Enable job alerts via email!

Senior It Grc And Data Privacy Analyst

Amartha

Daerah Khusus Ibukota Jakarta

On-site

IDR 200.000.000 - 300.000.000

Full time

Today
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading financial technology firm in Indonesia seeks a Senior IT GRC and Data Privacy Analyst to ensure compliance with regulatory standards and enhance data protection. The role involves developing GRC frameworks, conducting risk assessments, and collaborating with cross-functional teams to embed security best practices. Ideal candidates will have a minimum of 5 years experience in similar roles and strong communication skills in both Bahasa Indonesia and English.

Qualifications

  • Minimum 5 years of experience in IT Governance, Risk & Compliance, or Information Security.
  • Strong understanding of regulatory standards like ISO 27001, NIST, and UU PDP.
  • Hands-on experience in developing GRC frameworks and data privacy programs.
  • Solid knowledge of data protection principles and incident management.
  • Excellent communication skills in Bahasa Indonesia and English.

Responsibilities

  • Develop and maintain Amartha's GRC framework in alignment with regulations.
  • Conduct regular risk assessments and design mitigation plans.
  • Ensure adherence to data protection laws and manage incident responses.
  • Assess and monitor third-party vendors' security and privacy practices.
  • Support audit readiness and educate stakeholders on compliance.

Skills

IT Governance
Risk Management
Compliance Monitoring
Data Privacy
Analytical Skills
Stakeholder Management

Tools

Active Directory
LDAP
OAuth
SAML
Provisioning tools
Job description

About Amartha

At Amartha, we empower micro‑businesses across Indonesia, enabling growth and equal prosperity. We've supported over 2.7 million entrepreneurs—mostly women—by disbursing IDR 22.8 trillion in funding. As we step into 2025, Amartha is evolving into a technology‑driven financial ecosystem, expanding our reach in lending, funding, and payments. Through innovation and digital solutions, we aim to enhance accessibility, streamline processes, and create a seamless user experience.

About the Role

As a Senior IT GRC and Data Privacy Analyst at Amartha, you will play a key role in safeguarding our systems, data, and operations. You will lead the implementation of governance, risk, and compliance (GRC) frameworks while ensuring adherence to data privacy regulations such as ISO 27001, POJK, PSrE, and UU PDP. This role is crucial in strengthening Amartha’s security posture by embedding compliance and privacy best practices into every aspect of our technology and business processes.

About the Team

The Information Security team at Amartha is a highly analytical and collaborative group focused on driving security and privacy by design across the organization. We work closely with engineering, product, and operations teams to embed secure practices throughout the product lifecycle. Our mission is to be a trusted enabler of growth by ensuring resilience, compliance, and responsible data stewardship across Amartha's ecosystem.

What You Will Do
Governance, Risk, and Compliance (GRC)
  • Develop, implement, and maintain Amartha's GRC framework in alignment with regulatory standards and industry best practices
  • Conduct regular risk assessments to identify threats and vulnerabilities
  • Design and implement risk mitigation plans, and track resolution of identified issues
  • Monitor compliance with internal security policies and external regulations
Data Privacy & Protection
  • Ensure adherence to relevant data protection laws and regulations (e.g., UU PDP, GDPR, ISO 27701)
  • Conduct Data Protection Impact Assessments (DPIAs) for new products, initiatives, and vendors
  • Develop and maintain data privacy policies and procedures
  • Manage incident response for data breaches, including investigation, containment, and reporting
Vendor Risk & Compliance
  • Assess and monitor the security and privacy practices of third-party vendors
  • Support contract reviews to ensure vendors meet Amartha's compliance and data handling requirements
  • Partner with Procurement and Legal in vendor due diligence and onboarding
Regulatory & Policy Compliance
  • Stay current with evolving regulatory landscapes (e.g., POJK, PSrE, ISO 27001)
  • Support audit readiness and provide documentation for both internal and external audits
  • Educate and advise stakeholders across the company on compliance responsibilities
Identity & Access Management (IAM)
  • Develop and maintain IAM policies, processes, and technical controls
  • Administer user access management, including provisioning, de‑provisioning, and role reviews
  • Conduct periodic IAM audits and access certification campaigns
  • Work with infrastructure and engineering teams to implement access controls and enforce least‑privilege principles
Requirements
  • Minimum 5 years of experience in IT Governance, Risk & Compliance, or Information Security, preferably in financial services, fintech, or regulated industries
  • Strong understanding of regulatory standards and frameworks such as ISO 27001, NIST, POJK, PSrE, and UU PDP (or GDPR)
  • Hands‑on experience in developing and implementing GRC frameworks, data privacy programs, and compliance monitoring
  • Solid knowledge of data protection principles, incident management, and Data Protection Impact Assessments (DPIAs)
  • Familiarity with IAM technologies and concepts (e.g., Active Directory, LDAP, OAuth, SAML, provisioning tools)
  • Professional certifications are a plus (e.g., CRISC, CISM, CISA, CIPP, ISO 27001 Lead Implementer)
  • Excellent communication skills in both Bahasa Indonesia and English, with the ability to convey complex issues to technical and non‑technical audiences
  • Strong analytical, problem‑solving, and stakeholder management skills
  • Comfortable working in a fast‑paced, agile environment with cross‑functional collaboration
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.