
Internal Audit Manager
- ISO 27001
- Vulnerability Management
- Penetration Testing
- IAM
- Change Management
- Disaster Recovery
- Risk Management
- Regulatory Compliance
- AML
- PCI DSS
- CISA
- CRISC
- CISM
- CFE
- SQL
- Python
We are looking for an experiencedInternal Audit Managerwith strong expertise inIT Audit, Payment Systems, and Technology Riskto join our team.
In this role, you will lead risk-based internal audit activities across our technology infrastructure, payment systems, cybersecurity, and payment operations. You will work closely with business, technology, risk, and compliance stakeholders to identify key risks, assess the effectiveness of controls, and provide practical recommendations that strengthen our overall control environment.
You will also play an important role in ensuring that our technology and payment operations remain aligned with applicableBank Indonesia (BI) regulations and industry standards, while supporting the organization in maintaining secure, resilient, and reliable payment services.
About the Job:
Lead IT & Technology Audits
- Develop and execute an annualIT Risk-Based Audit Plan covering critical technology and payment infrastructure.
- Lead audits across core payment systems, cloud infrastructure, databases, networks, APIs, and payment gateway integrations.
- Assess the effectiveness of information security controls, includingISO 27001/ISMS, vulnerability management, penetration testing, Identity & Access Management (IAM), and cyber resilience.
- ReviewSystem Development Life Cycle (SDLC) practices, security testing, and change management controls to ensure appropriate governance before production deployment.
- Evaluate and testBusiness Continuity Plans (BCP) andDisaster Recovery Plans (DRP) to assess the resilience and availability of critical payment services.
Audit Payment Systems & Operations
- Conduct end-to-end audits of payment transaction flows, includingissuing, acquiring, switching, clearing, and settlement.
- Assess the effectiveness of fund management processes, includingsource-of-funds administration, floating fund reconciliation, and settlement to merchants and business partners.
- Review payment operations to identify control gaps, operational risks, and opportunities to improve process effectiveness.
- Evaluatefraud prevention and detection controls, including Fraud Detection Systems (FDS), transaction risk management, and dispute/chargeback management.
Strengthen Regulatory Compliance & Governance
- Assess compliance of technology and payment operations with applicableBank Indonesia regulations and requirements, including those relating to Payment Service Providers (PJP), the National Payment System, IT risk management, AML/CFT (APU-PPT), and personal data protection.
- Support regulatory and certification audits, includingBank Indonesia examinations, ISO 27001, and PCI-DSS assessments.
- Translate regulatory and audit requirements into practical control improvements across the organization.
Deliver High-Impact Audit Insights
- Lead the end-to-end audit process, fromrisk assessment and audit planning through fieldwork, reporting, and follow-up.
- Prepare clear, objective, and actionable audit reports highlighting key risks, root causes, and recommendations.
- Present significant audit findings and insights toSenior Management, the Board of Directors, and the Audit Committee.
- Work collaboratively with relevant stakeholders to agree onCorrective Action Plans (CAPs) and monitor remediation progress.
- Use data-driven audit techniques to analyze transaction data, identify anomalies, and enhance audit effectiveness.
About You :
- Bachelor's degree inInformation Systems, Computer Science, Information Technology, Accounting Information Systems, or a related field.
- Minimum of 5 years of work experience in IT Audit, Payment Systems Audit, IT Governance, GRC, or a related field.
- 2โ3 years of experience at Manager, Assistant Manager, or Lead Auditor level, preferably within a Payment Service Provider (PJP), fintech, banking, switching, or payment gateway environment.
- Hands-on experience in auditingpayment systems, technology infrastructure, cybersecurity, and/or technology risk.
- Experience leading or participating inBank Indonesia regulatory examinations andISO 27001 / PCI-DSS certification audits is highly preferred.
- Certified ISO 27001:2022 Information Security Management Systems is required.
- Deep understanding ofpayment system architecture and operations, particularly PJP Category 1, including electronic money, fund transfers, payment gateways, reconciliation, and settlement.
- Strong understanding of applicableBank Indonesia regulations related to payment system operations, cybersecurity and resilience, IT risk management, and AML/CFT.
- Strong communication and stakeholder management skills, with the confidence to engage with both technical and business teams.
- Excellent written and verbal communication skills both in Bahasa Indonesia and English
- Comfortable working in a fast-paced and evolving environment where technology and payment processes continuously change.
- Additional certifications such asCISA (Certified Information Systems Auditor),CRISC, CISM, CIA/QIA, or CFEare a plus.
- Familiarity with programming languages and automation tools (e.g., SQL, Python) for data analytics and audit automation
#LI-DI1
Internal Audit Manager ยท Kredivo Group