GRC Specialist
Indonesia - Jakarta, Green Office Park 1
Traveloka
Explore the world & live life your way. Best prices for hotels, flights, & attractions. Plan your own perfect trip.It's fun to work in a company where people truly BELIEVE in what they're doing!
Job Description
- Establish and maintain information security policies, standard, guidelines, procedures and controls to ensure they meets with company's risk appetite and compliance with applicable regulatory and legal requirements as well as industry standard
- Enforce information security policies, standard, guidelines, procedures and controls implementation
- Ensure and improve compliance such as PCI DSS 4.0, SNI ISO/IEC 27001:2022, and other information security related compliance, law and regulation
- Manage and perform end to end risk assessment for various Information systems, services and processes
- Act as a Subject Matter Expert (SME) for trending GRC and Information Security topics
- Maintain expertise on security trends through training, research and development in order to mitigate potential security exposures
- Develop, promote and monitor our corporate wide Information Security awareness and Training Program
- Lead and coordinate cross projects with Traveloka internal stakeholder
- Represent team with external stakeholders to manage discussions on advisory, certifications, standards and compliance
- Take ownership on the assigned project
- Contribute in the process improvement
Requirements
- 3-5 years+ of relevant professional experience is preferred
- Have a good understanding about threat, vulnerability, impact and risk and their implementation on business process
- In-depth knowledge with as many as the following law, regulations, frameworks, and/or industry standards: COBIT, ISO/IEC 27000-series, PCI/DSS, NIST SP 800-53/30, GDPR, PDPA, PP71, UU ITE, etc
- Demonstrated skills in risk assessment, both quantitatively and qualitatively. Familiarity with maturity models as aids to gap assessment and remediation planning
- Ability to act independently and exercise good judgment as well as the ability to work cross functionally and create virtual teams
- Ability to prioritize and multitask
- Flexibility and adaptability in work approach
- Strong written and verbal communication skills especially in English
- Strong interpersonal skills
- Strong problem-solving and negotiation skills
- Calmness and clarity of thought under pressure and ability to maintain confidentiality
- Ability to perform effective interaction with a broad range of people and roles. Accept responsibility and personal accountability
- Ability to stay updated with current information security trends
- Certified in CISSP, CGEIT, CISA, CISM, or other information security certification will be an added value
If you like wild growth and working with happy, enthusiastic over-achievers, you'll enjoy your career with us!
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
1
0
0
Category:
Compliance Jobs
Tags: CISA CISM CISSP COBIT Compliance GDPR NIST NIST 800-53 PCI DSS Risk assessment
Perks/benefits: Career development
Region:
Asia/Pacific
Country:
Indonesia
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Information Systems Security Officer jobsSenior Cloud Security Engineer jobsInformation System Security Officer jobsSenior Cybersecurity Engineer jobsInformation Security Specialist jobsInformation Security Manager jobsSenior Network Security Engineer jobsSecurity Consultant jobsCyber Security Specialist jobsIT Security Engineer jobsSecurity Specialist jobsSenior Information Security Analyst jobsSenior Penetration Tester jobsIT Security Analyst jobsSenior Cyber Security Engineer jobsSystems Engineer jobsChief Information Security Officer jobsSystems Administrator jobsStaff Security Engineer jobsInformation System Security Officer (ISSO) jobsPrincipal Security Engineer jobsThreat Intelligence Analyst jobsSenior Product Security Engineer jobsCloud Security Architect jobsInformation Systems Security Engineer jobs
GDPR jobsEncryption jobsPowerShell jobsDevSecOps jobsEDR jobsSaaS jobsIDS jobsSplunk jobsSDLC jobsRMF jobsIPS jobsTop Secret jobsSQL jobsIntrusion detection jobsBash jobsThreat detection jobsActive Directory jobsCompTIA jobsDoDD 8570 jobsITIL jobsOWASP jobsDocker jobsBanking jobsCRISC jobsUNIX jobs
Finance jobsTCP/IP jobsClearance Required jobsGIAC jobsCISO jobsIndustrial jobsTerraform jobsHIPAA jobsIT infrastructure jobsSOC 2 jobsSANS jobsJavaScript jobsVPN jobsOSCP jobsCCSP jobsMITRE ATT&CK jobsSOAR jobsJira jobsDNS jobsSOX jobsData Analytics jobsPolygraph jobsNIST 800-53 jobsGCIH jobsSecurity strategy jobs