SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
GoTo Group, Southeast Asia's largest digital ecosystem, is seeking an experienced Internal Auditor - IT to lead IT audit and risk assessment initiatives across the organization. The role focuses on planning and executing risk-based IT audits covering technology infrastructure, applications, cloud environments, IT operations, and technology governance.
Key responsibilities include:
• Planning and executing comprehensive risk-based IT audits across technology infrastructure, applications, cloud environments, IT operations, and governance frameworks
• Assessing IT general controls, application controls, access management, change management, and incident management processes
• Evaluating cybersecurity, information security, vulnerability management, business continuity, and disaster recovery capabilities
• Assessing data governance, data integrity, system interfaces, and controls over critical systems and information assets
• Conducting risk assessments, defining audit procedures, performing walkthroughs and control testing, and maintaining audit documentation
• Developing clear audit findings, identifying root causes and impacts, and providing practical recommendations to strengthen IT controls and mitigate technology risks
• Collaborating with Technology, Information Security, Risk, Compliance, and business stakeholders to validate findings and monitor remediation efforts
GoTo Group operates a diverse digital ecosystem including mobility (Gojek), delivery, payments, financial services (GoTo Financial, GoPay, GoPayLater), and e-commerce (Tokopedia), serving millions of users and driver partners across Southeast Asia.
Requirements:
• 6–8 years of experience in IT audit, technology risk, information security audit, internal audit, or related assurance functions
• Strong experience in IT general controls, application controls, cybersecurity, IT operations, cloud technology, data governance, and technology risk management
• Strong knowledge of risk-based IT audit methodologies and IT control frameworks (COBIT, ISO 27001, NIST, or similar)
• CISA (Certified Information Systems Auditor) certification is mandatory
• Familiarity with Indonesian technology and digital regulations, including Komdigi requirements, is highly preferred
• Experience working with technology regulators, government institutions, or regulated technology environments is highly preferred
• Strong analytical, communication, stakeholder management, and project management skills with ability to translate technical risks into clear business implications