most inspiring and supportive leaders in the business.

Sound like you? Then read on.

About The Role

The role is responsible to ensure the implementation and compliance of Group Information Security Standard and ISMS policies, while meeting local regulatory requirements (OJK, PDP Law) and aligning with international frameworks (ISO/IEC 27001:2022, NIST CSF 2.0). Act as the local focal point for security governance, risk management, incident response, and regulatory engagement.

Key responsibilities
  • Localize and enforce Group Information Security Standard and ISMS policies across the BU; map controls to ISO/IEC 27001:2022 Annex A (93 controls) and maintain the Statement of Applicability (SoA).
  • Ensure a risk management program consistent with NIST CSF 2.0 and Group governance framework, covering governance, supply‑chain risk, and measurable outcomes.
  • Ensure compliance with OJK Regulation No. 4/POJK.05/2021 (IT risk management for non‑bank financial institutions/insurance) and Indonesia PDP Law, reconciling any gaps between local regulations and Group standards.
  • Act as liaison between Group CISO Office and local BU for policy interpretation, exceptions, and risk acceptance processes.
2) Control Implementation & Assurance
  • Ensure technical and procedural controls are aligned to Group Information Security Standard, ISO/IEC 27001:2022 Annex A, and NIST CSF 2.0.
  • Coordinate with Group Security Operations team for SOC, SIEM, EDR, vulnerability management, ensuring localization for Indonesia regulatory reporting.
  • Support internal audits, external certification, and regulator inquiries; track remediation and risk acceptance with clear KPIs.
3) Incident Response & Business Continuity
  • Maintain BU incident response playbooks; ensure cross-border coordination with Group Security Operations team for escalations and evidence preservation.
  • Ensure Test and improve BCP/DR capabilities to meet local resiliency and OJK expectations.
4) Third‑Party & Cloud Risk Management
  • Ensure risk assessments and ongoing assurance for vendors and cloud providers, consistent with Group Standard and OJK outsourcing guidance.
  • Ensure cloud architectures is validated against ISO 27001, NIST CSF, and Group requirements.
5) Secure Product & Data Lifecycle
  • Ensure security‑by‑design is embedded for digital insurance services; ensure compliance with OJK digital insurance regulations and Group security principles.
  • Oversee data classification, retention, and deletion per PDP Law and Group standards.
6) Awareness & Culture
  • Deliver targeted security awareness programs aligned with Group Information Security Standard, ISO, and NIST frameworks.
  • Provide regular risk posture and compliance updates to BU leadership and Group CISO.
Qualifications
  • Bachelor’s degree in Information Security, Computer Science, or related field; advanced certifications a plus (ISO 27001 Lead Implementer/Lead Auditor, CISSP, CISM, CCSP).
  • 5-8+ years in information security, preferably in insurance/financial services with exposure to Indonesia OJK compliance and PDP Law requirements.
  • Demonstrated experience implementing ISO/IEC 27001:2022 Annex A controls and operating a program mapped to NIST CSF 2.0.
  • Hands‑on knowledge of cloud security (IaaS/PaaS/SaaS), identity & access management, SIEM/EDR, vulnerability management, and secure SDLC practices.
  • Fluent in English and Bahasa Indonesia (written and spoken) for effective communication with local regulators, internal teams, and Group stakeholders.
  • Strong presentation and reporting skills for senior management, regulators, and auditors.
  • Proficient in drafting policies, risk reports, incident summaries, and compliance documentation in English for Group and in Bahasa Indonesia for local regulatory needs.

Build a career with us as we help our customers and the community live Healthier, Longer, Better Lives.

You must provide all requested information, including Personal Data, to be considered for this career opportunity. Failure to provide such information may influence the processing and outcome of your application. You are responsible for ensuring that the information you submit is accurate and up-to-date.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Officer
Information Security Officer

Indonesia Stock Exchange • Jakarta Pusat

On-site
IDR 167,400,000 - 256,680,000
Information Security & Compliance Architect
Information Security & Compliance Architect

AIA Indonesia • Jakarta Pusat

On-site
IDR 90,000,000 - 130,000,000
Head of IT Security
Head of IT Security

Pengiklan Anonim • Tangerang

On-site
IDR 400,000,000 - 800,000,000
Risk Officer
Risk Officer

PT ITSEC Asia Tbk • Jakarta Selatan

On-site
IT Business Partners
IT Business Partners

AIA Indonesia • Daerah Khusus Ibukota Jakarta

On-site
Head of IT Security
Head of IT Security

PT Media Indonusa (Jakarta) • Jakarta Utara

On-site
IDR 900,000,000 - 1,300,000,000
Information Security Officer
Information Security Officer

White Glove Hiring • Jakarta Pusat

Hybrid
IDR 180,000,000 - 280,000,000
Retirement
Special for women
Food
+11
Sr Specialist, Security
Sr Specialist, Security

Mubadala Energy • Jakarta Pusat

On-site
IDR 600,000,000 - 1,000,000,000
IT Governance Specialist
IT Governance Specialist

Cermati.com • Jakarta Pusat

On-site
IDR 300,000,000 - 450,000,000
IT Security & GRC (Lead/Manager)
IT Security & GRC (Lead/Manager)

Cermati • Daerah Khusus Ibukota Jakarta

On-site
IDR 300,000,000 - 500,000,000