Senior IT GRC & Data Privacy Analyst

Amartha Other US Location

Company

Amartha

Location

Other US Location

Type

Full Time

Job Description

Description

About the Role 

The Senior IT GRC and Data Privacy Analyst plays a crucial role in Amartha. You will be the warrior who will spearhead various IT GRC and Data Privacy programs to protect Amartha from internal and external threats, including monitoring and managing compliance with ISO 27001, POJK, PSrE, PDP, and other applicable regulations.

About the team

The Information Security team in Amartha is a group of dynamic, highly-analytical individuals who are highly mindful in driving security and privacy by design within the various aspects of product lifecycle and engineering processes. We are the team who are highly passionate to be the security enabler of Amartha’s systems

Job Desc/What will you do

GRC Framework Development and Maintenance:

  • Develop, implement, and maintain a comprehensive GRC framework that aligns with industry best practices and regulatory requirements.
  • Conduct regular risk assessments to identify potential threats and vulnerabilities.
  • Develop and implement risk mitigation strategies and action plans.
  • Monitor and report on compliance with internal policies and external regulations.

Data Privacy Compliance:

  • Ensure compliance with applicable data privacy regulations and data protection laws.
  • Conduct data privacy impact assessments (DPIAs) for new projects or initiatives.
  • Develop and implement data privacy policies and procedures.
  • Manage data breaches and incidents, including notification processes and remediation activities.

Vendor Management:

  • Assess the security and privacy practices of third-party vendors and suppliers.
  • Negotiate and manage vendor contracts to ensure compliance with security and privacy requirements.

Regulatory Compliance:

  • Stay up-to-date with evolving regulatory requirements and industry best practices.
  • Provide guidance and support to the organization in meeting compliance obligations.

Identity and Access Management (IAM):

  • Develop and maintain IAM policies, standards, and procedures.
  • Implement and manage IAM systems and tools (e.g., identity provisioning, access control, single sign-on).
  • Ensure the effective administration of user accounts and privileges.
  • Conduct regular IAM audits and reviews to identify and address security gaps.
  • Manage access certifications and segregation of duties controls.
Requirements

Requirements

  • 5+ years of related job experience
  • Strong analytical and interpersonal skills
  • Excellent communication both in written and spoken (English)
  • Ability to express information clearly at different organizational levels
  • Strong understanding of industry standards such as ISO 27001, NIST Cybersecurity Framework, GDPR, UU PDP
  • Experience in the financial services industry (esp. Microfinance, Payments, etc)
  • Having relevant certification are preferable (e.g. CRISC, CIPP, etc)
  • Experience with IAM technologies and frameworks (e.
  • g., Active Directory, LDAP, OAuth, SAML)

Apply Now

Date Posted

09/25/2024

Views

0

Back to Job Listings ❤️Add To Job List Company Info View Company Reviews
Positive
Subjectivity Score: 0.8

Similar Jobs

Senior Engineering Manager, Micros Foundations - Atlassian

Views in the last 30 days - 0

Atlassian is seeking a Senior Engineering Manager to lead a team of Backend Software Engineers The role involves guiding technical decisions prioritiz...

View Details

Senior Frontend Engineer - Simply Business

Views in the last 30 days - 0

Simply Business is seeking a Senior Frontend Engineer to join their Front End Tooling team The role involves developing products using best practices ...

View Details

Development Underwriter - Simply Business

Views in the last 30 days - 0

Simply Business is seeking a Development Underwriter with an Underwriting background to support their new MGA brand Nupro which aims to disrupt the sm...

View Details

E2E Solution Architect - Ahold Delhaize USA

Views in the last 30 days - 0

Ahold Delhaize USA is seeking a Solution Architect with extensive experience in IT architecture BigData Analytics and various software designs and dev...

View Details

E2E Solution Architect - Ahold Delhaize USA

Views in the last 30 days - 0

Ahold Delhaize USA is seeking a Solution Architect with extensive experience in IT architecture BigData Analytics and various software designs and dev...

View Details

E2E Solution Architect - Ahold Delhaize USA

Views in the last 30 days - 0

Ahold Delhaize USA a division of a global food retailer is seeking a Solution Architect for its US operations The role involves translating business r...

View Details