About the Role :
Reviewing and monitoring IT Security & Governance, Risk, & Compliance in accordance with the scope and time period set.
What You Will Do :
- Reviewing risks and developing security standards, procedures, and controls to manage risk. Conduct IT policy reviews and also perform performance tracking and dashboards, technologies, and tools.
- Reviewing IT Risk Assessment, IT Risk Compliance related to new business/product changes.
- Carry out monitoring of the effectiveness of the implementation of the RCSA process on a regular basis. Coordinate with internal business on technology compliance, audits and regulatory inquiries both internal and external. Representing IT from the perspective of Information security, recovery and technology risk.
- Ensuring organizational compliance and effectiveness of control processes to company requirements through appropriate communication, regular practice checks, and continuous policy/process improvement.
- Responsible for ensuring the planning and implementation of IT Disaster Recovery in order to support the agreed Business Continuity.
What You Need to Have :
- S1 Computer Science or related field
- Minimum 5 years experience in IT banking/fintech
- Experienced in the field of IT Governance and Risk
- Knowledge of ISO 27001, NIST, COBIT, and ITIL/ITSM,
- Mastery of OWASP Top 10, CWE/SANS Top 25, WASC
- Certified in Risk and Information Systems Control (CRISC) or equivalent
- Mastering IT Risk and Governance
- Understanding IT Compliance
- Familiar with ICT Business e.g. Consulting, Managed Services, Cloud Services, etc. Exposed in facets of IT e.g. Projects, Delivery Support, Infrastructure, SW Development, etc.
- Have experience in Industry standards for IT Governance and control frameworks e.g. COBIT, ITIL/ITSM, Project Development and SW, ISO 27001, InfoSec/Data Privacy, NIST.
- Have performed IT audits or are familiar with Information Security, Data Privacy, Information Systems Audit requirements and other IT risk management or due diligence practices
- Knowledge of IT Compliance and POJK MRTI