IT GRC Specialist
IT GRC Specialist
nityo infotech indonesia2-4 Years
- Posted 19 hours ago
- Be among the first 10 applicants
Job Description
What You'll Do
- Advise the board and senior management on IT internal controls, SOPs, governance, risk, and audit best practices
- Conduct internal audits to ensure compliance with best practices, regulatory requirements (including Data Protection), and contractual obligations
- Perform security and compliance assessments on new and existing systems, processes, and technologies
- Collaborate cross-functionally to define IT security standards and develop supporting organizational policies
- Partner with business units to ensure controls are adequate, appropriate, and effective
- Participate in disaster recovery and business continuity planning, including backup systems
- Conduct business impact analysis and support development of the IT risk register
- Stay current on regulatory developments and evolving IT/information security trends
- Design, consult on, and implement corporate compliance and risk processes — including change management — to ensure governance frameworks are well-implemented
Requirements
- Bachelor's degree in IT, Computing Studies, or Information Systems
- 2–3 years of experience in IT Governance, Risk & Compliance (GRC), ideally within a large environment
- Solid understanding of fundamental information security concepts and technologies
- Hands-on experience with SOP design, creation, approval-seeking, implementation, and change management
- IT security certification (e.g., CISA, CISM, ISO 27001) is a plus
- Strong problem-solving, relationship-building, team collaboration, and communication skills (written and oral)
- Trustworthy and goal-oriented with a proactive mindset
More Info
Key Skills
IT internal controls
IT security standards
audit best practices
IT risk register
