GRC Specialist
Indonesia - Jakarta, Green Office Park 1
Traveloka
Explore the world & live life your way. Best prices for hotels, flights, & attractions. Plan your own perfect trip.It's fun to work in a company where people truly BELIEVE in what they're doing!
Job Description
Establish and maintain information security policies, standard, guidelines, procedures and controls to ensure they meet with the company's risk appetite and compliance with applicable regulatory and legal requirements as well as industry standard
Enforce information security policies, standard, guidelines, procedures and controls implementation
Ensure and improve compliance such as PCI DSS, ISO/IEC 27001, and other information security related compliance, law and regulation
Manage and perform end to end risk assessments for various Information systems, services and processes
Act as a Subject Matter Expert (SME) for trending IT GRC and Information Security topics
Maintain expertise on security trends through training, research and development in order to mitigate potential security threats
Develop, promote and monitor our corporate wide Information Security awareness and Training Program
Collaborate and work closely with other stakeholders
Take ownership end to end of assigned projects
Identify and contribute to process improvements
Requirements
3-5 years of relevant professional experience is preferred
Have a good understanding about threat, vulnerability, impact and risk and their implementation on business processes
Demonstrable examples In-depth knowledge with as many as the following law, regulations, frameworks, and/or industry standards: COBIT, ISO/IEC 27000-series, PCI/DSS, NIST SP 800-53/30, GDPR, PDPA, UU ITE, UU PDP, etc
Demonstrated skills in risk assessment, both quantitatively and qualitatively. Familiarity with maturity models as aids for gap assessment and remediation planning
Experience of working on BCM projects or initiatives would be of added value
Ability to act independently and exercise good judgment as well as the ability to work cross functionally and create virtual teams
Ability to prioritize and multitask
Flexibility and adaptability in work approach
Strong written and verbal communication skills especially in English
Strong interpersonal skills
Strong problem-solving and negotiation skills
Calmness and clarity of thought under pressure and ability to maintain confidentiality
Ability to perform effective interaction with a broad range of people and roles. Accept responsibility and personal accountability
Ability to stay updated with current information security trends
Certified in CISSP, CGEIT, CISA, CISM, or other information security certification will be an added value
If you like wild growth and working with happy, enthusiastic over-achievers, you'll enjoy your career with us!
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: CISA CISM CISSP COBIT Compliance GDPR NIST NIST 800-53 PCI DSS Risk assessment
Perks/benefits: Career development
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.