Internal IT Audit Officer
Indonesia Stock Exchange
- Jakarta Selatan
- Permanen
- kerja tetap
- Experience in IT Security and/or Cybersecurity-related roles (either standalone or embedded within audit responsibilities) is highly desirable.
- Holding professional certifications (e.g., CISA, CISM, CRISC, CISSP, ISO 27001 LA/LI) or having attended formal trainings in IT Audit, Information Security, or GRC is a strong advantage.
- Demonstrated passion and initiative in cybersecurity, such as participation in ethical hacking communities, cybersecurity blogs/research, or self-initiated security testing projects, is a plus.
- Strong understanding of IT audit principles, including fieldwork, sampling, and risk-based audit.
- Familiarity with information and cyber security standards such as ISO 27001, NIST Cybersecurity Framework, or similar.
- Understanding of System Development Life Cycle (SDLC) and Project Management methodologies (e.g., PMI, Agile/Scrum, Prince2).
- Knowledge of IT governance frameworks like COBIT and their application to risk and control environments.
- IT & Cybersecurity Audit:
- Ability to apply IT audit and cybersecurity knowledge in evaluating internal controls, identifying security gaps, and recommending risk mitigation strategies aligned with frameworks such as ISO 27001, NIST CSF, or COBIT.
- Comfortable working collaboratively with external parties, including regulators (e.g., OJK), external auditors, and third-party consultants during security reviews, audits, and control evaluations, as well as monitoring and facilitating timely follow-up on agreed corrective actions.
- Technical Tools:
- Interest or basic experience in using data analytics, scripting (e.g., Excel, SQL, Python), and modern technologies such as AI to support audit automation, big data analysis, and risk identification. Familiarity with tools like Power BI, Tableau, or AI-based solutions is a plus, but not mandatory.
- Familiarity or exposure to cybersecurity tools such as SIEM, vulnerability scanners, and penetration testing frameworks, particularly in the context of IT audit or control evaluation. Enthusiasm to deepen skills in this area is highly valued.
- Strong analytical and problem-solving skills
- Collaborative and team-oriented
- Excellent communication and reporting abilities
- Detail-oriented with root-cause focus
- Proactive, independent, and solution-driven
Kalibrr