Join Xendit as an IT GRC Analyst to ensure compliance and manage IT certifications across Southeast Asia and beyond.
Posted by employer 2 months ago
First seen on Joblaze 1 week ago
Last verified on the company career page 1 day ago
Skills & Technologies
Requirements
Not disclosed in this posting: compensation, work arrangement, visa sponsorship.
Joblaze summary
The IT GRC Analyst at Xendit plays a crucial role in ensuring that the company's IT systems and processes comply with regulatory standards across multiple markets. This position requires expertise in frameworks like PCI-DSS and ISO 27001, along with a solid understanding of local regulations such as those from Bank Indonesia. Ideal candidates will have 3-5 years of experience in IT compliance and risk management, particularly in fintech or digital payments. The role involves close collaboration with various teams to integrate compliance into operational practices.
Joblaze insights
Quick facts
From the original posting
Xendit provides payment infrastructure across Southeast Asia and is expanding to Greater China and LATAM. We process payments, power marketplaces, disburse payroll and loans, provide KYC solutions, prevent fraud, and help businesses grow exponentially. We serve our customers by providing a suite of world-class APIs, eCommerce platform integrations, and easy to use applications for individual entrepreneurs, SMEs, and enterprises alike.
Our main focus is building the most advanced payment rails for Southeast Asia, with a clear goal in mind — to make payments across and within SEA simple, secure and easy for everyone. We serve thousands of businesses ranging from SMEs to multinational enterprises, and process millions of transactions monthly. We’ve been growing rapidly since our inception in 2015, onboarding hundreds of new customers every month, and backed by global top-10 VCs. We’re proud to be featured on among the fastest growing companies by Y-Combinator.
At Xendit, we are looking for a mid-level/senior-level IT GRC Analyst to sit at the intersection of technology, compliance, and risk — not just for Indonesia, but across all of Xendit's operating markets. As an individual contributor, you will be responsible for ensuring our IT systems, processes, and controls meet the regulatory obligations and certification standards of every jurisdiction we operate in. You will be our regional GRC go-to person, coordinating directly with regulatory bodies across the regions (Bank Indonesia / OJK, BSP, BOT, etc). Beyond regulatory compliance, you will own and drive the full lifecycle of our IT certifications such as PCI-DSS and ISO 27001. You will work closely with engineering, security, product, and legal teams to embed compliance into how we build and operate. This is a role for someone who is detail-oriented, thrives in multi-market complexity, and can translate a wide range of regulatory requirements into practical, actionable controls in a fast-moving fintech environment.