登录获取应用

职位 › 职位详情 昨天

IT GRC Analyst

Xendit · Jakarta, Indonesia

现场办公英语

职位介绍

摘自雇主发布的职位信息 · Xendit · 发布于2026年10月4日

Xendit provides payment infrastructure across Southeast Asia and is expanding to Greater China and LATAM. We process payments, power marketplaces, disburse payroll and loans, provide KYC solutions, prevent fraud, and help businesses grow exponentially. We serve our customers by providing a suite of world-class APIs, eCommerce platform integrations, and easy to use applications for individual entrepreneurs, SMEs, and enterprises alike.

Our main focus is building the most advanced payment rails for Southeast Asia, with a clear goal in mind — to make payments across and within SEA simple, secure and easy for everyone. We serve thousands of businesses ranging from SMEs to multinational enterprises, and process millions of transactions monthly. We’ve been growing rapidly since our inception in 2015, onboarding hundreds of new customers every month, and backed by global top-10 VCs. We’re proud to be featured on among the fastest growing companies by Y-Combinator.

About the Job

At Xendit, we are looking for a mid-level/senior-level IT GRC Analyst to sit at the intersection of technology, compliance, and risk — not just for Indonesia, but across all of Xendit's operating markets. As an individual contributor, you will be responsible for ensuring our IT systems, processes, and controls meet the regulatory obligations and certification standards of every jurisdiction we operate in. You will be our regional GRC go-to person, coordinating directly with regulatory bodies across the regions (Bank Indonesia / OJK, BSP, BOT, etc). Beyond regulatory compliance, you will own and drive the full lifecycle of our IT certifications such as PCI-DSS and ISO 27001. You will work closely with engineering, security, product, and legal teams to embed compliance into how we build and operate. This is a role for someone who is detail-oriented, thrives in multi-market complexity, and can translate a wide range of regulatory requirements into practical, actionable controls in a fast-moving fintech environment.

Minimum Qualifications

  • 3–5 years of hands-on experience in IT GRC, IT Risk Management, or IT Compliance roles
  • Solid working knowledge of PCI-DSS, ISO 27001 frameworks, including implementation, certification, and audit readiness
  • Familiarity with Bank Indonesia (BI) and OJK IT governance regulations applicable to payment service providers in Indonesia
  • Exposure to or willingness to take regulatory requirements in at least one other Southeast Asian or international market (e.g., BSP, BOT, MAS, BNM, or equivalent)
  • Proven experience conducting IT risk assessments, control testing, and gap analyses
  • Demonstrated ability

每个职位,都有你的匹配分

BabZituna按六个真实维度,将每个职位与你的资料对照评分,并告诉你为什么得出这个分数,公平性经过审计(阅读公开的偏见审计)。

获取应用 → ✓ 求职者100%免费
一个职位如何评分 示例
技能96经验90地点84工作方式74工作类型61薪资无数据

示例数据,并非真实候选人。每个维度根据你本人的资料按100分制评分;无法衡量的维度会如实标明,而不是猜测。