Tech Full-time
Jakarta, Indonesia
Stockbit / Bibit is looking for an IT Security – Governance, Risk & Compliance (GRC) professional to strengthen our security governance, risk management, and compliance practices.
You'll have the opportunity to build and strengthen security governance within a fast-growing fintech environment, working closely with Technology, Security, Risk, Compliance, and business teams.
Manage cyber risk identification, assessment, remediation tracking, and risk acceptance processes.
Ensure security compliance with regulatory requirements, internal/external audits, and applicable security standards.
Develop and maintain security policies, standards, controls, and control ownership frameworks.
Coordinate security audits, including evidence collection, finding management, and remediation tracking.
Establish and manage Third-Party / Vendor Security Risk Assessment processes.
Support data protection governance, including data classification, handling, and protection requirements.
Establish governance around access reviews, privileged access, and access control requirements.
Drive security awareness initiatives, including security training and phishing simulations.
Support business continuity, disaster recovery, and cyber resilience governance.
Manage security exceptions, compensating controls, and formal risk acceptance.
Support security incident handling, including incident coordination, documentation, post-incident review, and tracking of remediation actions.
Manage security dashboards and management reporting covering security posture, risk, compliance, initiatives, and security maturity
3–5 years of experience in IT Security, GRC, Cybersecurity, IT Audit, Risk Management, or related areas.
Strong understanding of security governance, risk management, and compliance frameworks.
Experience working with security audits, regulatory requirements, and control assessments.
Familiarity with frameworks and standards such as ISO 27001, NIST CSF, COBIT, or similar.
Experience in risk assessment, policy development, control implementation, and audit remediation.
Experience or good understanding of security incident handling and response processes.
Good understanding of information security, access management, data protection, and third-party risk.
Strong analytical, documentation, and stakeholder management skills.
Comfortable working with both technical and non-technical stakeholders.
Experience in fintech, financial services, or other regulated industries is a plus.
Share This Job