IT GRC
About Job
As an IT GRC professional at Paper.id, you will play a crucial role in managing the governance, risk, and compliance of our IT systems. You will be responsible for ensuring that our IT infrastructure aligns with regulatory standards and best practices, safeguarding the integrity and security of our data.
This position requires a proactive approach to identifying potential risks and implementing effective compliance strategies. You will work closely with various departments to ensure that all IT operations support the organization’s objectives, providing valuable insights to drive informed decision-making.
Skills & Qualification
Strong understanding of IT governance frameworks helps ensure alignment with business goals.
Proficiency in risk management methodologies aids in identifying and mitigating potential threats.
Knowledge of compliance regulations like GDPR and ISO standards is essential for maintaining legal and regulatory adherence.
Deep understanding of regulatory requirements, including Bank Indonesia (BI), OJK, ISO 27001:2022, SOC Type 2 (SOC2) and PCI DSS standards**.**
Analytical skills are crucial for assessing IT processes and identifying areas for improvement.
Excellent communication skills facilitate effective collaboration across diverse teams.
Experience with audit processes enhances the ability to prepare and respond to compliance audits.
Problem-solving abilities are necessary for developing innovative solutions to complex compliance challenges.
Responsibilities
Develop and implement IT governance frameworks to ensure compliance with industry standards
Conduct risk assessments to identify vulnerabilities in the IT infrastructure and recommend mitigation strategies
Collaborate with various departments to align IT operations with organizational objectives
Monitor compliance with IT policies and procedures and report on adherence to management
Prepare for and facilitate internal and external IT audits to ensure compliance with regulatory requirements
Provide guidance and training to staff on IT compliance and best practices to foster a culture of compliance
Stay updated on new regulations and emerging IT risks to continuously improve governance strategies