Skill diminta
Auditing
Deskripsi
Deskripsi pekerjaan Risk amangement & Cyber Security Solutionlabs Grup Indonesia
Requirements
Minimum Bachelor’s Degree (S1) in Information Technology, Computer Science, Information Systems, Cyber Security, Risk Management, or related field.
- Minimum 3–5 years of experience in Cyber Security, IT Risk Management, Information Security, GRC, or related roles.
- Strong understanding of Cyber Security, Information Security, IT Risk Management, and Governance, Risk & Compliance (GRC).
- Experienced in conducting IT/Cyber Security risk assessment, risk identification, analysis, and mitigation.
- Understanding of security frameworks and standards such as ISO 27001, NIST, COBIT, or similar.
- Familiar with security policies, procedures, controls, and compliance requirements.
- Experience in security assessment, vulnerability management, security monitoring, and incident management is preferred.
- Able to identify security risks, vulnerabilities, control gaps, and potential business impacts.
- Strong analytical, problem-solving, communication, and stakeholder management skills.
- Able to prepare risk assessment, security assessment, compliance, and management reports.
- Relevant certifications such as CISA, CISM, CISSP, CRISC, ISO 27001, or CEH are a plus.
- Key Responsibilities
- Conduct IT and Cyber Security risk assessments to identify risks, vulnerabilities, and potential business impacts.
- Develop and maintain risk registers, risk treatment plans, and mitigation strategies.
- Monitor and evaluate the effectiveness of security controls and risk mitigation measures.
- Identify security gaps and vulnerabilities and coordinate corrective and preventive actions.
- Support implementation and maintenance of Information Security and Cyber Security policies, standards, and procedures.
- Ensure security practices align with relevant regulatory requirements and security frameworks.
- Conduct or support security assessments, audits, compliance reviews, and control testing.
- Coordinate with IT, Infrastructure, Application, and other business teams to address security and risk issues.
- Support cyber security incident management, including investigation, escalation, documentation, and follow-up actions.
- Monitor and report cyber security risks, compliance status, vulnerabilities, and remediation progress to management.
- Prepare risk assessment, security assessment, audit, compliance, and management reports.
- Provide recommendations to improve the organization's cyber security posture, risk management, and security controls.