## About the Role
This role owns the governance structure that supports cloud adoption in a highly regulated banking environment. Its main purpose is to define and maintain the policies, controls, and operating documentation needed to keep multi-cloud activity aligned with internal standards and regulatory obligations.
The position works closely with Risk & Compliance Units, Internal Audit, Compliance, and Internal IT to map cloud controls to OJK and Bank Indonesia requirements. It also supports audit readiness and regulatory examinations while keeping the governance model current as requirements and cloud services evolve.
In addition, the role contributes to FinOps governance by improving spend visibility, tagging, chargeback/showback, budget oversight, and cost control. It also maintains governance documentation in both Bahasa Indonesia and English for compliance, risk, and operational use.
## Key Responsibilities
– Develop and maintain the multi-cloud governance framework, including policies, standards, guidelines, procedures, and work instructions.
– Map OJK and Bank Indonesia requirements, including POJK, SEOJK, and cloud-related regulations, to cloud technical controls.
– Maintain the regulatory-to-control traceability matrix.
– Build and update the cloud risk register and cloud risk assessment templates for cloud workloads.
– Manage the IAM access control matrix across AWS and GCP, supporting least-privilege access and maker-checker segregation of duties.
– Support FinOps governance through tagging strategy, chargeback/showback, budget tracking, cost optimization, and expenditure controls.
– Prepare audit evidence and support cloud audits in coordination with RCU, Internal Audit, Compliance, and Internal IT.
– Support readiness for OJK regulatory examinations.
– Maintain governance documentation in Bahasa Indonesia and English.
– Contribute to the ongoing improvement of Cloud Center of Excellence (Cloud COE) governance practices.
## Required Skills
– Multi-cloud governance framework development and maintenance
– Regulatory mapping between cloud controls and OJK / Bank Indonesia requirements
– Knowledge of POJK, SEOJK, and cloud-computing-related requirements
– Cloud risk register and risk assessment template management
– IAM access control matrix management across AWS and GCP
– Understanding of least-privilege access and maker-checker controls
– FinOps governance, including tagging, chargeback/showback, budget monitoring, and cost optimization
– Audit evidence preparation and cloud audit support
– Governance documentation in Bahasa Indonesia and English
– Cross-functional coordination with RCU, Internal Audit, Compliance, and Internal IT
## Cloud Platforms & Technologies
– **Cloud Providers:** AWS, GCP
– **Identity & Access Management:** IAM
## FinOps Responsibilities
– Cloud resource tagging strategy
– Chargeback and showback models
– Budget monitoring
– Cost optimization
– Expenditure control
## Why You Might Be Interested
This opportunity combines cloud governance, risk, compliance, and FinOps in a highly regulated banking setting. It is well suited to someone who enjoys building control frameworks, supporting audit readiness, and translating regulatory expectations into practical cloud controls. The role also spans AWS and GCP and involves close work with risk, audit, compliance, and internal IT stakeholders. Documentation in both Bahasa Indonesia and English adds an important operational and compliance dimension.

