Deskripsi pekerjaan Digital Governance, Risk, and Compliance (GRC) Referensiin_Aja
"Warning : Before apply this job posting, please write your account name same with your linkedin account "
From this Platform, we want to help our partners in spreading job vacancy below :
Key Responsibilities:
- Identify, assess, and develop end-to-end mitigation plans for risks arising from the adoption of digital technologies and IT infrastructure,
- Conduct IT risk and cybersecurity assessments of IT vendors and third parties (Third Party / Vendor Security Assessments) across the vendor lifecycle,
- Design, execute, and maintain periodic employee awareness programs on IT risk and cybersecurity practices,
- Develop and maintain IT and cybersecurity risk registers, including risk taxonomy, root-cause classification, and mapping of risks to business objectives and controls,
- Evaluate the design and operating effectiveness of IT controls and recommend remediation, with follow-up tracking to closure,
- Support the drafting, review, and cascade of digital governance policies and standards and monitor compliance,
- Coordinate internal/external audit and regulatory requests, prepare documentations, and track corrective actions.
Key Qualifications:
- Minimum 5 years in IT/digital risk management, IT governance, IT audit, or cybersecurity risk; experience in complex, regulated , holding-company, BUMN, or financial-institution environments is highly preferred.
- Strong understanding of IT governance and risk management frameworks (COBIT, ISO 27001, NIST); proven ability to perform end-to-end IT risk management, including risk assessment, control evaluation, and risk register maintenance.
- Hands-on experience conducting third-party / vendor security assessments and translating findings into actionable, risk-based mitigation plans.
- Ability to independently challenge risk assessments and risk- acceptance decisions; experience coordinating audits, preparing audit-ready documentation, and driving remediation.
- Certifications (preferred): CRISC, CISA, CISM, or ISO 27001
- Lead Implementer/Auditor.
- Strong stakeholder engagement and documentation discipline
- Working proficiency in both Bahasa Indonesia and English, written and spoken.
ASAP
Industry : Government
Location : Jakarta
Contract : 12 Months, WFO

