hirly

Xendit

IT GRC Analyst

Jakarta, Indonesia

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Xendit first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.4M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Seniority
Mid level
Country
ID
Work mode
On-site / unstated
First seen by hirly
13 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

Xendit provides payment infrastructure across Southeast Asia and is expanding to Greater China and LATAM. We process payments, power marketplaces, disburse payroll and loans, provide KYC solutions, prevent fraud, and help businesses grow exponentially. We serve our customers by providing a suite of world-class APIs, eCommerce platform integrations, and easy to use applications for individual entrepreneurs, SMEs, and enterprises alike.

Our main focus is building the most advanced payment rails for Southeast Asia, with a clear goal in mind — to make payments across and within SEA simple, secure and easy for everyone. We serve thousands of businesses ranging from SMEs to multinational enterprises, and process millions of transactions monthly. We’ve been growing rapidly since our inception in 2015, onboarding hundreds of new customers every month, and backed by global top-10 VCs . We’re proud to be featured on among the fastest growing companies by Y-Combinator .

About the Job

At Xendit, we are looking for a mid-level/senior-level IT GRC Analyst to sit at the intersection of technology, compliance, and risk — not just for Indonesia, but across all of Xendit's operating markets. As an individual contributor, you will be responsible for ensuring our IT systems, processes, and controls meet the regulatory obligations and certification standards of every jurisdiction we operate in. You will be our regional GRC go-to person, coordinating directly with regulatory bodies across the regions (Bank Indonesia / OJK, BSP, BOT, etc). Beyond regulatory compliance, you will own and drive the full lifecycle of our IT certifications such as PCI-DSS and ISO 27001. You will work closely with engineering, security, product, and legal teams to embed compliance into how we build and operate. This is a role for someone who is detail-oriented, thrives in multi-market complexity, and can translate a wide range of regulatory requirements into practical, actionable controls in a fast-moving fintech environment.

Minimum Qualifications

3–5 years of hands-on experience in IT GRC, IT Risk Management, or IT Compliance roles

Solid working knowledge of PCI-DSS, ISO 27001 frameworks, including implementation, certification, and audit readiness

Familiarity with Bank Indonesia (BI) and OJK IT governance regulations applicable to payment service providers in Indonesia

Exposure to or willingness to take regulatory requirements in at least one other Southeast Asian or international market (e.g., BSP, BOT, MAS, BNM, or equivalent)

Proven experience conducting IT risk assessments, control testing, and gap analyses

Demonstrated ability to develop, review, and maintain IT policies, standards, and procedures

Strong analytical skills with the ability to translate diverse regulatory requirements into technical and operational controls

Effective communicator who can engage both technical and non-technical stakeholders across multiple countries and time zones

Preferred Qualifications

Prior experience navigating Bank Indonesia's PJP (Penyelenggara Jasa Pembayaran) Category 1 or Category 2 licensing requirements, including ongoing IT compliance obligations and regulatory examination readiness

Hands-on experience managing end-to-end certification processes — scoping, readiness assessment, evidence preparation, auditor coordination, and post-certification surveillance — for ISO 27001, PCI-DSS, or SOC 2

Direct experience coordinating IT audits or regulatory examinations with regional bodies such as BSP (Philippines), BOT (Thailand), MAS (Singapore), BNM (Malaysia), etc

Relevant professional certifications such as CISA, CRISC, ISO 27001 Lead Implementer, or ISO 27001 Lead Auditor

Prior experience in fintech, digital payments, or financial services in a multi-market Southeast Asian or global context

Exposure to cloud environments and understanding of cloud security control frameworks

Background in working cross-functionally with engineering and product teams to embed compliance-by-design principles

Responsibilities

Own and support Xendit's compliance programs for certification and regulatory audits, ensuring controls are implemented, tested, and evidenced effectively

Serve as the primary GRC point of contact for regional regulatory needs, coordinating IT-related audit and examination processes with regional regulatory bodies

Manage the full certification lifecycle for applicable frameworks — from initial scoping and gap analysis through certification issuance and ongoing surveillance — ensuring timely renewals and continuous compliance

Conduct periodic IT risk assessments across markets, maintain a consolidated IT risk register, and track remediation activities through to closure

Perform internal control testing and assessments to evaluate the design and operating effectiveness of IT controls across Xendit's regional entities

Identify compliance gaps across markets and work with relevant teams to develop and execute remediation plans

Develop, review, update, and enforce IT policies, standards, and procedures in line with multi-jurisdictional regulatory and framework requirements

Coordinate regulatory and third-party audits end-to-end, including preparing evidence packages, managing auditor requests, and facilitating examiner meetings

Monitor the evolving regulatory landscape across all operating markets and assess the impact of new or updated requirements on Xendit's IT environment

Produce compliance dashboards, regional status reports, and management briefings to keep stakeholders informed of GRC posture across all markets

Collaborate with engineering, product, security, and legal teams to embed compliance and risk considerations into project delivery and system design

Support continuous improvement of GRC processes, tooling, and automation to scale compliance operations efficiently across a growing number of markets

Original posting on Xendit's site ↗

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job