Posted 2 months ago
Information Security Policy Specialist
AI Summary
Develops, standardizes, and maintains information security policies and procedures across cybersecurity domains, ensuring governance alignment with frameworks like ISO 27001 and NIST CSF.
About this role
Job Description Summary:
The Information Security Policy Specialist is responsible for developing, standardizing, and maintaining comprehensive information security policies, standards, and procedures across all cybersecurity domains. This role ensures consistent governance, eliminates outdated or fragmented documentation, and drives alignment with regulatory requirements, industry best practices, and organizational security objectives.
The specialist acts as a key contributor in establishing a unified, structured, and scalable policy framework to support effective cybersecurity governance and operational consistency.
Job Description:
- Develop, review, and maintain information security policies, standards, procedures, and guidelines.
- ·Standardize and consolidate security documentation to ensure consistency across the organization.
- Collaborate with Cybersecurity, IT, Risk, Compliance, and Legal teams to define and validate security controls.
- Ensure policies align with industry standards and frameworks such as ISO 27001/27002, NIST CSF, and CIS Controls.
- Support policy governance processes, including version control, review cycles, approvals, and audit readiness.
- Maintain a centralized policy repository and ensure documentation remains current with regulatory and business requirements.
- Promote awareness and adoption of information security policies through communication and training initiatives.
- Identify policy gaps and recommend continuous improvements to strengthen governance and compliance.
Job Requirements:
- Bachelor's degree in Information Security, Cybersecurity, Information Technology, or a related field.
- 3–7 years of experience in Information Security Governance, Risk & Compliance (GRC), or security policy development.
- Experience in developing and maintaining information security policies, standards, and procedures.
- Good understanding of cybersecurity domains, including IAM, Network Security, Cloud Security, Endpoint Security, and Data Protection.
- Familiar with security frameworks and standards such as ISO 27001/27002, NIST CSF, and CIS Controls.
- Strong technical writing, documentation, analytical, and stakeholder management skills.
- Ability to translate technical security requirements into clear and practical policies.
- Professional certifications such as CISA or CISM are an advantage.
"Our company has never levied any fees for the recruitment process nor has it required to order tickets and accommodation through a certain travel agent or certain person"
Skills
Explore related jobs
More jobs at PT Soci Mas
Similar Audit Readiness jobs
Jobs in Dki Jakarta
Browse these categories
Market data for this role
All reports →- SeriesRole reportsOne role family at a time: how many openings, what changed this week, who is hiring, what it pays.
- SeriesSalary reportsWhat employers publish in job postings, by level and workplace. Not self-reported pay.
- Market overviewState of tech hiring, September 2026: up 4.8%Tech hiring rose 4.8% month over month in September 2026, with 411,122 new listings. Customer support and account executive roles led the growth.