A complete application in a minute — tailored resume and cover letter, ready to send.
PT Orange Inovasi Digital is seeking an IT GRC & Security professional to lead ISO 27001 audit preparation, risk assessments, and policy development. You will coordinate evidence collection, control reviews, and remediation with cross-functional teams.
This role requires strong analytical, documentation, and communication skills, plus 2+ years in IT GRC or Information Security, and a practical understanding of security frameworks.
Manage ISO 27001 audit preparation and execution, including evidence collection, documentation, and follow-up on audit findings
Handle IT security governance, risk, and compliance activities, including risk assessments, control reviews, and security gap analysis
Develop and maintain IT security policies, procedures, standards, and related documentation
Monitor the implementation and effectiveness of security controls and coordinate remediation of identified risks and vulnerabilities
Collaborate with technical and business teams to strengthen security practices and ensure compliance with applicable requirements
Bachelor's degree in Computer Science, Software Engineering, Cybersecurity, Information Systems, or related field
Minimum 2 years of experience in IT GRC, IT Security, Information Security, or related role
Hands-on experience with ISO 27001 audits, including audit preparation, evidence collection, and follow-up on findings
Good understanding of IT security principles, security controls, risk management, and common security frameworks
Strong analytical, documentation, and communication skills, with the ability to work effectively with both technical and non-technical teams