IT GRC Specialist

Reposted 3 Days Ago
Be an Early Applicant
Ho Chi Minh City, VNM
In-Office
Senior level
Fintech • Payments • Financial Services
The Role
The IT GRC Specialist oversees governance, risk, and compliance activities in Southeast Asia, managing audits, developing frameworks, and facilitating compliance initiatives in a cross-functional manner.
Summary Generated by Built In

The IT GRC Specialist (SDE3) plays a critical role in supporting Kredivo Group’s Information Security and Compliance efforts. This role focuses on driving IT Governance, Risk, and Compliance (GRC) activities across our international entities—Vietnam, Thailand, and the Philippines.

While the candidate will report to the IT GRC Lead based in Indonesia, they are expected to operate independently and act as the main PIC for all IT GRC matters in the international markets, including coordinating audits, managing controls, and supporting local teams on compliance initiatives.

This role is ideally based in Vietnam, but we are open to candidates from Indonesia who meet the requirements and can provide strong regional support.

About the job:

Internal & External IT Audit Management & Coordination:

  • Act as the main PIC and lead strategies to manage increasing volumes of IT audits and compliance assessments, including ISO 27001, ITGC, Regional Financial IT Audits, Lender Assessments, and local regulator reviews in international markets.
  • Serve as the primary point of contact for all internal and external audit activities related to international entities.
  • Coordinate end-to-end audit processes, including scope alignment, scheduling, evidence collection, issue tracking, and closure.
  • Collaborate effectively with Internal Audit, External Auditors, and third-party assessors to facilitate smooth and timely assessments.
  • Ensure audits stay aligned with agreed scopes while maintaining strong professional relationships with all audit stakeholders.
  • Evaluate audit findings and work with cross-functional teams to define and implement corrective actions, ensuring alignment between audit results and actual implementation across the organization.

International IT GRC Ownership (VN, TH, PH)

  • Develop and establish the IT GRC framework in Vietnam, Thailand, and the Philippines, aligning with Kredivo Group’s global standards while addressing local requirements.
  • Conduct regular internal evaluations and risk assessments of IT and security controls to identify gaps and opportunities for improvement.
  • Implement and monitor adherence to Kredivo Group’s security policies and procedures, ensuring both local compliance and global alignment.
  • As main PIC compliance support for any country-specific regulatory requirements (e.g., State Bank of Vietnam) and lender-related audits, acting as the key liaison for international entities.
  • Maintain structured and auditable documentation, trackers, and progress reports for all IT GRC activities in the international markets.

Internal IT GRC & Compliance Support

  • Contribute to the development and continuous improvement of information security policies, standards, and procedures, ensuring relevance across all Kredivo Group entities.
  • Support the enhancement and localization of the Information Security Compliance Program to meet both global and region-specific requirements.
  • Perform and support access control reviews, enforcement of least privilege, and policy implementation—particularly in cloud, infrastructure, and endpoint environments.
  • Work closely with the Security Awareness team to tailor campaigns for international teams and track their effectiveness.
  • Design and maintain IT risk frameworks, and prepare clear reporting on audit status, control effectiveness, and compliance activities for internal stakeholders and leadership.
  • Ensure all documentation, evidence, and review records are clear, auditable, and accessible for internal reviews or external assessments.

About you:

  • Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or a related field.
  • Minimum 5+ years of experience in IT GRC, information security, or IT audit roles—preferably within Big4 consulting firms.
  • Proven experience in IT GRC, information security, or IT audit roles—preferably within financial services, fintech, or Bank industries.
  • Strong understanding of industry-recognized security frameworks (e.g., ISO 27001, NIST, PCIDSS, COBIT) and relevant regulatory requirements (e.g., Local Regulation, GDPR, etc.).
  • Hands-on experience in coordinating and responding to audits, including internal audits, external assessments, and regulatory reviews.
  • Excellent communication in english, interpersonal, and organizational skills, with the ability to engage effectively with both technical and non-technical stakeholders.
  • Self-motivated, detail-oriented, and able to manage multiple priorities with minimal supervision.
  • Prior experience working in a Big Four consulting or audit firm, especially in roles involving IT audit, risk, or compliance.
  • Adept at acting as an internal consultant to cross-functional teams, providing expert guidance on IT GRC and security-related matters.

Skills Required

  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related field
  • Minimum 5+ years of experience in IT GRC, information security, or IT audit roles
  • Strong understanding of industry-recognized security frameworks and relevant regulatory requirements
  • Hands-on experience in coordinating and responding to audits
  • Excellent communication in English, interpersonal, and organizational skills
  • Prior experience working in a Big Four consulting or audit firm
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
1,707 Employees

What We Do

Kredivo Group is Southeast Asia’s leading provider of digital financial services through its brands Kredivo, KrediFazz and Krom. Kredivo is the leading digital credit platform in Indonesia and Vietnam that gives customers instant credit financing for ecommerce and offline purchases, and personal loans, based on real-time decisioning. Kredivo users can buy now and pay later across the entirety of Indonesia’s retail commerce network with one of the lowest interest rates amongst digital credit providers in the country. Krom Bank Indonesia (formerly known as Bank Bisnis Internasional, IDX: BBSI) is the group’s bank entity and the operator of the Indonesian neobank Krom. Kredivo Group is backed by leading financial and strategic investors such as Mizuho Financial Group, Square Peg Capital, Jungle Ventures, Naver Corp, Mirae Asset, Telkom Indonesia and Victory Park Capital among others

Similar Jobs

Airwallex Logo Airwallex

Channel Partnerships Manager

Artificial Intelligence • Fintech • Payments • Business Intelligence • Financial Services • Generative AI
In-Office or Remote
Ho Chi Minh City, VNM
2200 Employees

Airwallex Logo Airwallex

Counsel

Artificial Intelligence • Fintech • Payments • Business Intelligence • Financial Services • Generative AI
In-Office
Ho Chi Minh City, VNM
2200 Employees

Cargill Logo Cargill

Digital Transformation Lead - ANH VietNam

Food • Greentech • Logistics • Sharing Economy • Transportation • Agriculture • Industrial
In-Office
Ho Chi Minh City, VNM
155000 Employees
5-5 Annually

Airwallex Logo Airwallex

Customer Success Manager

Artificial Intelligence • Fintech • Payments • Business Intelligence • Financial Services • Generative AI
In-Office or Remote
Ho Chi Minh City, VNM
2200 Employees

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
31 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account