Epicareer Might not Working Properly
Learn More

GRC Security Consultant

Salary undisclosed

Checking job availability...

Original
Simplified

softScheck is a fast-growing IT security consultancy firm in Asia. We provide cybersecurity consultancy services across multiple government agencies, Banks, MNCs, and large corporations.

PT softScheck Siber Securindo (Member of softScheck Group) is looking for a skilled and experienced GRC Security Consultant to join our team in Indonesia. You will play a pivotal role in delivering services related to security audits, compliance, risk management, and cybersecurity advisory.

Key Responsibilities

As a GRC security consultant, your daily job will include but not be limited to:

  • Plan, execute, and deliver comprehensive security audits, such as ISO 27001 Audits, SWIFT Audits, and Technical security audits to evaluate compliance with organizational policies and standards.
  • Prepare detailed audit reports with actionable findings and recommendations for clients.
  • Assist clients in achieving and maintaining compliance with key standards (e.g., PCI DSS, ISO 27001).
  • Conduct risk assessments to identify, evaluate, and prioritize risks, and develop risk mitigation plans.
  • Perform cybersecurity maturity assessments using frameworks like NIST CSF, C2M2, or custom maturity models.
  • Develop policies, procedures, and frameworks for governance, risk, and compliance tailored to client needs.

What we are looking for

  • 3+ years of experience in GRC, cybersecurity audits, risk management, or a related field.
  • Proven expertise in ISO 27001 Audits, SWIFT CSP compliance, and risk assessment methodologies.
  • Strong understanding of GRC frameworks, including ISO 27001, NIST CSF, COBIT, PCI DSS, GDPR, and SWIFT CSP.
  • Experience performing cybersecurity maturity assessments and developing improvement roadmaps.
  • Knowledge of technical controls (e.g., network security, access management, vulnerability management).
  • Strong written and verbal communication skills, with the ability to deliver clear, actionable reports.
  • Exceptional problem-solving and analytical skills.

Good to Have

Certifications such as ISO 27001 Lead Auditor/Implementer and CISA (Certified Information Systems Auditor)

Join softScheck!

softScheck is committed to building our team with high performing culture that emphasizes servant leadership and continuous improvement which constantly spur one another towards bringing the best version of oneself.

Your personal data will be processed for the purpose of managing softScheck's recruitment related activities, which includes setting up and conducting interviews and tests for applicants, evaluating, and assessing the results and as is otherwise needed in the recruitment and hiring process. Please consult our Privacy Notice (https://www.softscheck.sg/privacy-policy/), to know more about how we collect, use, and transfer the personal data of our candidates.

Privacy Policy - softScheck

softScheck is a fast-growing IT security consultancy firm in Asia. We provide cybersecurity consultancy services across multiple government agencies, Banks, MNCs, and large corporations.

PT softScheck Siber Securindo (Member of softScheck Group) is looking for a skilled and experienced GRC Security Consultant to join our team in Indonesia. You will play a pivotal role in delivering services related to security audits, compliance, risk management, and cybersecurity advisory.

Key Responsibilities

As a GRC security consultant, your daily job will include but not be limited to:

  • Plan, execute, and deliver comprehensive security audits, such as ISO 27001 Audits, SWIFT Audits, and Technical security audits to evaluate compliance with organizational policies and standards.
  • Prepare detailed audit reports with actionable findings and recommendations for clients.
  • Assist clients in achieving and maintaining compliance with key standards (e.g., PCI DSS, ISO 27001).
  • Conduct risk assessments to identify, evaluate, and prioritize risks, and develop risk mitigation plans.
  • Perform cybersecurity maturity assessments using frameworks like NIST CSF, C2M2, or custom maturity models.
  • Develop policies, procedures, and frameworks for governance, risk, and compliance tailored to client needs.

What we are looking for

  • 3+ years of experience in GRC, cybersecurity audits, risk management, or a related field.
  • Proven expertise in ISO 27001 Audits, SWIFT CSP compliance, and risk assessment methodologies.
  • Strong understanding of GRC frameworks, including ISO 27001, NIST CSF, COBIT, PCI DSS, GDPR, and SWIFT CSP.
  • Experience performing cybersecurity maturity assessments and developing improvement roadmaps.
  • Knowledge of technical controls (e.g., network security, access management, vulnerability management).
  • Strong written and verbal communication skills, with the ability to deliver clear, actionable reports.
  • Exceptional problem-solving and analytical skills.

Good to Have

Certifications such as ISO 27001 Lead Auditor/Implementer and CISA (Certified Information Systems Auditor)

Join softScheck!

softScheck is committed to building our team with high performing culture that emphasizes servant leadership and continuous improvement which constantly spur one another towards bringing the best version of oneself.

Your personal data will be processed for the purpose of managing softScheck's recruitment related activities, which includes setting up and conducting interviews and tests for applicants, evaluating, and assessing the results and as is otherwise needed in the recruitment and hiring process. Please consult our Privacy Notice (https://www.softscheck.sg/privacy-policy/), to know more about how we collect, use, and transfer the personal data of our candidates.

Privacy Policy - softScheck