IT Security Governance and Compliance

PT GTech Digital Asia

Tangerang

On-site

IDR 300,000,000 - 600,000,000

Full time

6 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

PT GTech Digital Asia is seeking an IT Risk and Compliance Senior Officer to support, execute, and continuously improve IT governance, risk, and compliance activities. The role emphasizes hands-on implementation, audit support for ISO/IEC 27001, and GDPR/PDP/NIST compliance within a technology-focused organization.

The position requires strong knowledge of IT governance, risk assessment, and policy development, with collaboration across IT, Security, PMO, and Legal to embed robust controls

Qualifications

  • Strong knowledge of IT Governance, IT Controls, and Information Security Controls.
  • Hands-on understanding of ISO/IEC 27001 (Clauses & Annex A), GDPR/PDP Regulation, NIST CSF / NIST SP 800.
  • Experience in control design, control implementation, and control effectiveness assessment.
  • Skilled in risk assessment, risk register management, and risk treatment tracking.
  • High attention to detail with strong documentation, evidence management, and audit support skills.
  • Experience in developing and maintaining policies, standards, procedures, and guidelines.
  • Ability to translate regulatory and security standards into operational and technical controls.
  • Familiar with secure-by-design and privacy-by-design principles.
  • Experience supporting project governance, SDLC controls, and compliance checkpoints.
  • Exposure to Change Control Board (CCB) and Design Review Board (DRB) processes.
  • Strong stakeholder communication and coordination across IT, Security, Engineering, PMO, and Legal.
  • Ability to prepare compliance reports, risk summaries, and management documentation.
  • Self-motivated, able to work independently with minimal supervision.

Responsibilities

  • Support, execute, and continuously improve IT GRC activities.
  • Oversee audit support for ISO/IEC 27001 and compliance with GDPR/PDP and NIST.
  • Embed governance and security controls across project delivery, change management, and design reviews.
  • Contribute to policy lifecycle and control design within a technology-focused organization.
  • Collaborate with IT, Security, Engineering, PMO, and Legal stakeholders.
  • Prepare compliance reports and risk summaries for management.

Skills

IT Governance
IT Controls
ISO/IEC 27001
GDPR PDP
NIST CSF
Risk assessment
Audit support
Policy development
Regulatory translation
Stakeholder communication
Control design
SDLC controls

Job description

The IT Risk and Compliance Senior Officer is responsible for supporting, executing, and continuously improving the organization’s IT governance, risk, and compliance (GRC) activities. This role focuses on hands‑on implementation, operational oversight, and audit support for ISO/IEC 27001 (internal and external audits), as well as compliance with GDPR / PDP Regulation and NIST requirements. The role ensures that governance and security controls are effectively embedded across project delivery, change management, design reviews, audit processes, and policy lifecycle within a technology-focused organization.

Job Description
The IT Risk and Compliance Senior Officer is responsible for supporting, executing, and continuously improving the organization’s IT governance, risk, and compliance (GRC) activities. This role focuses on hands‑on implementation, operational oversight, and audit support for ISO/IEC 27001 (internal and external audits), as well as compliance with GDPR / PDP Regulation and NIST requirements. The role ensures that governance and security controls are effectively embedded across project delivery, change management, design reviews, audit processes, and policy lifecycle within a technology-focused organization.

Minimum Qualifications
  • Strong knowledge of IT Governance, IT Controls, and Information Security Controls
  • Hands‑on understanding of ISO/IEC 27001 (Clauses & Annex A), GDPR/PDP Regulation, NIST CSF / NIST SP 800
  • Experience in control design, control implementation, and control effectiveness assessment
  • Skilled in risk assessment, risk register management, and risk treatment tracking
  • High attention to detail with strong documentation, evidence management, and audit support skills
  • Experience in developing and maintaining policies, standards, procedures, and guidelines
  • Ability to translate regulatory and security standards into operational and technical controls
  • Familiar with secure‑by‑design and privacy‑by‑design principles
  • Experience supporting project governance, SDLC controls, and compliance checkpoints
  • Exposure to Change Control Board (CCB) and Design Review Board (DRB) processes
  • Strong stakeholder communication and coordination across IT, Security, Engineering, PMO, and Legal
  • Ability to prepare compliance reports, risk summaries, and management documentation
  • Self‑motivated, able to work independently with minimal supervision
Unlock job insights

Hirer responsiveness Salary match Number of applicants

We are Technology Company and member of one of the largest group company in Indonesia with main focus on investing on technology. GTech provides technology solution that allows brands and organization to create a seamless customer experiences both online to offline with goal to improve revenue growth. Headed by Ariadi Anaya, Chief Executive Officer; GTech is a team of 80 passionate professionals driven by the spirit to be "bold and explore new things". And with its headquarters in Jakarta, we have team member spread across Singapore and China.

We are Technology Company and member of one of the largest group company in Indonesia with main focus on investing on technology. GTech provides technology solution that allows brands and organization to create a seamless customer experiences both online to offline with goal to improve revenue growth. Headed by Ariadi Anaya, Chief Executive Officer; GTech is a team of 80 passionate professionals driven by the spirit to be "bold and explore new things". And with its headquarters in Jakarta, we have team member spread across Singapore and China.

Researching careers? Find all the information and tips you need on career advice.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Compliance - GTech
IT Compliance - GTech

Gtech • Tangerang

On-site
IDR 180,000,000 - 280,000,000
GRC & IT Security Lead – ISO 27001, GDPR/NIST
GRC & IT Security Lead – ISO 27001, GDPR/NIST

PT GTech Digital Asia • Tangerang

On-site
IDR 300,000,000 - 600,000,000
Senior IT Compliance & Risk Officer (ISO27001/GDPR)
Senior IT Compliance & Risk Officer (ISO27001/GDPR)

Gtech • Tangerang

On-site
IDR 180,000,000 - 280,000,000
IT Governance Specialist
IT Governance Specialist

Cermati.com • Jakarta Pusat

On-site
IDR 300,000,000 - 450,000,000
Junior IT Governance
Junior IT Governance

Stie Yai • Jakarta Pusat

On-site
IDR 120,000,000 - 180,000,000
Junior IT Governance
Junior IT Governance

Indodana • Jakarta Pusat

On-site
IDR 200,880,000 - 357,120,000
null
Digital Governance, Risk, and Compliance (GRC)
Digital Governance, Risk, and Compliance (GRC)

Referensiin_Aja • Jakarta Barat

On-site
IDR 400,000,000 - 700,000,000
Senior IT Governance
Senior IT Governance

Akulaku Indonesia • Jakarta Pusat

On-site
IDR 539,665,407 - 809,498,110
Senior IT Governance
Senior IT Governance

Akulaku Group • Jakarta Pusat

On-site
IDR 180,000,000 - 360,000,000
IT GRC Analyst Jakarta, Indonesia
IT GRC Analyst Jakarta, Indonesia

Xendit Inc. • Daerah Khusus Ibukota Jakarta

On-site
IDR 25,000,000 - 35,000,000