SlipstreamJobsFresh Startup & VC-Backed Jobs

Lead Internal Auditor - IT

GoTo Group - Jakarta, Indonesia - In-office - posted 2026-09-30

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

GoTo Group, Southeast Asia's largest digital ecosystem, is seeking an experienced Internal Auditor - IT to lead IT audit and risk assessment initiatives across the organization. The role focuses on planning and executing risk-based IT audits covering technology infrastructure, applications, cloud environments, IT operations, and technology governance. Key responsibilities include: • Planning and executing comprehensive risk-based IT audits across technology infrastructure, applications, cloud environments, IT operations, and governance frameworks • Assessing IT general controls, application controls, access management, change management, and incident management processes • Evaluating cybersecurity, information security, vulnerability management, business continuity, and disaster recovery capabilities • Assessing data governance, data integrity, system interfaces, and controls over critical systems and information assets • Conducting risk assessments, defining audit procedures, performing walkthroughs and control testing, and maintaining audit documentation • Developing clear audit findings, identifying root causes and impacts, and providing practical recommendations to strengthen IT controls and mitigate technology risks • Collaborating with Technology, Information Security, Risk, Compliance, and business stakeholders to validate findings and monitor remediation efforts GoTo Group operates a diverse digital ecosystem including mobility (Gojek), delivery, payments, financial services (GoTo Financial, GoPay, GoPayLater), and e-commerce (Tokopedia), serving millions of users and driver partners across Southeast Asia. Requirements: • 6–8 years of experience in IT audit, technology risk, information security audit, internal audit, or related assurance functions • Strong experience in IT general controls, application controls, cybersecurity, IT operations, cloud technology, data governance, and technology risk management • Strong knowledge of risk-based IT audit methodologies and IT control frameworks (COBIT, ISO 27001, NIST, or similar) • CISA (Certified Information Systems Auditor) certification is mandatory • Familiarity with Indonesian technology and digital regulations, including Komdigi requirements, is highly preferred • Experience working with technology regulators, government institutions, or regulated technology environments is highly preferred • Strong analytical, communication, stakeholder management, and project management skills with ability to translate technical risks into clear business implications

Similar roles