IT GRC

Honest

Indonesia

On-site

IDR 240,000,000 - 480,000,000

Full time

7 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

ESOP
Training subsidies
Healthcare plan
Wellness allowance
Flat structure

Job summary

Honest is hiring an IT GRC Specialist to fortify governance, risk management, and compliance across our fintech tech stack. You will lead audits (PCI-DSS, ISO 27001), draft policies, and produce risk insights for stakeholders.

You will train staff on security culture, review third-party security, and ensure regulatory alignment with ISO and related standards in a fast-growing environment.

Qualifications

  • Knowledge of ISO, NIST, PCI-DSS frameworks.
  • Proven experience thriving in regulatory/audit environments (PCI-DSS, ISO 27001).
  • Attention to detail during risk assessments and controls testing.
  • Ability to translate compliance/tech terms into plain English.
  • Collaborate with international teams in English.

Responsibilities

  • Lead annual audits (PCI-DSS, ISO 27001, regulator-specific) and coordinate remediation.
  • Draft, maintain and align IT policies with ISO 27001 and local regulations.
  • Generate monthly cybersecurity KRIs and communicate risk posture to stakeholders.
  • Develop and deliver cybersecurity training and phishing simulations.
  • Identify IT risks early and advise on mitigations with stakeholders.
  • Coordinate IT governance processes and incident lesson-learned reviews.
  • Review vendor/partner security to ensure alignment with internal standards.

Skills

Compliance frameworks
Audit experience
Attention to detail
Communication skills
English proficiency

Job description

Who we are
We are Honest – a company committed to building financial products that people truly love. Our products are designed to be fair, simple, and genuinely useful in everyday life. Our diverse team brings together people from different backgrounds who share the same goal: to create meaningful solutions that make finance better. After successfully launching our first product, we're now in an exciting growth stage, learning fast, moving quickly, and building together as a team.

About the role

Join Honest as an IT GRC Specialist and help us build a secure, compliant, and resilient technology environment. You'll be at the forefront of technology governance, risk management, and regulatory compliance, partnering with teams across the organization to strengthen controls, manage IT risks, support audits, and ensure adherence to industry regulations. If you have a passion for technology risk, information security, and driving governance excellence in a dynamic fintech environment, we'd love to hear from you.

How you will make an impact
  • Audit and Regulatory Compliance PIC: You’ll lead the charge for annual audits ranging from PCI-DSS, ISO 27001, along with generic and regulator specific audits.
  • You’ll draft and maintain IT policies and procedures and ensure they are aligned with ISO 27001 and the latest local regulations while remaining readable by the general people.
  • Data-Driven Insights: Produce monthly cybersecurity Key Risk Indicators (KRI). Work with various stakeholders to tell the story of our cyber risk posture.
  • Human Firewall: Own our security culture by managing and conducting annual cybersecurity training and run phishing campaigns.
  • Risk Navigation: Identify IT risks before they become problems and help stakeholders how to mitigate.
  • IT Governance: Enforce IT governance by coordinating with stakeholders to follow the proper processes such as conducting lesson-learned for incidents or annual user access review.
  • Third-Party Trust: Review our vendor and partners to ensure their security standards match our own.
What you need to have
  • Framework knowledge: You know and understand ISO, NIST, PCI-DSS.
  • Audit experience: Proven experience thriving in high-stakes audits like regulatory audits, PCI-DSS or ISO 27001.
  • Attention to detail to notice the small stuff that others miss during risk assessments.
  • Communication skills: You need to to translate compliance or technical terms into plain English.
  • English to collaborate with diverse multi-national teams.
Why you'll love it here
  • Everyone gets ESOP — we're all owners here
  • Training course and book subsidies
  • You'll work with some of the sharpest people in the industry
  • Top-of-the-line medical healthcare plan
  • Monthly wellness allowance
  • One of the best-funded startups in Southeast Asia, backed by Silicon Valley investors
  • No titles or hierarchy — we value contribution and celebrate wins together

At Honest, we are committed to equal employment opportunities regardless of race, color, ethnicity, ancestry, religion, national origin, gender, sex, gender identity or expression, sexual orientation, age, citizenship, marital or parental status, disability, or other class protected by applicable law. We are proud to be an equal opportunity workplace.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT Security Operations
IT Security Operations

Honest • Indonesia

On-site
IDR 200,880,000 - 334,800,000
ESOP
Training subsidies
Excellent healthcare
+1
Compliance Specialist - Product
Compliance Specialist - Product

Honest • Indonesia

On-site
IDR 360,000,000 - 600,000,000
ESOP
Training course subsidies
Book subsidies
+1
Corporate Secretary Specialist
Corporate Secretary Specialist

Honest • Indonesia

On-site
IDR 420,000,000 - 660,000,000
ESOP
Training subsidies
Healthcare plan
HRBP
HRBP

Honest • Indonesia

On-site
IDR 250,000,000 - 450,000,000
ESOP
Medical coverage
Training subsidies
Head of Internal Audit
Head of Internal Audit

Honest • Jakarta Pusat

On-site
IDR 1,200,000,000 - 1,800,000,000
ESOP
Training subsidies
Collaborative team environment
Influencer Specialist
Influencer Specialist

Honest • Indonesia

On-site
IDR 167,400,000 - 357,120,000
ESOP
Training course and book subsidies
Top-tier medical healthcare plan
+1
IT GRC Manager - Digital Identity
IT GRC Manager - Digital Identity

PT GOTO GOJEK TOKOPEDIA TBK • Jakarta Utara

On-site
IDR 600,000,000 - 1,200,000,000
Medical Insurance
Gym Room
Play Room
+1
Head of Regulatory Compliance
Head of Regulatory Compliance

Honest • Indonesia

On-site
IDR 80,000,000 - 140,000,000
ESOP
13th month salary
Wellness allowance
+4
Head of Risk
Head of Risk

Honest • Indonesia

On-site
IDR 80,000,000 - 180,000,000
ESOP
Jakarta office
14 days annual leave
+4
IT GRC Manager - Digital Identity
IT GRC Manager - Digital Identity

GoPay • Jakarta Pusat

Hybrid
IDR 450,000,000 - 650,000,000