About the job Cybersecurity Information Security & Data Privacy Officer (Jakarta)
Meratus Group is a leading integrated maritime and logistics operator in Indonesia, pioneering innovative solutions that drive efficiency and sustainability in the industry. With a rich history dating back to 1957, Meratus has evolved into a powerhouse, operating over 45 shipping routes, a fleet of 100 vessels, and a network of container terminals and logistics centers.
At Meratus, we are committed to digitalization, innovation, and transformation, ensuring seamless logistics and maritime services across Indonesia and Southeast Asia. Our customer-centric approach and agile operations empower businesses to navigate complex supply chain challenges with confidence.
We take pride in fostering a dynamic and inclusive workplace, where talented professionals can thrive and contribute to shaping the future of maritime logistics. Join us and be part of a team that is redefining industry standards while making a meaningful impact on global trade and sustainability.
Position Overview : Cybersecurity, Information Security & Data Privacy Officer (Governance) is responsible for supporting information security governance, cybersecurity compliance, risk management, and data privacy initiatives across the organization.
Responsibilities :
- Policy & Framework Management: Develop, review, and maintain information security and data privacy policies, standards, and guidelines based on ISO 27001, NIST, and COBIT frameworks.
- Risk Assessments: Lead information security risk assessments, perform third-party/vendor risk reviews, and monitor corporate risk registers and treatment plans.
- Compliance & Audit Coordination: Assist internal and external security audits, tracking findings and remediation action plans.
- Privacy Governance: Support Personal Data Protection (PDP) compliance initiatives and privacy governance across all enterprise business lines.
- Security Awareness: Design, execute, and evaluate company-wide cybersecurity awareness and information security training programs.
- Enterprise Collaboration: Participate in broader enterprise risk management, business continuity planning, cyber resilience programs, and secure cloud adoption governance.
Requirements :
- Bachelor's degree in Cybersecurity, Information Security, Computer Science.
- 2 - 3 years of dedicated experience in IT Governance, Risk, and Compliance (GRC) or Data Privacy.
- Deep knowledge of Indonesian PDP regulations, ISO 27001 implementation, and NIST frameworks.
- Proven experience handling internal/external audits and building risk registers.
- Excellent documentation, reporting, and presentation skills.