SlipstreamJobsFresh Startup & VC-Backed Jobs

IT GRC Manager - Digital Identity

GoTo Group - Jakarta, Indonesia - In-office - posted 2026-09-28

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

GoTo Group, Southeast Asia's largest digital ecosystem, is seeking an IT GRC Manager to lead governance, risk, and compliance initiatives for its identity services products. This is a hands-on management role bridging policy and practice across the organization. You will spearhead the development and implementation of a robust GRC framework tailored to identity services, monitor execution of internal controls, and drive the organization toward ISO 27001 and ISO 27701 certifications while ensuring continuous readiness for regulatory audits. Within the first six months, you will fortify the company's risk posture and influence critical IT policy reforms to enhance organizational resilience against evolving cyber threats. Key responsibilities include: - Coordinating with the compliance team to ensure all initiatives comply with internal and external standards and regulations - Conducting routine evaluation of policies and procedures to maintain best-practice risk mitigation and assessment functions aligned with company strategy - Acting as a Subject Matter Expert to stakeholders, providing consultation on IT GRC requirements for lending and identity products - Ensuring effective governance, risk management, and compliance across the organization - Developing and maintaining compliance, governance, and risk-related IT and business process flows - Coordinating with IT work units on data requests, internal audit findings, external audits, and regulatory follow-ups - Developing processes to safeguard and archive IT development documents - Implementing governance using ISO 27001, ISO 27701, and other relevant technology and security best practices You will be the primary liaison between Engineering & Tech (ensuring security controls are built into platforms from day one), Legal & Regulatory (translating complex financial laws into actionable IT policies), and People & Partner Teams (fostering company-wide security culture). The GTF IT GRC team values mentorship, clear communication, and collaborative problem-solving, believing GRC is most effective when collaborative, not just corrective. Requirements: - Minimum 5 years of experience in IT governance, risk management, and compliance - Excellent experience with PSrE, ISO 27001, ISO 27701, ITIL, and COBIT - Proven track record of successfully leading and achieving ISO 27001 and ISO 27701 certifications - Excellent stakeholder management skills with ability to communicate and influence at all organizational levels - Demonstrated ability to deliver results with limited resources and minimal supervision - Extensive experience managing and navigating regulatory audits and ensuring compliance with industry standards - Strong leadership skills with ability to effectively lead a small team and foster collaborative work environment - Strong adaptability and flexibility to take on new areas of responsibility while leveraging existing skills and experience - One or more of the following certifications preferred: CISA, CISM, CRISC, ITIL, COBIT, or ISO 27001 LA

Similar roles