job description
Join MOL AccessPortal as a Senior IT Risk & Compliance Specialist in the vibrant heart of Bali! This is a unique opportunity to lead critical initiatives in IT risk management, regulatory compliance, and ISO/IEC 27001 implementation while enjoying the dynamic work-life balance of one of the world’s most sought-after destinations.
In this role, you will play a pivotal part in safeguarding our digital infrastructure, ensuring adherence to global standards, and driving continuous improvement in our security posture. Your expertise will directly contribute to mitigating risks, enhancing compliance frameworks, and fostering a culture of security awareness across the organization.
If you are a seasoned professional with a passion for cybersecurity, governance, and risk mitigation, and you thrive in a collaborative, forward-thinking environment, we want to hear from you. This position offers competitive compensation, career growth, and the chance to work in a tropical paradise with a global impact.
Responsibility
- Conduct comprehensive IT risk assessments to identify vulnerabilities and recommend mitigation strategies.
- Lead regulatory compliance gap analyses to ensure alignment with local and international standards (e.g., ISO/IEC 27001, GDPR, PDPA).
- Develop, implement, and maintain information security policies, procedures, and controls.
- Oversee the ISO/IEC 27001 certification process, including audits, documentation, and continuous improvement initiatives.
- Collaborate with cross-functional teams to integrate risk management best practices into business processes.
- Monitor and report on compliance status, highlighting risks and proposing corrective actions.
- Provide training and awareness programs to educate employees on security protocols and compliance requirements.
- Stay abreast of emerging cybersecurity threats, regulations, and industry trends to proactively address risks.
Qualifications
- Bachelor’s degree in Information Technology, Cybersecurity, Risk Management, or a related field. Advanced degrees or certifications (e.g., CISSP, CISM, ISO 27001 Lead Auditor/Implementer, CRISC) are a plus.
- Minimum 5+ years of experience in IT risk management, compliance, or information security roles.
- Proven track record in conducting risk assessments, compliance audits, and implementing security frameworks.
- In-depth knowledge of ISO/IEC 27001, NIST, COBIT, or other relevant standards.
- Strong understanding of data privacy laws (e.g., GDPR, PDPA) and industry-specific regulations.
- Excellent analytical, problem-solving, and communication skills to articulate complex concepts to stakeholders.
- Experience with security tools (e.g., SIEM, GRC platforms) and risk management methodologies.
- Ability to work independently and collaboratively in a fast-paced, international environment.