Junior IT Governance
Department:
Job Summary
- Assist in researching regulatory updates industry best practices and IT GRC benchmarks to support senior team members in drafting any internal policy & procedure proposals.
- Design update and enforce IT GRC policies aligned with financial sector regulations and global frameworks (COBIT 2019 ISO 27001 ISO 27701 ISO 31000 GDPR)
- Gather organize and summarize input and operational pain points from various Departments (HR Legal Business Units) regarding existing IT compliance & security common practices.
- Assist in drafting core SOPs updating governance policies and maintaining regulatory compliance checklists while control checklists designed to improve daily internal IT GRC culture following POJK PBI regarding IT implementation on Fintech Industry.
- Identify & help map proposed internal controls against existing cross-departments workflows to identify potential operational friction before policies are finalized.
- Assist in identifying all relevant risks in IT related activity tasks collect manage and conduct IT risk control self assessment to prevent and define risk mitigation designed proposals.
- Collect organize and verify audit evidence for internal reviews and external regulatory inspections (audit support internal team).
- Work with IT Infrastructure IT Information & Security and Data Platform teams to log review and track system change requests. Thats a good value to understand and know in general (at least) regarding IT Infra Info-sec and data governance implementation.
- Conduct routine checks to ensure day-to-day operations & business implementation are aligned with IT governance implementation on financial industry standards.
- Become a support PIC to drive any change management and implementation for IT GRC policies.
- Become a support PIC for communicating things related to IT Security IT Risk Management Governance and Compliance for both internal and external stakeholders.
- Working closely and supporting execution tasks with mid and senior management personnel across the organization to understand the organizations contexts strategy and governance needs to adapt policies accordingly.
Qualifications :
- Bachelors degree in computer science information systems related fields or equivalent work experience
- Working experience as Compliance & Information Security IT Governance Risk and Compliance (IT GRC) Risk Management or IT Auditor in the financial service industry or banking or a similar company in governance roles is a plus
- Good logical analysis & problem solving skills
- Excellent verbal/written communication & organizational skills
- Leadership execution & process oriented and negotiation skills
- Knowledge of cybersecurity standards such as ISO 27001 ISO 27701 PCI-DSS and NIST 2
- Knowledge of regulations such as POJK PBI LPBBTI and UU PDP GDPR
- Knowledge of IT Governance framework such as COBIT ITIL
- Knowledge of cybersecurity frameworks
- Good understanding of legal principles personal data protection laws or obtaining Data Protection Officer certification is a plus
Remote Work :
No
Employment Type :
Contract
About Company
Cermati is a financial technology (fintech) startup based in Indonesia. Cermati simplifies the process of finding and applying for financial product by bringing everything online so people can shop around for financial products online and can apply online without having to physically ... View more