11 часов назад
IT GRC Analyst (Fintech)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
IT GRC Analyst (Fintech): Managing regional IT governance, risk, compliance, and certification programs across Xendit's payment infrastructure with an accent on PCI-DSS, ISO 27001, regulatory audits, and multi-market controls. Focus on conducting risk assessments, testing control effectiveness, coordinating regulators and auditors, and translating complex requirements into actionable technical and operational controls.
Location: Jakarta, Indonesia
Company
provides payment infrastructure across Southeast Asia and is expanding into Greater China and LATAM through APIs, eCommerce integrations, and applications for entrepreneurs, SMEs, and enterprises.
What you will do
- Own and support IT compliance programs for regulatory audits and certifications, ensuring controls are implemented, tested, and evidenced.
- Coordinate IT audits and examinations with regional regulatory bodies across 's operating markets.
- Manage the full certification lifecycle for PCI-DSS, ISO 27001, and other applicable frameworks, including scoping, gap analysis, evidence preparation, auditor coordination, renewals, and surveillance.
- Conduct IT risk assessments, maintain a consolidated risk register, test controls, and track remediation through closure.
- Develop and maintain IT policies, standards, and procedures aligned with multi-jurisdictional requirements.
- Collaborate with engineering, product, security, and legal teams to embed compliance and risk considerations into system design and project delivery.
Requirements
- 3–5 years of hands-on experience in IT GRC, IT risk management, or IT compliance.
- Working knowledge of PCI-DSS and ISO 27001 implementation, certification, and audit readiness.
- Familiarity with Bank Indonesia and OJK IT governance regulations for payment service providers.
- Experience with IT risk assessments, control testing, gap analyses, and remediation planning.
- Ability to develop, review, and maintain IT policies, standards, and procedures.
- Strong analytical and communication skills for working with technical and non-technical stakeholders across multiple countries and time zones.
Nice to have
- Experience with Bank Indonesia PJP Category 1 or Category 2 licensing and regulatory examination readiness.
- Experience managing ISO 27001, PCI-DSS, or SOC 2 certification processes.
- Experience coordinating examinations with BSP, BOT, MAS, BNM, or comparable regional regulators.
- CISA, CRISC, ISO 27001 Lead Implementer, or ISO 27001 Lead Auditor certification.
- Fintech, digital payments, cloud security, or compliance-by-design experience.
Culture & Benefits
- Work across a fast-growing fintech environment and multiple Southeast Asian and international markets.
- Collaborate cross-functionally with engineering, product, security, and legal teams.
- Support the continuous improvement, tooling, and automation of regional GRC operations.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →