Overview
About the Role
Full job description
About the Role At GoTo, our technology ecosystem operates at immense scale and complexity, supporting critical platforms, systems, and data across the organization. As the Internal Audit Lead (IT), you will lead the end-to-end execution of risk-based IT audits, assessing technology processes, IT controls, cybersecurity, data management, and system environments. Working closely with technology, security, risk, and business stakeholders, you will identify control gaps and technology risks, evaluate compliance with relevant regulatory requirements, and translate audit findings into practical recommendations that strengthen technology governance, security, and resilience. This role offers broad exposure to complex technology environments and requires strong IT audit expertise, analytical thinking, and stakeholder management skills.
IT & Risk-Based Audit Execution : Plan and execute risk-based IT audits covering technology infrastructure, applications, cloud environments, IT operations, and technology governance. IT Controls Assessment : Assess IT general controls, application controls, access management, change management, incident management, and other key technology processes. Cybersecurity & Technology Risk : Evaluate cybersecurity, information security, vulnerability management, business continuity, disaster recovery, and other technology-related risks. Data & System Audit : Assess data governance, data integrity, system interfaces, data flows, and controls over critical systems and information assets. Audit Planning & Fieldwork : Conduct risk assessments, define audit procedures, perform walkthroughs and control testing, analyze evidence, and maintain audit documentation. Reporting & Recommendations : Develop clear audit findings, identify root causes and impacts, and provide practical recommendations to strengthen IT controls and mitigate technology risks. Stakeholder & Remediation Management : Work with Technology, Information Security, Risk, Compliance, and business stakeholders to validate findings and monitor remediation.
6–8 years of experience in IT audit, technology risk, information security audit, internal audit, or related assurance functions. Strong experience in IT general controls, application controls, cybersecurity, IT operations, cloud technology, data governance, and technology risk management. Strong knowledge of risk-based IT audit methodologies and IT control frameworks, with familiarity with COBIT, ISO 27001, NIST, or similar frameworks. CISA (Certified Information Systems Auditor) certification is mandatory. Familiarity with Indonesian technology and digital regulations, including relevant Komdigi requirements and regulatory expectations, is highly preferred. Experience working with technology regulators, government institutions, or regulated technology environments is highly preferred. Strong analytical, communication, stakeholder management, and project management skills, with the ability to translate technical risks into clear business implications.
Tips for this job
Practical JobOpportunity guidance. These tips do not replace official rules or create new eligibility requirements.
- Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
- Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
- Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
- Apply through the original employer or official recruitment destination shown on this page.
Verification notes
laptop-ats-crawler v3
JobOpportunity is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.
Apply through JobOpportunity →Browse current JobOpportunity listings from Gotogroup (lever) →