Amartha Logo

Amartha

Senior IT GRC & Data Privacy Analyst

Posted 4 Days Ago
Be an Early Applicant
South Jakarta City, Jakarta
Senior level
South Jakarta City, Jakarta
Senior level
As a Senior IT GRC & Data Privacy Analyst, you will lead IT governance, risk, and compliance initiatives and manage data privacy programs at Amartha, ensuring compliance with regulations and conducting risk assessments. Your role will involve developing frameworks, managing vendor compliance, and overseeing Identity and Access Management policies.
The summary above was generated by AI

Description

About the Role 

The Senior IT GRC and Data Privacy Analyst plays a crucial role in Amartha. You will be the warrior who will spearhead various IT GRC and Data Privacy programs to protect Amartha from internal and external threats, including monitoring and managing compliance with ISO 27001, POJK, PSrE, PDP, and other applicable regulations.

About the team

The Information Security team in Amartha is a group of dynamic, highly-analytical individuals who are highly mindful in driving security and privacy by design within the various aspects of product lifecycle and engineering processes. We are the team who are highly passionate to be the security enabler of Amartha’s systems

Job Desc/What will you do

GRC Framework Development and Maintenance:

  • Develop, implement, and maintain a comprehensive GRC framework that aligns with industry best practices and regulatory requirements.
  • Conduct regular risk assessments to identify potential threats and vulnerabilities.
  • Develop and implement risk mitigation strategies and action plans.
  • Monitor and report on compliance with internal policies and external regulations.

Data Privacy Compliance:

  • Ensure compliance with applicable data privacy regulations and data protection laws.
  • Conduct data privacy impact assessments (DPIAs) for new projects or initiatives.
  • Develop and implement data privacy policies and procedures.
  • Manage data breaches and incidents, including notification processes and remediation activities.

Vendor Management:

  • Assess the security and privacy practices of third-party vendors and suppliers.
  • Negotiate and manage vendor contracts to ensure compliance with security and privacy requirements.

Regulatory Compliance:

  • Stay up-to-date with evolving regulatory requirements and industry best practices.
  • Provide guidance and support to the organization in meeting compliance obligations.

Identity and Access Management (IAM):

  • Develop and maintain IAM policies, standards, and procedures.
  • Implement and manage IAM systems and tools (e.g., identity provisioning, access control, single sign-on).
  • Ensure the effective administration of user accounts and privileges.
  • Conduct regular IAM audits and reviews to identify and address security gaps.
  • Manage access certifications and segregation of duties controls.
Requirements

Requirements

  • 5+ years of related job experience
  • Strong analytical and interpersonal skills
  • Excellent communication both in written and spoken (English)
  • Ability to express information clearly at different organizational levels
  • Strong understanding of industry standards such as ISO 27001, NIST Cybersecurity Framework, GDPR, UU PDP
  • Experience in the financial services industry (esp. Microfinance, Payments, etc)
  • Having relevant certification are preferable (e.g. CRISC, CIPP, etc)
  • Experience with IAM technologies and frameworks (e.
  • g., Active Directory, LDAP, OAuth, SAML)

Top Skills

Gdpr
Iso 27001
Nist

Similar Jobs

Be an Early Applicant
4 Days Ago
South Jakarta City, Jakarta, IDN
9,850 Employees
Junior
9,850 Employees
Junior
Consulting • Cybersecurity
The Machine Learning Engineer will interpret customer needs and extract value from data using GCP tools, participate in pre-sales activities, advocate for Google Cloud products, suggest solutions, develop new products or integrations, and engage in group company relations as required.
Be an Early Applicant
5 Days Ago
3 Locations
525 Employees
Senior level
525 Employees
Senior level
Fintech • Payments • Financial Services
As a Senior Data Scientist, you will analyze complex datasets and develop machine learning models for credit scoring, fraud detection, and risk assessment. You will also conduct data analysis to derive insights, maintain dashboards for model performance metrics, and lead projects while mentoring junior team members.
Be an Early Applicant
5 Days Ago
South Jakarta City, Jakarta, IDN
1,938 Employees
Senior level
1,938 Employees
Senior level
Fintech • Software • Financial Services
The Funding Portfolio Risk Senior Analyst conducts comprehensive credit analysis and monitors credit portfolio performance while identifying risks and trends. This role collaborates with various teams to maintain accurate databases, execute stress testing, and ensure compliance with credit policies. Additionally, the analyst prepares detailed reports and presentations for management and stays updated on relevant market trends and regulations.

What you need to know about the Bengaluru Tech Scene

Dubbed the "Silicon Valley of India," Bengaluru has emerged as the nation's leading hub for information technology and a go-to destination for startups. Home to tech giants like ISRO, Infosys, Wipro and HAL, the city attracts and cultivates a rich pool of tech talent, supported by numerous educational and research institutions including the Indian Institute of Science, Bangalore Institute of Technology, and the International Institute of Information Technology.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account