job description
Are you a seasoned Governance, Risk, and Compliance (GRC) Specialist looking to make a significant impact in a dynamic organization? Total Information Management Corp. is seeking a proactive and detail-oriented professional to lead our GRC initiatives, ensuring regulatory compliance and mitigating risks across our operations.
In this role, you will play a pivotal part in developing, implementing, and monitoring GRC frameworks that align with industry standards and regulatory requirements. You will collaborate with cross-functional teams to foster a culture of compliance and risk awareness, driving continuous improvement in our governance practices.
Based in the vibrant and culturally rich location of Canggu, Bali, this position offers a unique opportunity to work in a serene yet innovative environment, blending professional growth with an exceptional quality of life.
Responsibility
- Develop, implement, and maintain comprehensive GRC frameworks to ensure compliance with local and international regulations.
- Conduct regular risk assessments and audits to identify potential vulnerabilities and recommend mitigation strategies.
- Lead the design and execution of compliance training programs for employees at all levels.
- Monitor and report on compliance metrics, providing insights and recommendations to senior management.
- Collaborate with legal, IT, and operational teams to ensure alignment with GRC policies and procedures.
- Stay abreast of emerging regulatory changes and industry best practices to proactively update GRC strategies.
- Manage relationships with external auditors, regulators, and other stakeholders to ensure transparency and accountability.
- Drive continuous improvement initiatives to enhance the effectiveness and efficiency of GRC processes.
Qualifications
- Bachelor’s degree in Business Administration, Law, Information Technology, or a related field. Advanced degrees or certifications (e.g., CISA, CRISC, CGEIT) are a plus.
- Minimum of 5 years of experience in governance, risk management, or compliance roles, preferably within the ICT sector.
- In-depth knowledge of regulatory frameworks such as ISO 27001, GDPR, and local data protection laws.
- Strong analytical and problem-solving skills, with the ability to interpret complex regulatory requirements.
- Excellent communication and interpersonal skills, with the ability to influence and engage stakeholders at all levels.
- Proven experience in conducting risk assessments, audits, and compliance reviews.
- Proficiency in GRC tools and technologies, with the ability to leverage data analytics for risk management.
- High ethical standards and a commitment to fostering a culture of integrity and compliance.