IT GRC (Governance, Risk, and Compliance)
pt bank rakyat indonesia (persero) tbk- Posted 8 hours ago
- Be among the first 10 applicants
Job Description
About the Company
Bank Rakyat Indonesia (BRI) is one of the largest state-owned banks in Indonesia. For more than 130 years of providing the best services for all levels of society, BRI has taken part in efforts to develop the country. With the vision of The Most Valuable Banking Group in Southeast Asia and Champion of Financial Inclusion , BRI focuses on developing the best talent with strong characters to give back to Indonesia.
BRI is not only a place to work, but a place where you can optimize your best potential to contribute and give impact.
Open Position: IT GRC (Governance, Risk, and Compliance)
About the Role
As an IT GRC, you will play a key role in supporting IT governance, risk, and compliance activities. You will collaborate with IT, Cybersecurity, Risk, and Audit teams to conduct control assessments, manage compliance evidence, monitor remediation, and ensure alignment with applicable policies, regulations, and frameworks.
Responsibilities
- Support IT Governance, Risk, and Compliance (GRC) initiatives, including IT control assessments, compliance activities, and audit coordination.
- Act as a liaison between IT/IS/Cybersecurity teams and Risk/Audit functions to facilitate assessments, evidence collection, and compliance requirements.
- Manage GRC activities and documentation, including questionnaires, control assessments, audit evidence, asset information, and user access reviews.
- Perform and document control testing, identify compliance gaps, and support the preparation of audit narratives and reports.
- Monitor and support the remediation of audit findings, risk exceptions, and compliance issues, including tracking action plans and their progress.
- Collaborate with IT/IS teams to review and maintain security policies, procedures, KPIs, and KRIs.
- Monitor changes in regulations, frameworks, and industry best practices to support ongoing compliance and risk management.
- Work collaboratively with cross-functional stakeholders, including IT, Cybersecurity, Risk, Audit, Engineering, and Legal teams.
Qualifications
- Bachelor's degree in Information Security, Information Systems/Technology, Cybersecurity, Risk Management, or a related field.
- Minimum 2 year of experience in IT GRC, IT Audit, IT Risk, Compliance, or a related function.
- Good understanding of IT governance, risk management, internal controls, and compliance practices.
- Familiarity with GRC platforms/tools and IT control assessment processes.
- Basic understanding of enterprise IT infrastructure, including operating systems, directory services, and security technologies.
- Familiarity with Microsoft Office 365, particularly Excel and SharePoint.
- Knowledge of relevant frameworks and standards such as ISO 27001, NIST CSF, SOX, and OJK/Bank Indonesia regulations is preferred.
- Strong analytical, documentation, and problem-solving skills, with attention to detail.
- Excellent written and verbal communication skills, with the ability to prepare clear control narratives and reports.
- Strong interpersonal and stakeholder management skills, with the ability to collaborate effectively across functions.
- Experience in IT consulting or public accounting/audit is a plus.
Equal Opportunity Statement
We are committed to diversity and inclusivity in our hiring practices.
More Info
Key Skills
compliance activities
NIST CSF
IT control assessments
OJK Bank Indonesia regulations




