Risk Policy & Strategy Manager

  • Full-time

Company Description

Grab is Southeast Asia's leading superapp. From getting your favourite meals delivered to helping you manage your finances and getting around town hassle-free, we've got your back with everything. In Grab, purpose gives us joy and habits build excellence, while harnessing the power of Technology and AI to deliver the mission of driving Southeast Asia forward by economically empowering everyone, with heart, hunger, honour, and humility.

Job Description

About The Team

The ID Trust & Safety's Fraud Strategy team protects Grab Indonesia's financial ecosystem (OVO, Grab Payments, and Ofin) from fraud, including scams, promo abuse, and unauthorized transactions. As a high-ownership team, we manage end-to-end fraud prevention. We analyze emerging threats, write risk policies, and collaborate with cross-functional partners (Product, Engineering, Compliance) and regulators (OJK, BI) to minimize fraud losses.

Get To Know The Role

As Risk Policy & Strategy Manager, OVO, you will own OVO's fraud risk strategy and policy across the full payments lifecycle — cash-in, purchase, cash-out, transfer, and OVO Points. You are the accountable person for OVO's fraud OKRs: Promo Abuse Loss Rate, Account Takeover Incident Rate, Complaint Rate, and transaction Decline Rates.

You will work closely with OVO's product, engineering, data, operations, and compliance teams. You will also serve as the OVO risk representative in external engagements — including regulatory discussions, internal/external audits, and cross-entity risk alignment across Grab, OVO, and Ofin.

This is a senior individual contributor role with broad scope. You will be reporting to the Fraud Strategy Manager. This is an onsite role based in Jakarta.

 

Critical Task You Will Perform

  • Strategy & Policy Ownership: Define and maintain the anti-fraud risk framework for OVO, targeting promo abuse, account takeovers, scams, and emerging fraud patterns.
  • Metric & OKR Accountability: Track and optimize core fraud metrics, including loss, incident, complaint, and transaction decline rates across the user lifecycle.
  • Risk Controls & Product Assessment: Manage fraud detection rules, enforce Maker-Checker SOPs, and conduct pre-launch risk assessments to catch product vulnerabilities early.
  • Incident Response & Root Cause Analysis: Lead Root Cause Analysis (RCA) for fraud incidents, deliver remediation reports, and maintain audit-ready evidence for internal and external auditors.
  • Stakeholder & Regulatory Alignment: Partner with cross-functional teams (Product, Engineering, Compliance) and support engagements with key regulators like OJK, BI, and PPATK.

Qualifications

  • 5+ years in fraud risk management, risk policy, or financial crime strategy — ideally within a fintech, digital payments, or e-wallet environment.
  • Strong understanding of digital payment fraud typologies: promo abuse, Account Takeover, scams, mule accounts, unauthorized app exploitation, and QRIS/payment-rail-specific risks.
  • Demonstrated experience writing and owning risk policy frameworks — from threat identification through rule design, escalation thresholds, and regulatory documentation.
  • Proficiency in data-driven decision-making: ability to interpret fraud metrics, review SQL-based dashboards, and translate data signals into policy and rule changes.
  • Experience working with fraud decisioning systems (e.g., GrabDefence/Griffin or equivalent rule engines) and familiarity with Maker-Checker governance workflows.
  • Strong stakeholder management skills — comfortable engaging cross-functional teams (Product, Eng, Data, Compliance) and representing risk positions to senior leadership and external regulators (OJK, BI, PPATK).
  • Fluency in Bahasa Indonesia and English (written and spoken) — required for regulatory documentation, internal SOPs, and cross-regional collaboration.
  • Experience with regulatory engagement in Indonesia's fintech landscape (OJK, BI, PPATK) is a strong plus.

By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply

Privacy Notice