IT GRC Analyst
XenditJob Description
📋 Description Own and support compliance programs for certification and audits; ensure controls are implemented and tested. Serve as primary GRC contact for regional regulatory needs; coordinate IT audits with regional bodies. Manage full certification lifecycle (scoping, gap analysis, issuance, surveillance). Conduct periodic IT risk assessments across markets; maintain risk register and track remediation. Perform internal control testing to evaluate IT control design and operation. Identify gaps across markets and coordinate remediation plans. 🎯 Requirements 3–5 years in IT GRC, IT risk, or IT compliance roles. PCI-DSS and ISO 27001 knowledge with implementation, certification, and audit readiness. Familiarity with Bank Indonesia (BI) and OJK regulations for payment providers. Willingness to address regulatory requirements in another Southeast Asian or international market (e.g., BSP, BOT, MAS, BNM). Proven experience conducting IT risk assessments, control testing, and gap analyses. Develop, review, and maintain IT policies, standards, and procedures.