Internal Audit Manager
Jakarta, Indonesia
We are looking for an experienced Internal Audit Managerwith strong expertise in IT Audit, Payment Systems, and Technology Riskto join our team.
In this role, you will lead risk-based internal audit activities across our technology infrastructure, payment systems, cybersecurity, and payment operations. You will work closely with business, technology, risk, and compliance stakeholders to identify key risks, assess the effectiveness of controls, and provide practical recommendations that strengthen our overall control environment.
You will also play an important role in ensuring that our technology and payment operations remain aligned with applicable Bank Indonesia (BI) regulations and industry standards, while supporting the organization in maintaining secure, resilient, and reliable payment services.
About the Job:
Lead IT & Technology Audits
- Develop and execute an annual IT Risk-Based Audit Plan covering critical technology and payment infrastructure.
- Lead audits across core payment systems, cloud infrastructure, databases, networks, APIs, and payment gateway integrations.
- Assess the effectiveness of information security controls, including ISO 27001/ISMS, vulnerability management, penetration testing, Identity & Access Management (IAM), and cyber resilience.
- Review System Development Life Cycle (SDLC) practices, security testing, and change management controls to ensure appropriate governance before production deployment.
- Evaluate and test Business Continuity Plans (BCP) and Disaster Recovery Plans (DRP) to assess the resilience and availability of critical payment services.
Audit Payment Systems & Operations
- Conduct end-to-end audits of payment transaction flows, including issuing, acquiring, switching, clearing, and settlement.
- Assess the effectiveness of fund management processes, including source-of-funds administration, floating fund reconciliation, and settlement to merchants and business partners.
- Review payment operations to identify control gaps, operational risks, and opportunities to improve process effectiveness.
- Evaluate fraud prevention and detection controls, including Fraud Detection Systems (FDS), transaction risk management, and dispute/chargeback management.
Strengthen Regulatory Compliance & Governance
- Assess compliance of technology and payment operations with applicable Bank Indonesia regulations and requirements, including those relating to Payment Service Providers (PJP), the National Payment System, IT risk management, AML/CFT (APU-PPT), and personal data protection.
- Support regulatory and certification audits, including Bank Indonesia examinations, ISO 27001, and PCI-DSS assessments.
- Translate regulatory and audit requirements into practical control improvements across the organization.
Deliver High-Impact Audit Insights
- Lead the end-to-end audit process, from risk assessment and audit planning through fieldwork, reporting, and follow-up.
- Prepare clear, objective, and actionable audit reports highlighting key risks, root causes, and recommendations.
- Present significant audit findings and insights to Senior Management, the Board of Directors, and the Audit Committee.
- Work collaboratively with relevant stakeholders to agree on Corrective Action Plans (CAPs) and monitor remediation progress.
- Use data-driven audit techniques to analyze transaction data, identify anomalies, and enhance audit effectiveness.
About You :
- Bachelor's degree in Information Systems, Computer Science, Information Technology, Accounting Information Systems, or a related field.
- Minimum of 5 years of work experience in IT Audit, Payment Systems Audit, IT Governance, GRC, or a related field.
- 2–3 years of experience at Manager, Assistant Manager, or Lead Auditor level, preferably within a Payment Service Provider (PJP), fintech, banking, switching, or payment gateway environment.
- Hands-on experience in auditing payment systems, technology infrastructure, cybersecurity, and/or technology risk.
- Experience leading or participating in Bank Indonesia regulatory examinations and ISO 27001 / PCI-DSS certification audits is highly preferred.
- Certified ISO 27001:2022 Information Security Management Systems is required.
- Deep understanding of payment system architecture and operations, particularly PJP Category 1, including electronic money, fund transfers, payment gateways, reconciliation, and settlement.
- Strong understanding of applicable Bank Indonesia regulations related to payment system operations, cybersecurity and resilience, IT risk management, and AML/CFT.
- Strong communication and stakeholder management skills, with the confidence to engage with both technical and business teams.
- Excellent written and verbal communication skills both in Bahasa Indonesia and English
- Comfortable working in a fast-paced and evolving environment where technology and payment processes continuously change.
- Additional certifications such as CISA (Certified Information Systems Auditor), CRISC, CISM, CIA/QIA, or CFEare a plus.
- Familiarity with programming languages and automation tools (e.g., SQL, Python) for data analytics and audit automation
#LI-DI1