Lead Internal Auditor - IT - Digital Signature

Lever, Inc.

Jakarta Pusat

On-site

IDR 500,000,000 - 900,000,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

GoTo is seeking an Internal Audit Lead (IT) to drive end-to-end risk-based IT audits across infrastructure, cloud, and data environments. You will collaborate with Technology, Security, Risk, and Compliance teams to identify control gaps and recommend improvements.

Ideal candidates have 6–8 years in IT audit or technology risk, strong knowledge of IT controls, cybersecurity, and data governance, plus a CISA certification.

Qualifications

  • 6–8 years of IT audit or technology risk experience.
  • Strong knowledge of IT controls, cybersecurity, data governance, and risk management.

Responsibilities

  • Plan and execute risk-based IT audits across infrastructure, applications, cloud, and operations.
  • Assess IT general controls and application controls, access, change, and incident management.
  • Evaluate cybersecurity, information security, vulnerability management, and disaster recovery.
  • Assess data governance, data integrity, interfaces, data flows, and critical systems controls.
  • Conduct risk assessments, define audit procedures, walkthroughs, and testing; document evidence.

Skills

IT Audit
IT Risk
COBIT/ISO27001
CISA

Tools

COBIT
ISO 27001
NIST

Job description

About the Role

At GoTo, our technology ecosystem operates at immense scale and complexity, supporting critical platforms, systems, and data across the organization. As the Internal Audit Lead (IT), you will lead the end-to-end execution of risk-based IT audits, assessing technology processes, IT controls, cybersecurity, data management, and system environments. Working closely with technology, security, risk, and business stakeholders, you will identify control gaps and technology risks, evaluate compliance with relevant regulatory requirements, and translate audit findings into practical recommendations that strengthen technology governance, security, and resilience. This role offers broad exposure to complex technology environments and requires strong IT audit expertise, analytical thinking, and stakeholder management skills.

What You Will Do
  • IT & Risk-Based Audit Execution: Plan and execute risk-based IT audits covering technology infrastructure, applications, cloud environments, IT operations, and technology governance.
  • IT Controls Assessment: Assess IT general controls, application controls, access management, change management, incident management, and other key technology processes.
  • Cybersecurity & Technology Risk: Evaluate cybersecurity, information security, vulnerability management, business continuity, disaster recovery, and other technology-related risks.
  • Data & System Audit: Assess data governance, data integrity, system interfaces, data flows, and controls over critical systems and information assets.
  • Audit Planning & Fieldwork: Conduct risk assessments, define audit procedures, perform walkthroughs and control testing, analyze evidence, and maintain audit documentation.
  • Reporting & Recommendations: Develop clear audit findings, identify root causes and impacts, and provide practical recommendations to strengthen IT controls and mitigate technology risks.
  • Stakeholder & Remediation Management: Work with Technology, Information Security, Risk, Compliance, and business stakeholders to validate findings and monitor remediation.
What You Will Need
  • 6–8 years of experience in IT audit, technology risk, information security audit, internal audit, or related assurance functions.
  • Strong experience in IT general controls, application controls, cybersecurity, IT operations, cloud technology, data governance, and technology risk management.
  • Strong knowledge of risk-based IT audit methodologies and IT control frameworks, with familiarity with COBIT, ISO 27001, NIST, or similar frameworks.
  • CISA (Certified Information Systems Auditor) certification is mandatory.
  • Familiarity with Indonesian technology and digital regulations, including relevant Komdigi requirements and regulatory expectations, is highly preferred.
  • Experience working with technology regulators, government institutions, or regulated technology environments is highly preferred.
  • Strong analytical, communication, stakeholder management, and project management skills, with the ability to translate technical risks into clear business implications.
About the Team

Our team, GoTo Internal Audit, is a growing group of dedicated auditors with deepening expertise in our respective areas. As part of GoTo’s Internal Audit function, we support the Board’s oversight role and provide guidance to Management on operational efficiency, risk management, and asset protection across Gojek, Tokopedia, and GoTo Financial.

Our goal is to be a trusted business partner by delivering high-quality audits that help improve operational excellence through stronger controls and governance practices, while offering valuable insights on the transparency of performance in relation to business objectives. As a publicly listed company, we also play a key role in safeguarding stakeholders’ interests, ensuring asset protection, and maintaining regulatory compliance.

About GoTo Group

GoTo is the largest digital ecosystem in Indonesia. GoTo's mission is 'empower progress' by offering technology infrastructure and solutions that help everyone to access and thrive in the digital economy.

The GoTo ecosystem provides a wide range of services, including mobility, delivery, payments, financial services, and technology solutions for merchants. The ecosystem also provides e-commerce services through Tokopedia and banking services through its partnership with Bank Jago.

About Gojek

Gojek is Southeast Asia’s leading on-demand platform and pioneer of the multi-service ecosystem with over 2.5 million driver partners across the regions offering a wide range of services such as transportation, food delivery, logistics and more. With its mission to create impact at scale, Gojek is committed to resolving consumer problems and raising standards of living by connecting consumers to the best providers of goods and services in the market.

About GoTo Financial

GoTo Financial accelerates financial inclusion through its leading financial services and merchants solutions. Its consumer services include GoPay and GoPayLater and serve businesses of all sizes through Midtrans, Moka, GoBiz Plus, GoBiz, and Selly. With its trusted and inclusive ecosystem of products, GoTo Financial is open to new growth opportunities and aims to empower everyone to Make It Happen, Make It Together, Make It Last.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Internal Auditor - Business
Lead Internal Auditor - Business

Lever, Inc. • Jakarta Pusat

On-site
IDR 600,000,000 - 1,000,000,000
Lead Internal Auditor - IT - Payment
Lead Internal Auditor - IT - Payment

Lever, Inc. • Jakarta Pusat

On-site
IDR 480,000,000 - 750,000,000
Lead Internal Auditor - Lending
Lead Internal Auditor - Lending

GoTo Financial • Jakarta Utara

On-site
IDR 90,000,000 - 140,000,000
Lead Internal Auditor - IT - Payment
Lead Internal Auditor - IT - Payment

GoTo Financial • Jakarta Utara

On-site
IDR 400,000,000 - 700,000,000
IT GRC Manager - Payments
IT GRC Manager - Payments

GoTo Group • Jakarta Pusat

On-site
IDR 334,800,000 - 613,800,000
Lead Internal Auditor - IT - Digital Signature
Lead Internal Auditor - IT - Digital Signature

GoTo Financial • Jakarta Utara

On-site
IDR 600,000,000 - 900,000,000
IT GRC Manager - Digital Identity
IT GRC Manager - Digital Identity

GoPay • Jakarta Pusat

Hybrid
IDR 450,000,000 - 650,000,000
IT GRC Manager - Digital Identity
IT GRC Manager - Digital Identity

Lever, Inc. • Jakarta Pusat

On-site
IDR 600,000,000 - 900,000,000
Senior Internal Auditor: Risk & Controls Leader
Senior Internal Auditor: Risk & Controls Leader

Lever, Inc. • Jakarta Pusat

On-site
IDR 600,000,000 - 1,000,000,000
Senior Internal Auditor - Risk-Based, Multilingual
Senior Internal Auditor - Risk-Based, Multilingual

GoTo Financial • Jakarta Utara

On-site
IDR 90,000,000 - 140,000,000