LOWONGAN
Xendit provides payment infrastructure across Southeast Asia and is expanding into Greater China and LATAM. Its services include payment processing, marketplace infrastructure, payroll and loan disbursements, KYC solutions, and fraud prevention. It offers APIs, eCommerce platform integrations, and applications for individual entrepreneurs, SMEs, and enterprises. Founded in 2015, Xendit serves thousands of businesses, from SMEs to multinational enterprises, processes millions of transactions each month, and adds hundreds of customers monthly. It is backed by global top-10 VCs and has been featured by Y Combinator among the fastest-growing companies. Its goal is to make payments within and across Southeast Asia simple, secure, and easy for everyone.
Xendit is seeking a mid-level or senior-level IT GRC Analyst to work as an individual contributor across all its operating markets, not only Indonesia. The role ensures IT systems, processes, and controls meet each jurisdiction’s regulatory obligations and certification standards. It involves direct coordination with regional regulators, including Bank Indonesia, OJK, BSP, and BOT; ownership of certifications such as PCI-DSS and ISO 27001; and collaboration with engineering, security, product, and legal teams to incorporate compliance into systems and operations. The role calls for someone detail-oriented who can handle multi-market complexity and turn regulatory requirements into practical controls in a fast-moving fintech environment.
Minimum qualifications include 3–5 years of hands-on experience in IT GRC, IT risk management, or IT compliance; working knowledge of PCI-DSS and ISO 27001 implementation, certification, and audit readiness; and familiarity with BI and OJK IT governance regulations for Indonesian payment service providers. Candidates should have exposure to, or be willing to take on, regulatory requirements in at least one other Southeast Asian or international market, such as those of BSP, BOT, MAS, BNM, or an equivalent body. They must have experience with IT risk assessments, control testing, gap analyses, and maintaining IT policies, standards, and procedures, along with strong analytical and communication skills for working with technical and non-technical stakeholders across countries and time zones.
Preferred qualifications include experience with Bank Indonesia’s PJP Category 1 or Category 2 licensing requirements, ongoing IT compliance, and regulatory examination readiness; end-to-end management of ISO 27001, PCI-DSS, or SOC 2 certification, from scoping and evidence preparation to auditor coordination and post-certification surveillance; and direct coordination of IT audits or examinations with regional bodies such as BSP, BOT, MAS, or BNM. Relevant certifications include CISA, CRISC, ISO 27001 Lead Implementer, or ISO 27001 Lead Auditor. Experience in fintech, digital payments, or financial services across multiple Southeast Asian or global markets, exposure to cloud security control frameworks, and cross-functional work with engineering and product teams on compliance-by-design are also preferred.
Responsibilities include managing certification and regulatory audit programs; serving as the regional GRC contact for IT audits and examinations; and overseeing certification from scoping and gap analysis through issuance, surveillance, renewal, and continuous compliance. The analyst will conduct periodic IT risk assessments across markets, maintain a consolidated risk register, track remediation to closure, test the design and operating effectiveness of controls, and address compliance gaps with relevant teams. The role also develops and enforces IT policies, coordinates regulatory and third-party audits, monitors changing requirements across operating markets, prepares compliance dashboards and management reports, incorporates risk and compliance into project delivery and system design, and improves GRC processes, tools, and automation as operations expand.
IT GRC Analyst
Xendit • Jakarta • Gaji tidak dicantumkan
Deskripsi Pekerjaan
Ringkasan
- Perusahaan
- Xendit
- Lokasi
- Jakarta
- Tipe kerja
- —
- Gaji
- Gaji tidak dicantumkan
- Tanggal tayang
- 18 Jun 2026
- Terlihat sejak
- 29 Sep 2026
Sumber & keterlacakan data
Greenhouse ATS (first-party) — https://job-boards.greenhouse.io/xendit/jobs/7731687003
Siap melamar? Langsung di sumber asli.Buka Halaman Lamaran
Lowongan Terkait Lainnya
LOWONGAN2bln
Head of Security & AI Governance
Flip • Los Angeles
Gaji tidak dicantumkanLihat Detail →
FULL_TIME3blnDevSecOps Engineer/Lead
Ajaib • Jakarta
Gaji tidak dicantumkanLihat Detail →
FULL_TIME3blnOffensive Security Engineer/Lead
Ajaib • Jakarta
Gaji tidak dicantumkanLihat Detail →
FULL_TIME4blnIT Support & Project Manager
Ajaib • Jakarta
Gaji tidak dicantumkanLihat Detail →