Company
| Legal Name | Xendit Ltd |
| Headquarters | Jakarta, Indonesia |
| Website | https://xendit.co |
Roles & Responsibilities Deliver a Delightfully Secure Customer Experience Xendit is an Indonesian fintech company that provides payment infrastructure across Indonesia. Xendit processes payments, runs marketplaces, disburses payroll and loans, detects fraud and helps other businesses grow exponentially. We serve these companies by providing a suite of world-class APIs and a dashboard UI that simplifies processes. Our main focus is to build the most advanced payment rails for Indonesia, with a clear goal in mind — to make payments in Indonesia simple, secure and easy for everyone. We currently serve local SMEs to some of Indonesia’s largest tech startups and also giant-sized businesses like Samsung. We process millions of transactions monthly, growing 25% month on month for the last 2 years. We are trusted and backed by some of the largest VCs in the world, who invested in Facebook, Slack, Twitch and Grab, and are alumni of the prestigious YCombinator (S15). Mission Your mission is to ensure that Xendit’s customers feel delightfully safe and secure across all of our platforms. Outcomes Develop, implement and monitor a comprehensive information security program, including: Full fledged security operations center with SIEM daily monitoring, continuously adapting rule sets to effectively automated threat response Regular vulnerability assessment and penetration testing of entire scope. Corporate endpoint protection program. Support S-SDLC together with the engineering teams. Comprehensive risk assessment and treatment program together with the product teams. Coordinate Internal and external audit against relevant standards applicable to Xendit such as PCIDSS, ISO 27001, ITGC Special support required for regulatory compliance - PBI (Bank Indonesia licenses for Payment Gateway and Electronic Money), POJK (Financial Services Authority -OJK license for eKYC, scoring and data validation schemes), PKominfo (electronic service provider registrations and local data processing and storage requirements). Develop, socialize and enforce security policies and procedures with rigorous maintenance of the evidence of compliance. Implement change control processes to ensure integrity and accountability. Access control management via IAM, SSO, RBAC, password and key management aligned with the applicable standards. Drive the incident response mechanism for security incidents, and be the approver of the incident reports. Serve as the Data Protection Officer, supporting data classification, data privacy, data retention and disposal policies Regular reporting of security posture to the organization. Respond to requests for security documentation, certifications and enquiries. Support trainings and onboarding on security on a regular basis. Develop and execute a security strategy and roadmap, with buy-in from the organization and affiliates. Ensure appropriate tools are evaluated, procured, deployed and renewed. Hire and upskill personnel in security team to meet security objectives. Work directly with the business units to facilitate risk assessment and risk management processes Understand and interact with all stakeholders to ensure the consistent application of policies and standards across all technology projects, systems and services Provide leadership to the information security organization Partner with business and product teams to raise awareness of risk management concerns Assist with the overall business technology planning, providing a current knowledge and future vision of technology and systems You may be a good fit if You have worked in a company with high scale traffic You have worked in a company with big data You have worked with limited human and financial resources and been able to get more done with less You have worked to scale companies’ humans and technology through massive growth stages You have worked to implement technical and compliance certifications You have experience in hiring and retaining top quality talent You have worked in a highly regulated environment You have worked in a multicultural environment You have worked to align internal and external stakeholders to hit long term targets You have set up and run security operations personally Requirements You have a strong understanding of security of applications, infrastructure and data. Professional security management certification such as CISSP, CISA, PCI QSA, ISO 27001 LA Minimum of 5 to 10 years of experience in a combination of risk management, information security and IT jobs Knowledge of common information security management frameworks, such as ISO/IEC 27001, PCIDSS and NIST. Excellent written and verbal communication skills and high level of personal integrity Innovative thinking and leadership with an ability to lead and motivate cross-functional, interdisciplinary teams Experience with contract and vendor negotiations and management including managed services. Experience in secure software development lifecycle or other best in class development practices. Experience with Cloud computing/Elastic computing across virtualized environments. You have a strong track record of learning on the job You thrive on autonomy and have proven you can push towards a goal by yourself You communicate and drive alignment well across teams Your Philosophy You believe in building seamless solutions that require minimal human involvement You believe in growing people You’re customer oriented in your communication and solutioning You believe in leading from the front You’re committed to building digital infrastructure for SEA Bonus Points You’ve worked in a venture backed, high growth payments startup You’ve worked in SEA
| Country | City | Job Ads |
|---|---|---|
| Indonesia | Jakarta | 371 |
| Philippines | Manila | 201 |
| Malaysia | Kuala Lumpur | 122 |
| Thailand | Bangkok | 81 |
| Singapore | Singapore | 59 |
| Indonesia | Jakarta Raya | 36 |
| Thailand | กรุงเทพมหานคร | 21 |
| Taiwan, Province of China | Taipei | 18 |
| United States | Manila | 16 |
| Indonesia | DKI Jakarta | 13 |
Loading map...
Legal Form: Ltd
Company Size: 501 - 1000
Job Ads found: 968
Job Ads per Month: 22.0
Hiring Locations: 15
| Date of first job ad | 31.10.2019, 11:02 |
| Date of last job ad | 08.07.2026, 22:12 |
| Date merged | 13.07.2026, 18:42 |
| Date created | 31.10.2019, 11:02 |