Glints Keuangan & Perbankan Full Time

AI Governance & Compliance Officer

AiSensum (PT Aisensum Bigdata Analytics)

Setiabudi IDR 7.000.000 – 10.000.000 Diposting 17 jam lalu
Lokasi Setiabudi
Gaji IDR 7.000.000 – 10.000.000
Tipe Kerja Full Time
Negara Indonesia

Deskripsi Pekerjaan

Informasi lengkap tentang posisi dan persyaratan

Ringkasan Yukerja

Lowongan AI Governance & Compliance Officer di AiSensum (PT Aisensum Bigdata Analytics) kami kurasi dari Glints (kategori Keuangan & Perbankan). Perhatikan lokasi kerja (Setiabudi) sebelum melamar. Yukerja.com bukan pemberi kerja — lamaran diproses di situs sumber resmi.


ABOUT THE ROLE

AISensum builds AI products for frontline retail and marketing teams. We are entering the European market, starting with a Netherlands pilot, and our AI coaching product falls squarely under the EU AI Act as a high-risk system. That brings real, dated obligations under the AI Act and the GDPR, alongside the data protection regimes we already operate under across Indonesia, Australia and India.

We are hiring our first AI Governance & Compliance Officer to own this end-to-end. You will turn regulatory requirements into a working programme: the documents, the controls, the evidence, and the tracking that let us launch and scale without cutting corners. You will not work alone on the law itself; we retain specialist counsel in the EU, but you will be the person inside AISensum who holds the whole picture, keeps every obligation mapped to an owner and a deadline, and refuses to let anything slip.

This role is based in Jakarta because it works hand in hand with our engineering and product teams here. It is deliberately scoped for someone early in a privacy and data protection career who is exceptionally rigorous, wants ownership fast, and is ready to build a compliance function from the ground up.


WHAT YOU'LL OWN

EU AI Act & GDPR readiness (primary focus)

  • Artefact pipeline. Coordinate and draft the compliance pack for each deployment: the DPIA support pack, data processing agreements, employee notices, opt-out procedures, instructions for use, and authorised-representative paperwork. You draft and assemble; counsel signs off.
  • High-risk provider readiness. Build toward the AI Act provider obligations that apply from December 2027: risk management, data governance, technical documentation, logging, human oversight, quality management, conformity assessment and the EU declaration of conformity.
  • Live-now obligations. Keep us clean on what already applies: AI literacy training records, the workplace emotion-recognition prohibition, transparency and labelling, and the full GDPR stack.
  • Cross-border transfers. Maintain the sub-processor register and the transfer mechanisms for every third party in the data path, including model and speech-to-text providers, and keep the transfer impact assessments current.
  • Bias & data quality. Coordinate bias testing of scoring inputs and keyword libraries with the engineering team, and keep the results documented.

Data protection

  • Multi-regime coverage. Support our existing obligations under Indonesia's PDP Law (No. 27 of 2022), Australia's Privacy Act and the APPs, and India's DPDP Act 2023 and Rules 2025, so our processor commitments hold up in every market we operate in.
  • Breach & incident readiness. Maintain incident and breach protocols that meet the tightest applicable notification window, and run the drill so we can actually hit it.

Programme & Jira governance

  • Single source of truth. Own the compliance backlog in Jira. Every obligation, artefact and engineering commitment mapped to a ticket, an owner, a deadline and its evidence, with nothing tracked only in someone's head.
  • Keep the trail audit-grade. Maintain clean, retrievable records so that on any given day we can show a regulator, a client or an auditor exactly where we stand. 
  • Drive to done. Chase engineers, partners and external counsel to closure. Escalate early, hold the line on deadlines, and say no clearly when something is not ready.


WHO YOU ARE

  • 1 to 2 years in privacy, data protection or regulatory compliance. We will seriously consider an outstanding fresher who can show the rigour and the appetite.
  • Bachelor's degree in law, preferably with a data protection, technology or international dimension. Degrees in public policy, regulatory affairs or a related field are welcome where paired with a privacy focus. A privacy certification such as CIPP/E, or a clear plan to obtain one, is highly valued. 
  • On a privacy and data protection track, working knowledge of the GDPR, and either a certification such as CIPP/E or IAPP membership, or a clear plan to get there. Direct EU AI Act exposure is a strong plus; genuine eagerness to master it is essential.
  • Exceptionally strict and detail-obsessed. You notice the missing clause, the wrong date, the untracked task, and it bothers you until it is fixed. This is the single most important trait for this role.
  • Fluent English, spoken and written. Dutch is a strong advantage, and another European language such as German or French is a plus. This helps you review European-language documents, but it is not a hard requirement.
  • Disciplined with tools and tracking. Comfortable running a programme in Jira or a similar system, and turning a messy list of obligations into a clean, current board.
  • Able to read enough of the technical picture, data flows, logging, model and API calls, cloud regions, to ask the right questions of engineers, without needing to be an engineer yourself.
  • Based in Jakarta, or ready to relocate, and comfortable working closely with the founder and the local product and engineering teams.


Nice to have

  • Hands-on with DPIAs, records of processing (ROPA), or sub-processor management.
  • Familiarity with any of the Indonesian PDP Law, Australian Privacy Act, or Indian DPDP Act.
  • Exposure to ISO 27001, SOC 2, or a formal audit or GRC environment.
  • Experience coordinating external counsel or working across time zones with an EU-based team.


WHAT WE OFFER

  • Competitive salary and the chance to build a compliance function from zero, not inherit someone else's.
  • Real ownership of a high-stakes workstream, with a direct line to the founder.
  • A front-row seat to how the EU AI Act plays out in practice, on a genuine high-risk deployment.
  • A clear growth path toward Data Protection Officer or Head of Compliance as we scale across Europe and APAC.


Disclaimer: Yukerja.com adalah agregator lowongan kerja, bukan pemberi kerja. Lowongan ini diagregasi dari Glints. Proses lamaran dilakukan di situs resmi perusahaan atau portal sumber. Kami tidak bertanggung jawab atas keakuratan informasi lowongan.

Tips Melamar AI Governance & Compliance Officer

  1. Baca deskripsi lengkap dan pastikan skill Anda match sebelum melamar ke AiSensum (PT Aisensum Bigdata Analytics).
  2. Sesuaikan CV dan cover letter dengan kata kunci dari job description — terutama untuk kategori Keuangan & Perbankan.
  3. Klik Lamar Sekarang untuk diarahkan ke Glints. Proses rekrutmen sepenuhnya di situs sumber.
  4. Siapkan portfolio atau LinkedIn yang update jika diminta di tahap screening.
  5. Waspadai permintaan transfer uang — lowongan resmi tidak memungut biaya.

Artikel terkait: CV ATS · Blog Karir & Tips