SecurityNow Hiring

GRC Analyst / Consultant

Guide Indonesian organizations to earn — and keep — their ISO 27001 certification.

Full-timeHybridDepok, West JavaMin. 2 years
Apply for This Role

About This Role

You will be at the front line of Cloudsphere's GRC practice, walking clients from gap analysis all the way through certification audit. The role combines deep standards knowledge with the ability to translate controls into practices client teams actually follow day to day.

What You Will Do

  • Run gap analyses and risk assessments against ISO/IEC 27001:2022, NIST CSF, and Indonesia's PDP Law.
  • Produce ISMS documentation: policies, procedures, the Statement of Applicability, and risk registers.
  • Facilitate workshops and security awareness training with client stakeholders.
  • Conduct internal audits and support clients through Stage 1 and Stage 2 certification audits.
  • Track finding closure and report compliance progress to client management.

What We Are Looking For

  • At least 2 years in GRC, compliance, IT audit, or risk management.
  • Deep working knowledge of ISO/IEC 27001:2022 and its 93 Annex A controls.
  • Ability to write clean, precise policy documents and audit reports.
  • Strong communication in both Indonesian and English, written and spoken.
  • Comfortable working directly with clients across very different maturity levels.

Nice to Have

  • ISO 27001 Lead Auditor / Lead Implementer, CISA, or CISM certification.
  • Experience implementing ISO 27701, ISO 22301, or PCI DSS compliance.
  • Practical grasp of applying Indonesia's PDP Law (No. 27 of 2022) in finance or tech.

Application Form

Apply for This Role

Fill in the details below and attach your CV. Your application goes straight to our recruitment team at [email protected].

Applying for

GRC Analyst / Consultant

Drag your file here, or click to browse

PDF only, 4 MB maximum.

Loading security verification…

Your CV is forwarded directly to our recruitment team by email and is never stored on this website's servers.