IT Security Governance and Compliance

GTech GroupTangerang, Bantenkalibrravaldatud 08.09.2026
Nõutav:SecuritySenior

The IT Risk and Compliance Senior Officer is responsible for supporting, executing, and continuously improving the organization’s IT governance, risk, and compliance (GRC) activities. This role focuses on hands-on implementation, operational oversight, and audit support for ISO/IEC 27001 (internal and external audits), as well as compliance with GDPR / PDP Regulation and NIST requirements. The role ensures that governance and security controls are effectively embedded across project delivery, change management, design reviews, audit processes, and policy lifecycle within a technology-focused organization.

Strong knowledge of IT Governance, IT Controls, and Information Security Controls

Hands-on understanding of ISO/IEC 27001 (Clauses & Annex A), GDPR/PDP Regulation, NIST CSF / NIST SP 800

Experience in control design, control implementation, and control effectiveness assessment

Skilled in risk assessment, risk register management, and risk treatment tracking

High attention to detail with strong documentation, evidence management, and audit support skills

Experience in developing and maintaining policies, standards, procedures, and guidelines

Ability to translate regulatory and security standards into operational and technical controls

Familiar with secure-by-design and privacy-by-design principles

Experience supporting project governance, SDLC controls, and compliance checkpoints

Exposure to Change Control Board (CCB) and Design Review Board (DRB) processes

Strong stakeholder communication and coordination across IT, Security, Engineering, PMO, and Legal

Ability to prepare compliance reports, risk summaries, and management documentation

Self-motivated, able to work independently with minimal supervision