job description
Join Kwe Apll Technology Services as a Governance, Risk & Compliance (GRC) Analyst in the vibrant heart of Bali, Indonesia. This is a unique opportunity to drive the enhancement of our GRC framework, collaborating with cross-functional stakeholders to strengthen risk management, internal controls, governance, compliance, and reporting mechanisms.
In this dynamic role, you will play a pivotal part in ensuring our organization adheres to regulatory requirements while fostering a culture of risk awareness and operational excellence. Based in one of Bali’s most sought-after locations—Canggu, Ubud, Denpasar, Jimbaran, Nusa Dua, or Kuta—you’ll enjoy a perfect blend of professional growth and island living.
We are seeking a detail-oriented professional with a passion for governance and risk mitigation to help us build robust compliance strategies that align with industry best practices and global standards.
Responsibility
- Develop, implement, and maintain the company’s Governance, Risk, and Compliance (GRC) framework in alignment with industry standards (e.g., ISO 27001, COBIT, NIST).
- Conduct risk assessments and identify control gaps, proposing actionable mitigation strategies.
- Collaborate with IT, Legal, Finance, and Operations teams to ensure compliance with regulatory requirements (e.g., GDPR, PDPA, SOX).
- Monitor and report on compliance status, including audit findings, remediation progress, and key risk indicators (KRIs).
- Design and deliver GRC training programs to enhance risk awareness across the organization.
- Automate and streamline compliance reporting using GRC tools (e.g., RSA Archer, MetricStream, ServiceNow).
- Support internal and external audits, ensuring timely and accurate documentation.
- Stay updated on emerging regulations, threats, and industry trends to proactively adjust GRC strategies.
Qualifications
- Bachelor’s degree in Information Technology, Business Administration, Risk Management, or a related field.
- Minimum 3-5 years of experience in GRC, risk management, or compliance roles, preferably in the IT or financial services sector.
- Strong knowledge of GRC frameworks (e.g., ISO 27001, COBIT, ITIL, NIST) and regulatory requirements (e.g., GDPR, PDPA).
- Experience with GRC software tools (e.g., RSA Archer, MetricStream, ServiceNow) is a plus.
- Excellent analytical, problem-solving, and communication skills.
- Certifications such as CISA, CISSP, CISM, or CRISC are highly advantageous.
- Ability to work independently and collaboratively in a fast-paced, multicultural environment.
- Fluency in English; proficiency in Indonesian (Bahasa) is a bonus.