Senior IT GRC & Data Privacy Analyst

Apply Now ↗

About this role

At Amartha, we empower micro-businesses across Indonesia, enabling growth and equal prosperity. We've supported over 2.7 million entrepreneurs—mostly women—by disbursing IDR 22.8 trillion in funding. As we step into 2025, Amartha is evolving into a technology-driven financial ecosystem, expanding our reach in lending, funding, and payments. Through innovation and digital solutions, we aim to enhance accessibility, streamline processes, and create a seamless user experience.

About The Role

The Senior IT GRC and Data Privacy Analyst plays a crucial role in Amartha. You will be the warrior who will spearhead various IT GRC and Data Privacy programs to protect Amartha from internal and external threats, including monitoring and managing compliance with ISO 27001, POJK, PSrE, PDP, and other applicable regulations.

Responsibilities

GRC Framework Development and Maintenance:

  • Develop, implement, and maintain a comprehensive GRC framework that aligns with industry best practices and regulatory requirements.
  • Conduct regular risk assessments to identify potential threats and vulnerabilities.
  • Develop and implement risk mitigation strategies and action plans.
  • Monitor and report on compliance with internal policies and external regulations.

Data Privacy Compliance:

  • Ensure compliance with applicable data privacy regulations and data protection laws.
  • Conduct data privacy impact assessments (DPIAs) for new projects or initiatives.
  • Develop and implement data privacy policies and procedures.
  • Manage data breaches and incidents, including notification processes and remediation activities.

Vendor Management:

  • Assess the security and privacy practices of third-party vendors and suppliers.
  • Negotiate and manage vendor contracts to ensure compliance with security and privacy requirements.

Regulatory Compliance:

  • Stay up-to-date with evolving regulatory requirements and industry best practices.
  • Provide guidance and support to the organization in meeting compliance obligations.

Identity and Access Management (IAM):

  • Develop and maintain IAM policies, standards, and procedures.
  • Implement and manage IAM systems and tools (e.g., identity provisioning, access control, single sign-on).
  • Ensure the effective administration of user accounts and privileges.
  • Conduct regular IAM audits and reviews to identify and address security gaps.
  • Manage access certifications and segregation of duties controls.
  • 5+ years of related job experience
  • Strong analytical and interpersonal skills
  • Excellent communication both in written and spoken (English)
  • Ability to express information clearly at different organizational levels
  • Strong understanding of industry standards such as ISO 27001, NIST Cybersecurity Framework, GDPR, UU PDP
  • Experience in the financial services industry (esp. Microfinance, Payments, etc)
  • Having relevant certification are preferable (e.g.  CRISC, CIPP, etc)
  • Experience with IAM technologies and frameworks (e.g., Active Directory, LDAP, OAuth, SAML)

Frequently Asked Questions

Is the salary disclosed for the Senior IT GRC & Data Privacy Analyst position at mWmGxgPks2XJybYCh8mEJG?
The salary for this Senior IT GRC & Data Privacy Analyst role at mWmGxgPks2XJybYCh8mEJG is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the Senior IT GRC & Data Privacy Analyst position at mWmGxgPks2XJybYCh8mEJG located?
This Senior IT GRC & Data Privacy Analyst role at mWmGxgPks2XJybYCh8mEJG is based in South Jakarta, South Jakarta City, Indonesia. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Is the Senior IT GRC & Data Privacy Analyst role at mWmGxgPks2XJybYCh8mEJG full-time or part-time?
This is listed as a Full time position. It is posted as a Senior IT GRC & Data Privacy Analyst role in the Non Tech department at mWmGxgPks2XJybYCh8mEJG.
Which team or department does the Senior IT GRC & Data Privacy Analyst at mWmGxgPks2XJybYCh8mEJG belong to?
This Senior IT GRC & Data Privacy Analyst position is part of the Non Tech department at mWmGxgPks2XJybYCh8mEJG. See the full job description for more information about the team structure and responsibilities.
How do I apply for the Senior IT GRC & Data Privacy Analyst position at mWmGxgPks2XJybYCh8mEJG?
Click the "Apply Now" button on this page. You will be redirected to mWmGxgPks2XJybYCh8mEJG's official application portal hosted on workable where you can submit your application directly.
When was the Senior IT GRC & Data Privacy Analyst job at mWmGxgPks2XJybYCh8mEJG posted?
This Senior IT GRC & Data Privacy Analyst position at mWmGxgPks2XJybYCh8mEJG was posted on May 8, 2026. Apply as soon as possible — early applications are often reviewed first.
Senior IT GRC & Data Privacy Analyst
mWmGxgPks2XJybYCh8mEJG
Apply for this role ↗

You'll be redirected to mWmGxgPks2XJybYCh8mEJG's official application page on workable.