job description
Join PCI as a Senior IT Risk and Compliance Officer in the vibrant heart of Bali, Indonesia. This is a unique opportunity to lead and enhance our IT governance, risk management, and compliance frameworks in a dynamic, fast-paced environment. You will play a pivotal role in ensuring our IT systems adhere to global standards, regulatory requirements, and best practices while mitigating risks and driving operational excellence.
Based in Badung, you’ll collaborate with cross-functional teams to implement robust security protocols, conduct risk assessments, and develop compliance strategies that align with industry benchmarks. Your expertise will be instrumental in safeguarding our digital assets and maintaining the trust of our stakeholders.
If you are a strategic thinker with a passion for IT risk management and a desire to work in a tropical paradise, we invite you to apply and take the next step in your career with PCI.
Responsibility
- Develop, implement, and maintain IT risk management frameworks in alignment with industry standards (e.g., ISO 27001, NIST, COBIT).
- Conduct comprehensive risk assessments and audits to identify vulnerabilities in IT systems and processes.
- Ensure compliance with local and international regulations, including data protection laws (e.g., GDPR, PDPA).
- Collaborate with IT and business teams to design and enforce security policies, procedures, and controls.
- Monitor and report on IT risk exposure, providing actionable insights to senior management.
- Lead incident response and investigation efforts for IT security breaches or compliance violations.
- Provide training and awareness programs to educate employees on IT risk and compliance best practices.
- Stay abreast of emerging threats, regulatory changes, and technological advancements in IT risk and compliance.
Qualifications
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field. Advanced degrees or certifications (e.g., CISA, CISSP, CISM, CRISC) are a plus.
- Minimum 5 years of experience in IT risk management, compliance, or cybersecurity, with at least 2 years in a senior or leadership role.
- Proven expertise in IT governance frameworks (e.g., ISO 27001, NIST, COBIT) and regulatory requirements (e.g., GDPR, PDPA).
- Strong analytical and problem-solving skills, with the ability to assess complex IT risks and propose mitigating solutions.
- Excellent communication and stakeholder management skills, with the ability to articulate technical concepts to non-technical audiences.
- Experience conducting IT audits, risk assessments, and compliance reviews.
- Familiarity with security tools (e.g., SIEM, vulnerability scanners, GRC platforms) and risk management methodologies.
- Ability to work independently and collaboratively in a fast-paced, multicultural environment.