Senior IT GRC Analyst - Consumer Lending
GoTo Group · Indonesia
About The Role
As a Senior IT GRC Analyst at GoTo Financial, you’ll play a key role in ensuring our systems and processes meet regulatory, security, and risk requirements. Your work will help reduce compliance risks and support secure product development across our lending entities. You’ll collaborate closely with Business, Product, Operations, Compliance, Legal, DPPO, Engineering, Audit, and other supporting teams. If you’re excited about solving complex compliance challenges in a fast-paced fintech environment, this role is for you!
What You Will Do: Coordinate the execution of IT Governance, Risk, and Compliance (GRC) initiatives across GoTo Financial entities. Collaborate with cross-functional teams (e.g., Business, Product, Ops, Compliance, Legal, DPPO, Engineering, Audit) to ensure proper control implementation and alignment. Drive continuous improvement of IT risk management processes, including risk assessments, control testing, and issue tracking. Support audit preparation and act as a liaison for both internal and external audits (ISO, OJK, EY, etc.). Ensure timely closure of audit findings and monitor ongoing compliance with internal policies and regulatory requirements. Monitor the effectiveness of security controls on critical systems and vendors, and escalate risks to relevant stakeholders. Facilitate and coordinate technical evidence gathering for regular regulatory submissions, ensuring IT-related requests are fulfilled accurately and on schedule.
What You Will Need: Minimum 4 to 6 years of experience in IT Governance, Risk Management, or Compliance, preferably in the financial services or fintech sector.
Strong understanding of regulatory frameworks such as ISO 27001, ISO 27701, OJK regulations, and data privacy standards.
Experience handling internal and external audits, including evidence preparation and follow-up.
Ability to assess and improve IT controls, risk management processes, and compliance documentation.
Strong collaboration and communication skills to work cross-functionally with Business, Product, Ops, Compliance, Legal, DPPO, Engineering, Audit, and other supporting teams.
Proactive, detail-oriented professional with a proven ability to manage multiple priorities and remain highly responsive in a fast-paced, dynamic environment.
Strong experience managing regular regulatory deliverables and timelines, with the ability to liaise with cross-functional teams to gather compliance evidence efficiently.