IT GRC Analyst
Job description
About the role
You will serve as the central GRC expert ensuring that our IT risk, security, and compliance posture aligns with the diverse regulatory landscapes of every market Xendit operates within. This position requires you to own the interpretation and implementation of controls that satisfy regulators such as Bank Indonesia and OJK without exception. You will be the primary liaison between technical teams and external auditors, driving evidence collection and certification readiness. The role demands a high level of ownership over the full lifecycle of IT certifications including PCI-DSS and ISO 27001. You will translate complex regulatory language into clear technical requirements that engineering and product teams can execute. Success in this role means maintaining a living view of our compliance posture across all operating regions. You will proactively identify gaps before they become audit findings or regulatory concerns.
Key facts
What you'll do
Coordinate closely with regulatory bodies across Southeast Asia to ensure IT governance rules are interpreted correctly and implemented consistently.
Own the end-to-end management of IT certification programs, driving scoping, evidence gathering, and remediation activities for standards such as PCI-DSS and ISO 27001.
Perform detailed IT risk assessments and control testing to validate that our systems and processes meet both internal policies and external regulatory expectations.
Develop, review, and maintain IT policies, standards, and procedures so they reflect current regulations and are practical for day-to-day execution.
Liaise directly with engineering, security, product, and legal teams to embed compliance requirements into product design and operational workflows.
Monitor changes in regulatory requirements across jurisdictions and map them to existing controls to ensure ongoing adherence.
Conduct gap analyses to compare our current implementation against frameworks like PCI-DSS, ISO 27001, and specific regional mandates from BSP, BOT, and other authorities.
Serve as the regional GRC go-to person, providing clear guidance to stakeholders in multiple countries and time zones during audits or examinations.
Support the preparation of audit evidence, response documentation, and remediation tracking to ensure timely closure of findings.
Drive continuous improvement of the GRC and compliance programs by identifying inefficiencies and proposing enhancements to control design and monitoring.
Collaborate with third-party auditors and internal stakeholders to coordinate audit schedules, resolve findings, and verify corrective actions.
Maintain a structured inventory of controls and exceptions to support decision-making and risk discussions with leadership.
Contribute to the development of risk-based testing strategies that align technology controls with business objectives and regulatory requirements.
Promote a culture of compliance by partnering with technical teams to integrate controls early in the development lifecycle.
Requirements
You must bring 3-5 years of hands-on experience in IT GRC, IT Risk Management, or IT Compliance roles in complex environments.
You must possess a solid working knowledge of PCI-DSS and ISO 27001 frameworks, including implementation details, certification processes, and audit readiness practices.
You must demonstrate familiarity with Bank Indonesia (BI) and OJK IT governance regulations that apply to payment service providers in Indonesia.
You must show exposure to or a willingness to learn regulatory requirements in at least one additional Southeast Asian or international market such as BSP, BOT, MAS, or BNM.
You must have proven experience conducting IT risk assessments, control testing, and gap analyses across technology and operational processes.
You must have a demonstrated ability to develop, review, and maintain IT policies, standards, and procedures that are both accurate and actionable.
You must possess strong analytical skills to interpret diverse regulatory requirements and convert them into practical technical and operational controls.
You must be an effective communicator who can engage technical and non-technical stakeholders across multiple countries and time zones with clarity and professionalism.
Nice to have
You may have prior experience navigating Bank Indonesia PJP Category 1 or Category 2 licensing requirements, including ongoing IT compliance obligations and regulatory examination readiness.
You may have hands-on experience managing end-to-end certification processes for ISO 27001, PCI-DSS, or SOC 2, including scoping, readiness assessment, evidence preparation, and auditor coordination.
You may have direct experience coordinating IT audits or regulatory examinations with regional bodies such as BSP, BOT, MAS, or BNM.
You may hold relevant professional certifications such as CISA, CRISC, ISO 27001 Lead Implementer, or ISO 27001 Lead Auditor.
You may have prior experience in fintech, digital payments, or financial services within a multi-market Southeast Asian or global context.
You may have exposure to cloud environments and an understanding of cloud security control frameworks relevant to payment infrastructure.
You may have a background in working cross-functionally with engineering and product teams to embed compliance-by-design principles into delivery practices.
Practical notes
The engagement details and specific compensation information are not provided in the source material.
No official apply page is referenced in the source, so no application instructions are included here.
No explicit information regarding working hours, travel expectations, or visa requirements is provided in the source text.