IT Security & GRC (Lead/Manager)

Cermati

Daerah Khusus Ibukota Jakarta

On-site

IDR 270,000,000 - 330,000,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Cermati is seeking an IT Governance, Risk, and Compliance (IT GRC) professional with a minimum of three years in banking or financial services. The role focuses on building and maintaining IT policies, ensuring regulatory compliance, and coordinating audits.

The candidate should have experience with ISO 27001 and PCI-DSS and understand Indonesian regulations such as OJK, BI, and Kemkominfo. Strong communication and writing skills are required to drive policy socialization and collaboration

Qualifications

  • Minimum 3 years in IT GRC or IT auditing within banking or financial services

Responsibilities

  • Develop and maintain IT policies, standards, and procedures per internal and Indonesian regulations (POJK, PBI)
  • Coordinate with Compliance to perform gap assessment and mitigate risks
  • Ensure all initiatives comply with standards and regulations (internal and external)
  • Develop and implement RBAC and least privilege access management
  • Assess effectiveness of IT controls to safeguard information and ensure availability
  • Coordinate with IT units to follow up on data requests and audits
  • Update internal control framework per ITGC, ITAC, ISO 27001, PCI DSS, and industry best practices
  • Socialize IT policy and awareness in day-to-day operations

Skills

IT GRC
Policy development
Communication skills
Audit & compliance

Job description

Cermati is a financial technology (fintech) startup based in Indonesia. Cermati simplifies the process of finding and applying for financial product by bringing everything online so people can shop around for financial products online and can apply online without having to physically visit a bank.

Our team hailed from Silicon Valley Tech companies such as Google, Microsoft, LinkedIn and Sofi as well as Indonesian startups such as Doku andTouchten. We have graduates from well known universities such as Universitas Indonesia, ITB, Stanford, University of Washington, Cornell and many others. We are building a company with the same culture of openness, transparency, drive and meritocracy as Silicon Valley companies. Join us in our cause to build a world class fintech company in Indonesia.

Job Description
  • Develop and maintain IT policies, standards, and procedures according to applicable internal and external requirements, including the applicable regulations in Indonesia (POJK, PBI)
  • Coordinate with the Compliance team to perform gap assessment. Recommend appropriate measures to mitigate risks.
  • Ensure that every initiative, development, and collaboration complies with the standards and regulations (internal and external)
  • Develop and implement the RBAC and least privilege of access management
  • Assess the effectiveness of IT controls, policies, and procedures in place to safeguard information assets, ensure data integrity, and maintain system availability
  • Coordinate with the related IT work units to follow up on data requests and the implementation of audit recommendations (internal audit, external audit, and regulator)
  • Continuously update and implement the internal control framework, policies, and procedures to strengthen the organization's IT governance according to IT General Control, IT Application control, ISO 27001, PCI DSS, and other industry best practices
  • Socialization and regular awareness to ensure IT policy, procedures, guidelines, and standards are implemented in the day-to-day operations
Qualifications
  • A minimum of 3 years of experience as Information Security, IT Governance, Risk, and Compliance (IT GRC), or IT Auditor in banking or the financial service industry
  • Experience in developing and maintaining IT and/or information security policies and procedures
  • Demonstrate good communication and writing skills
  • Proven experience in implementing and/or auditing ISO 27001 and PCI-DSS standards
  • Good understanding of the applicable regulatory requirements (such as OJK, BI, and Kemkominfo) and how they impact IT policies
  • One or more of the following or equivalent certifications preferred: CISA, CRISC, CISSP
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Strategic GRC & IT Security Lead for Fintech
Strategic GRC & IT Security Lead for Fintech

Cermati • Daerah Khusus Ibukota Jakarta

On-site
IDR 300,000,000 - 500,000,000
Internal Audit Associate
Internal Audit Associate

Cermati • Jakarta Pusat

On-site
IDR 122,760,000 - 200,880,000
IT Governance Specialist
IT Governance Specialist

Cermati.com • Jakarta Pusat

On-site
IDR 300,000,000 - 450,000,000
Junior IT Governance
Junior IT Governance

Indodana • Jakarta Pusat

On-site
IDR 200,880,000 - 357,120,000
null
Business Development Support Officer (Admin) - Digital Insurance
Business Development Support Officer (Admin) - Digital Insurance

PT Dwi Cermat Indonesia • Kemayoran

On-site
Business Development Support Officer - Digital Insurance
Business Development Support Officer - Digital Insurance

PT Dwi Cermat Indonesia • Kemayoran

On-site
IDR 200,880,000 - 312,480,000
Junior IT Governance
Junior IT Governance

Cermati • Jakarta Pusat

On-site
IDR 180,000,000 - 360,000,000
IT Governance Specialist
IT Governance Specialist

PT Dwi Cermat Indonesia • Jakarta Pusat

On-site
IDR 720,000,000 - 1,080,000,000
Branch Audit Associate
Branch Audit Associate

PT Dwi Cermat Indonesia • Jakarta Pusat

On-site
IDR 167,400,000 - 279,000,000
IT GRC
IT GRC

Siswaku Indonesia Pintar • Surakarta

On-site
IDR 180,000,000 - 300,000,000