job description
Are you an Information Security & Privacy Officer seeking a role that values your expertise beyond just a ticket number? Join our close-knit, community-focused team in the heart of Bali, where collaboration and professional growth are at the core of our culture.
In this role, you will play a pivotal part in safeguarding our digital assets, ensuring compliance with global privacy standards, and fostering a security-first mindset across the organization. Unlike traditional corporate environments, we prioritize work-life balance, meaningful contributions, and a supportive workplace—no night shifts, no endless queues of repetitive tasks.
Bali offers a unique blend of professional opportunity and tropical lifestyle, making this an ideal position for those who thrive in dynamic, forward-thinking settings while enjoying the island’s vibrant culture and serene landscapes.
Responsibility
- Develop, implement, and maintain information security policies, standards, and procedures aligned with industry best practices (e.g., ISO 27001, GDPR, NIST).
- Conduct regular risk assessments and vulnerability audits to identify and mitigate potential security threats.
- Oversee data privacy compliance, ensuring adherence to local and international regulations (e.g., PDPA, GDPR).
- Lead security awareness training for employees to foster a culture of cybersecurity vigilance.
- Monitor and respond to security incidents, coordinating with IT teams to resolve breaches or vulnerabilities.
- Collaborate with cross-functional teams to integrate security controls into business processes and systems.
- Manage third-party vendor risk assessments to ensure partners meet security and privacy requirements.
- Stay updated on emerging cybersecurity threats and trends, recommending proactive measures to enhance protection.
Qualifications
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field; advanced degrees or certifications (e.g., CISSP, CISM, CIPP) are a plus.
- Minimum 3–5 years of experience in information security, risk management, or privacy compliance.
- In-depth knowledge of security frameworks (ISO 27001, NIST), privacy laws (GDPR, PDPA), and industry standards.
- Experience with security tools (e.g., SIEM, IDS/IPS, firewalls, encryption technologies) and vulnerability assessment methodologies.
- Strong analytical, problem-solving, and communication skills to articulate complex security concepts to non-technical stakeholders.
- Proven ability to design and deliver security training programs.
- Familiarity with cloud security (AWS, Azure, GCP) and secure SDLC practices is advantageous.
- High ethical standards and a commitment to confidentiality and integrity.