About the RoleAt GoTo, our business operates at immense scale, speed, and complexity across a technology-driven ecosystem. As the Internal Audit Lead, you will lead the end-to-end execution of risk-based audits, assessing operational processes, internal controls, and technology-enabled risks across the organization. Working closely with business and technology stakeholders, you will identify control gaps, evaluate risk exposure, and translate audit findings into practical recommendations that strengthen governance and operational resilience. This role offers broad exposure to complex business environments and requires strong technical audit expertise, stakeholder management, and the ability to deliver high-quality, actionable audit insights.
What You Will Do
Risk-Based Audit Execution: Plan and execute risk-based audits across payment systems and processes, covering areas such as payment processing, transaction lifecycle, reconciliation, settlement, refunds, chargebacks, and payment operations.
Process & Control Assessment: Assess end-to-end business processes to identify control gaps, operational inefficiencies, leakage points, and potential fraud risks, and evaluate the adequacy and effectiveness of existing controls.
Technology & Automated Control Audits: Evaluate application controls, automated controls, system integrations, data flows, access controls, and technology-enabled processes supporting payment systems.
Audit Planning & Fieldwork: Conduct risk assessments, define audit scope and testing procedures, perform fieldwork and control testing, analyze evidence, and ensure audit working papers meet established audit methodology and quality standards.
Audit Reporting & Recommendations: Develop clear and concise audit findings, identify root causes and potential business impacts, and provide practical recommendations to strengthen payment controls and mitigate identified risks.
Stakeholder Management & Remediation: Partner with process owners and business stakeholders to validate audit findings, communicate key risks, and monitor management action plans through to timely remediation.
Audit Quality & Continuous Improvement: Contribute to enhancing audit methodologies, data analytics, control testing approaches, and continuous monitoring techniques for payment-related risks.
What You Will Need
6–8 years of professional experience in internal audit, IT audit, operational audit, risk management, internal controls, or related assurance functions, with experience in payment systems or technology-enabled financial services highly preferred.
Strong experience in payment systems, payment processing, transaction flows, reconciliation, settlement, digital payments, fintech, or other technology-driven financial ecosystems is highly preferred.
Strong knowledge of IT audit, risk-based audit methodologies, internal control frameworks, application and automated controls, system integrations, and technology risk.
Familiarity with Bank Indonesia (BI) regulations, regulatory requirements, and supervisory expectations, particularly those relevant to payment systems, technology risk, information security, and internal controls, is highly preferred.
CISA (Certified Information Systems Auditor) certification is mandatory, given the technology-focused audit scope and regulatory exposure.
Strong analytical and problem-solving skills, with the ability to assess complex payment processes, identify control weaknesses, perform root-cause analysis, and develop practical recommendations.
Strong written and verbal English communication skills, with the ability to clearly communicate audit findings and prepare concise audit reports and documentation.
Strong stakeholder and project management capabilities, with the ability to work effectively with business, technology, finance, risk, and regulatory stakeholders under tight timelines.
About the Team
Our team, GoTo Internal Audit, is a growing group of dedicated auditors with deepening expertise in our respective areas. As part of GoTo’s Internal Audit function, we support the Board’s oversight role and provide guidance to Management on operational efficiency, risk management, and asset protection across GoTo, Gojek, and GoTo Financial.
Our goal is to be a trusted business partner by delivering high-quality audits that help improve operational excellence through stronger controls and governance practices, while offering valuable insights on the transparency of performance in relation to business objectives. As a publicly listed company, we also play a key role in safeguarding stakeholders’ interests, ensuring asset protection, and maintaining regulatory compliance.
About GoTo Group
GoTo is the largest digital ecosystem in Indonesia. GoTo's mission is to 'empower progress' by offering technology infrastructure and solutions that help everyone to access and thrive in the digital economy.
The GoTo ecosystem provides a wide range of services, including mobility, delivery, payments, financial services, and technology solutions for merchants. The ecosystem also provides e-commerce services through Tokopedia and banking services through its partnership with Bank Jago.
About Gojek
Gojek is Southeast Asia’s leading on-demand platform and pioneer of the multi-service ecosystem with over 2.5 million driver partners across the regions offering a wide range of services such as transportation, food delivery, logistics and more. With its mission to create impact at scale, Gojek is committed to resolving consumer problems and raising standards of living by connecting consumers to the best providers of goods and services in the market.
About GoTo Financial
GoTo Financial accelerates financial inclusion through its leading financial services and merchants solutions. Its consumer services include GoPay and GoPayLater and serve businesses of all sizes through Midtrans, Moka, GoBiz Plus, GoBiz, and Selly. With its trusted and inclusive ecosystem of products, GoTo Financial is open to new growth opportunities and aims to empower everyone to Make It Happen, Make It Together, Make It Last.
GoTo and its business units, including Gojek and GoToFinancial ("GoTo") only post job opportunities on our official channels on our respective company websites and on LinkedIn. GoTo is not liable for any job postings or job offers that did not originate from us. You should conduct your own due diligence to prevent being victims of any fake job scams, if they did not originate from GoTo's official recruitment channels.
#LI-ONSITE