SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
GoTo Group, Southeast Asia's largest digital ecosystem, is seeking an experienced Internal Auditor - IT to lead risk-based audit execution across its payment systems and financial services infrastructure.
In this role, you will plan and execute comprehensive risk-based audits covering payment processing, transaction lifecycle, reconciliation, settlement, refunds, chargebacks, and payment operations. You will assess end-to-end business processes to identify control gaps, operational inefficiencies, leakage points, and fraud risks, evaluating the adequacy and effectiveness of existing controls.
Key responsibilities include:
- Conducting technology and automated control audits, evaluating application controls, system integrations, data flows, and access controls supporting payment systems
- Performing audit planning and fieldwork, including risk assessments, scope definition, testing procedures, evidence analysis, and quality assurance of audit working papers
- Developing clear audit findings with root-cause analysis and practical recommendations to strengthen payment controls and mitigate risks
- Managing stakeholder relationships with process owners and business stakeholders to validate findings, communicate risks, and monitor remediation of management action plans
- Contributing to continuous improvement of audit methodologies, data analytics, and control testing approaches for payment-related risks
GoTo Group operates a diverse ecosystem including Gojek (on-demand mobility and delivery), Tokopedia (e-commerce), and GoTo Financial (payments, lending, and merchant solutions), serving millions of users across Southeast Asia.
REQUIREMENTS:
- 6–8 years of professional experience in internal audit, IT audit, operational audit, risk management, internal controls, or related assurance functions
- Experience in payment systems or technology-enabled financial services highly preferred
- Strong knowledge of IT audit, risk-based audit methodologies, internal control frameworks, application and automated controls, system integrations, and technology risk
- Familiarity with Bank Indonesia (BI) regulations, regulatory requirements, and supervisory expectations relevant to payment systems, technology risk, information security, and internal controls (highly preferred)
- CISA (Certified Information Systems Auditor) certification mandatory
- Strong analytical and problem-solving skills with ability to assess complex payment processes and perform root-cause analysis
- Strong written and verbal English communication skills
- Strong stakeholder and project management capabilities