IT Security - Governance, Risk & Compliance (GRC)

Stockbit
Stockbit

IT, Compliance / Regulatory

Jakarta, Indonesia

Posted on Aug 22, 2026
Stockbit / Bibit is looking for an IT Security – Governance, Risk & Compliance (GRC) professional to strengthen our security governance, risk management, and compliance practices.

You'll have the opportunity to build and strengthen security governance within a fast-growing fintech environment, working closely with Technology, Security, Risk, Compliance, and business teams.

What You'll Do

  • Manage cyber risk identification, assessment, remediation tracking, and risk acceptance processes.
  • Ensure security compliance with regulatory requirements, internal/external audits, and applicable security standards.
  • Develop and maintain security policies, standards, controls, and control ownership frameworks.
  • Coordinate security audits, including evidence collection, finding management, and remediation tracking.
  • Establish and manage Third-Party / Vendor Security Risk Assessment processes.
  • Support data protection governance, including data classification, handling, and protection requirements.
  • Establish governance around access reviews, privileged access, and access control requirements.
  • Drive security awareness initiatives, including security training and phishing simulations.
  • Support business continuity, disaster recovery, and cyber resilience governance.
  • Manage security exceptions, compensating controls, and formal risk acceptance.
  • Support security incident handling, including incident coordination, documentation, post-incident review, and tracking of remediation actions.
  • Manage security dashboards and management reporting covering security posture, risk, compliance, initiatives, and security maturity

What We're Looking For

  • 3–5 years of experience in IT Security, GRC, Cybersecurity, IT Audit, Risk Management, or related areas.
  • Strong understanding of security governance, risk management, and compliance frameworks.
  • Experience working with security audits, regulatory requirements, and control assessments.
  • Familiarity with frameworks and standards such as ISO 27001, NIST CSF, COBIT, or similar.
  • Experience in risk assessment, policy development, control implementation, and audit remediation.
  • Experience or good understanding of security incident handling and response processes.
  • Good understanding of information security, access management, data protection, and third-party risk.
  • Strong analytical, documentation, and stakeholder management skills.
  • Comfortable working with both technical and non-technical stakeholders.
  • Experience in fintech, financial services, or other regulated industries is a plus.