Job description for IT Governance, Risk & Compliance Expert at Nityo Infotech
IT Governance, Risk & Compliance Expert
Location: Jakarta
Employment Type: Contract (6 months, extendable)
Work Arrangement: Full WFO
About the Role
We are looking for an experienced IT Governance, Risk & Compliance (GRC) Expert to strengthen IT governance, risk management, and compliance initiatives across the organization. This role is responsible for ensuring that IT systems, services, and infrastructure align with governance frameworks, regulatory requirements, security standards, and industry best practices while supporting business objectives.
Key Responsibilities
- Advise senior management on IT governance, internal controls, SOPs, risk management, and audit best practices.
- Conduct internal IT audits to ensure compliance with organizational policies, regulatory requirements, contractual obligations, and data protection standards.
- Perform security and compliance assessments for new and existing systems, applications, and processes.
- Develop and maintain IT governance frameworks, security standards, policies, and procedures.
- Collaborate with cross-functional teams to ensure IT controls are effective, appropriate, and consistently implemented.
- Support disaster recovery (DR) and business continuity planning (BCP), including backup and recovery processes.
- Conduct business impact analysis and maintain the organization's IT risk register.
- Monitor emerging regulations, cybersecurity threats, and industry trends to ensure ongoing compliance.
- Design, implement, and manage governance, risk, and compliance processes, including change management and stakeholder engagement.
- Promote a culture of governance, risk awareness, and continuous improvement across the organization.
Minimum Qualifications
- Bachelor's degree in Information Technology, Computer Science, Information Systems, or a related field.
- Minimum 2–3 years of experience in IT Governance, Risk & Compliance (GRC) or a similar role.
- Experience managing IT governance, risk, compliance, and internal control processes within a medium to large organization.
- Experience developing, implementing, and maintaining IT policies, SOPs, and governance frameworks.
- Strong understanding of information security principles, IT governance, and risk management.
- Familiarity with regulatory compliance, IT audits, and data protection requirements.
- Professional certifications in information security or IT governance (e.g., ISO 27001, CISA, CRISC, COBIT, ITIL) will be an advantage.

