job description
Are you a meticulous security and compliance professional looking to make an impact in a dynamic IT environment? CBTW, a leading player in the Information & Communication Technology sector, is seeking a Security and Compliance Referent (Delivery) to join our growing team in Bali, Indonesia (Canggu, Ubud, Denpasar, Jimbaran, Nusa Dua, Kuta, or Badung).
In this critical role, you will be the guardian of our delivery processes, ensuring robust security measures, regulatory compliance, and risk mitigation across all projects. You’ll collaborate with cross-functional teams to embed security best practices, streamline governance frameworks, and drive continuous improvement in our service lines. If you thrive in a fast-paced environment where your expertise directly shapes operational excellence, this is your opportunity to shine.
At CBTW, we value innovation, integrity, and collaboration. As our Security and Compliance Referent, you’ll enjoy a supportive work culture, professional growth opportunities, and the chance to work on high-impact projects that redefine industry standards. Join us and be part of a team that prioritizes security, compliance, and client trust.
Why CBTW?
- Competitive salary package (IDR 18M–25M/month) with performance bonuses
- Flexible hybrid work arrangements in Bali’s most vibrant locations
- Career advancement opportunities in a growing IT firm
- Comprehensive health and wellness benefits
- Collaborative and inclusive work environment
Responsibility
- Develop, implement, and maintain security and compliance frameworks for delivery processes, ensuring alignment with industry standards (e.g., ISO 27001, NIST, GDPR).
- Conduct regular risk assessments and audits to identify vulnerabilities, recommend mitigation strategies, and track remediation efforts.
- Collaborate with project teams to integrate security and compliance requirements into project lifecycles, from planning to execution.
- Monitor regulatory changes and update internal policies to ensure ongoing compliance with local and international laws.
- Provide guidance and training to employees on security best practices, data protection, and compliance obligations.
- Support incident response efforts, including investigation, documentation, and reporting of security breaches or compliance violations.
- Liaise with external auditors, regulators, and clients to demonstrate compliance and address inquiries.
- Drive continuous improvement initiatives to enhance security posture and operational efficiency.
Qualifications
- Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, or a related field. Certifications such as CISSP, CISM, ISO 27001 Lead Auditor, or equivalent are a plus.
- Minimum 3–5 years of experience in security, compliance, or governance roles, preferably in the IT or delivery services sector.
- Strong understanding of security frameworks (ISO 27001, NIST, COBIT) and regulatory requirements (GDPR, PDPA, etc.).
- Proven experience conducting risk assessments, audits, and compliance reviews.
- Excellent analytical, problem-solving, and communication skills, with the ability to translate complex security concepts for non-technical stakeholders.
- Familiarity with project management methodologies (Agile, Waterfall) and their application in secure delivery environments.
- Detail-oriented with a proactive approach to identifying and addressing security gaps.
- Ability to work independently and collaboratively in a fast-paced, multicultural environment.