IT Auditor Lead

Jakarta, Indonesia | Risk & Compliance | Full-time | Hybrid

Apply

Mekari is Indonesia's no. 1 Software-as-a-Service (SaaS) company. With our ecosystem of software solutions—including Mekari Jurnal, Mekari Talenta, Mekari Qontak, and Mekari Flex, we aim to facilitate entrepreneurs and leaders as they accelerate the digital transformation of their businesses.

In our 10+ years of journey we have reached over 3 Million platform users, and we're not planning to stop any time soon. We need more people like you: builders and owners with calculated ambition who are ready to #ElevateThroughImpact and raise Indonesia's software standard.

Key Responsibilities

  • Maintain the quarterly IT internal audit plan, ensuring alignment with key risks and organizational priorities.
  • Lead end-to-end IT audit engagements, from planning, fieldwork, to reporting.
  • Identify and assess IT-related risks, including cybersecurity, data privacy, operational technology risks, and emerging tech risks.
  • Evaluate the effectiveness of IT controls across applications, infrastructure, cybersecurity, cloud environments, and data governance.
  • Review system configurations, access controls, change management, and IT operations for potential risks and control gaps.
  • Conduct annual audits for compliance with ISO 27001 and other relevant standards or regulations, as well as special audits (e.g., investigations, security incidents, and ad hoc assignments).
  • Drive and monitor the implementation of IT audit recommendations across relevant teams (Engineering, Product, InfoSec, IT Ops).
  • Develop and maintain audit reports, issue logs, dashboards, and management updates on IT control health.
  • Provide early warning indicators on emerging IT risks, system vulnerabilities, or deviations from expected controls.
  • Support awareness initiatives related to IT governance, cybersecurity, and internal controls.

Requirements:

  • 3–6 years of experience in IT Audit, IT Risk, Cybersecurity, or Technology Assurance.
  • Strong understanding of IT general controls (ITGC), application controls, cloud environments, cybersecurity frameworks, and technology risk assessment.
  • Familiarity with standards such as ISO 27001, SOC 2, NIST, COBIT, or similar frameworks.
  • Strong technical foundation with familiarity in SQL, JavaScript, and Python for data analysis or system review.
  • Relevant certifications such as CISA, CRISC, ISO 27001 Lead Auditor/Implementer are a strong plus.
  • Strong communication, coordination, interviewing, and issue-challenging skills when dealing with technical teams.
  • Highly detail-oriented, analytical, and comfortable managing multiple concurrent audit or review activities.
Our team will review your application and will be in touch if your application is shortlisted to the next stage. If you do not hear from us in 30 days, we will keep your resume on file in case a relevant opportunity opens up.
 
Don't forget to check our Recruitment FAQ at bit.ly/FAQMekariHiringENG or bit.ly/FAQMekariHiringINA to find the answers to commonly asked questions regarding our recruitment process.
 
We wish you the best. Hope to see you around soon!