IT Governance
Key Responsibilities
- Identify, assess, and develop end-to-end mitigation plans for risks arising from the
adoption of digital technologies and IT infrastructure,
- Conduct IT risk and cybersecurity assessments of IT vendors and third parties (Third-
Party / Vendor Security Assessments) across the vendor lifecycle,
- Design, execute, and maintain periodic employee awareness programs on IT risk and
cybersecurity practices,
- Develop and maintain IT and cybersecurity risk registers, including risk taxonomy,
root-cause classification, and mapping of risks to business objectives and controls,
- Evaluate the design and operating effectiveness of IT controls and recommend
remediation, with follow-up tracking to closure,
- Support the drafting, review, and cascade of digital governance policies and
standards and monitor compliance,
- Coordinate internal/external audit and regulatory requests, prepare documentations,
and track corrective actions.
Key Qualifications
- Minimum 5 years in IT/digital risk management, IT governance,
IT audit, or cybersecurity risk; experience in complex, regulated, holding-company, BUMN, or financial-institution environments is highly preferred.
- Strong understanding of IT governance and risk management
frameworks (COBIT, ISO 27001, NIST); proven ability to perform end-to-end IT risk management, including risk assessment, control evaluation, and risk register maintenance.
- Hands-on experience conducting third-party / vendor security
assessments and translating findings into actionable, risk-based mitigation plans.
- Ability to independently challenge risk assessments and risk-
acceptance decisions; experience coordinating audits, preparing audit-ready documentation, and driving remediation.
- Certifications (preferred): CRISC, CISA, CISM, or ISO 27001
Lead Implementer/Auditor.
- Strong stakeholder engagement and documentation discipline
Working proficiency in both Bahasa Indonesia and English, written and spoken.