Skip to content

Open nowPosted 12 days ago

Internal Audit Manager - IT

kredivo-group73 open roles

Where
Jakarta, Indonesia
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowInternal Audit Manager - ITkredivo-group · Jakarta, Indonesia
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on kredivo-group's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 12 days ago

The posting

We are looking for an experienced Internal Audit Manager with strong expertise in IT Audit, Payment Systems, and Technology Risk to join our team.

In this role, you will lead risk-based internal audit activities across our technology infrastructure, payment systems, cybersecurity, and payment operations. You will work closely with business, technology, risk, and compliance stakeholders to identify key risks, assess the effectiveness of controls, and provide practical recommendations that strengthen our overall control environment.

You will also play an important role in ensuring that our technology and payment operations remain aligned with applicable Bank Indonesia (BI) regulations and industry standards, while supporting the organization in maintaining secure, resilient, and reliable payment services.

About the Job:

Lead IT & Technology Audits

  • Develop and execute an annual IT Risk-Based Audit Plan covering critical technology and payment infrastructure.
  • Lead audits across core payment systems, cloud infrastructure, databases, networks, APIs, and payment gateway integrations.
  • Assess the effectiveness of information security controls, including ISO 27001/ISMS, vulnerability management, penetration testing, Identity & Access Management (IAM), and cyber resilience.
  • Review System Development Life Cycle (SDLC) practices, security testing, and change management controls to ensure appropriate governance before production deployment.
  • Evaluate and test Business Continuity Plans (BCP) and Disaster Recovery Plans (DRP) to assess the resilience and availability of critical payment services.

Audit Payment Systems & Operations

  • Conduct end-to-end audits of payment transaction flows, including issuing, acquiring, switching, clearing, and settlement.
  • Assess the effectiveness of fund management processes, including source-of-funds administration, floating fund reconciliation, and settlement to merchants and business partners.
  • Review payment operations to identify control gaps, operational risks, and opportunities to improve process effectiveness.
  • Evaluate fraud prevention and detection controls, including Fraud Detection Systems (FDS), transaction risk management, and dispute/chargeback management.

Strengthen Regulatory Compliance & Governance

  • Assess compliance of technology and payment operations with applicable Bank Indonesia regulations and requirements, including those relating to Payment Service Providers (PJP), the National Payment System, IT risk management, AML/CFT (APU-PPT), and personal data protection.
  • Support regulatory and certification audits, including Bank Indonesia examinations, ISO 27001, and PCI-DSS assessments.
  • Translate regulatory and audit requirements into practical control improvements across the organization.

Deliver High-Impact Audit Insights

  • Lead the end-to-end audit process, from risk assessment and audit planning through fieldwork, reporting, and follow-up.
  • Prepare clear, objective, and actionable audit reports highlighting key risks, root causes, and recommendations.
  • Present significant audit findings and insights to Senior Management, the Board of Directors, and the Audit Committee.
  • Work collaboratively with relevant stakeholders to agree on Corrective Action Plans (CAPs) and monitor remediation progress.
  • Use data-driven audit techniques to analyze transaction data, identify anomalies, and enhance audit effectiveness.

About You :

  • Bachelor's degree in Information Systems, Computer Science, Information Technology, Accounting Information Systems, or a related field.
  • Minimum of 5 years of work experience in IT Audit, Payment Systems Audit, IT Governance, GRC, or a related field.
  • 2–3 years of experience at Manager, Assistant Manager, or Lead Auditor level, preferably within a Payment Service Provider (PJP), fintech, banking, switching, or payment gateway environment.
  • Hands-on experience in auditing payment systems, technology infrastructure, cybersecurity, and/or technology risk.
  • Experience leading or participating in Bank Indonesia regulatory examinations and ISO 27001 / PCI-DSS certification audits is highly preferred.
  • Certified ISO 27001:2022 Information Security Management Systems is required.
  • Deep understanding of payment system architecture and operations, particularly PJP Category 1, including electronic money, fund transfers, payment gateways, reconciliation, and settlement.
  • Strong understanding of applicable Bank Indonesia regulations related to payment system operations, cybersecurity and resilience, IT risk management, and AML/CFT.
  • Strong communication and stakeholder management skills, with the confidence to engage with both technical and business teams.
  • Excellent written and verbal communication skills both in Bahasa Indonesia and English
  • Comfortable working in a fast-paced and evolving environment where technology and payment processes continuously change.
  • Additional certifications such as CISA (Certified Information Systems Auditor), CRISC, CISM, CIA/QIA, or CFE are a plus.
  • Familiarity with programming languages and automation tools (e.g., SQL, Python) for data analytics and audit automation

#LI-DI1

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against kredivo-group's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on kredivo-group's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    kredivo-group's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.