Information Security Policy Specialist
Grow with the top seeds in the industry- Location
- DKI Jakarta
- Workplace
- —
- Employment
- —
- Salary
- —
Posted 2mo ago
Job Description Summary
The Information Security Policy Specialist is responsible for developing, standardizing, and maintaining comprehensive information security policies, standards, and procedures across all cybersecurity domains. This role ensures consistent governance, eliminates outdated or fragmented documentation, and drives alignment with regulatory requirements, industry best practices, and organizational security objectives.
The specialist acts as a key contributor in establishing a unified, structured, and scalable policy framework to support effective cybersecurity governance and operational consistency.
Job Description
- Develop, review, and maintain information security policies, standards, procedures, and guidelines.
- ·Standardize and consolidate security documentation to ensure consistency across the organization.
- Collaborate with Cybersecurity, IT, Risk, Compliance, and Legal teams to define and validate security controls.
- Ensure policies align with industry standards and frameworks such as ISO 27001/27002, NIST CSF, and CIS Controls.
- Support policy governance processes, including version control, review cycles, approvals, and audit readiness.
- Maintain a centralized policy repository and ensure documentation remains current with regulatory and business requirements.
- Promote awareness and adoption of information security policies through communication and training initiatives.
- Identify policy gaps and recommend continuous improvements to strengthen governance and compliance.
Job Requirements
- Bachelor's degree in Information Security, Cybersecurity, Information Technology, or a related field.
- 3–7 years of experience in Information Security Governance, Risk & Compliance (GRC), or security policy development.
- Experience in developing and maintaining information security policies, standards, and procedures.
- Good understanding of cybersecurity domains, including IAM, Network Security, Cloud Security, Endpoint Security, and Data Protection.
- Familiar with security frameworks and standards such as ISO 27001/27002, NIST CSF, and CIS Controls.
- Strong technical writing, documentation, analytical, and stakeholder management skills.
- Ability to translate technical security requirements into clear and practical policies.
- Professional certifications such as CISA or CISM are an advantage.
"Our company has never levied any fees for the recruitment process nor has it required to order tickets and accommodation through a certain travel agent or certain person"
Skills
- ISO 27001
- NIST
- IAM
More jobs at Grow with the top seeds in the industry
All 14Digital Engineer
Grow with the top seeds in the industry · DKI Jakarta · 2d ago
Admin & Data Analyst
Grow with the top seeds in the industry · Medan · 2d ago
QA Analyst
Grow with the top seeds in the industry · Dumai · 3d ago
Operational & Support Analyst & Improvement
Grow with the top seeds in the industry · DKI Jakarta · 7d ago
GA Helpdesk Officer
Grow with the top seeds in the industry · DKI Jakarta · 8d ago
Similar roles
FY27 - Assurance - Manager & Senior Manager - IT Cybersecurity
Pwc · Jakarta · yesterday
Offensive Security Engineer\Lead
AiR · Jakarta · 16d ago
Information Security Engineer
Talent Insider · Central Jakarta · 16d ago
Head of Information Security
Noraa · Jakarta, Indonesia · 17d ago
Senior Security Analyst, Team Lead
Bitdefender · Indonesia · 24d ago
Cyber Security Staff
Binus · Jakarta · 1mo ago