
Security Compliance Engineer
Posted Jul 18

Posted Jul 18
This is a fully remote position, open to applicants in India.
• Serve as the main technical liaison for IRAP assessments as well as commercial compliance and regulatory inquiries.
• Articulate the Dashboard infrastructure, system architecture, data flows, and security controls to assessors and regulators.
• Collaborate with global Compliance and Security teams to gather evidence, documentation, and responses necessary for IRAP.
• Work alongside Engineering Teams to confirm and implement necessary controls.
• Monitor updates to ASD ISM, IRAP guidance, the Essential Eight, Australian government cloud/security expectations, and related privacy or critical infrastructure requirements; evaluate the impact on Dashboard services.
• Contribute to audit preparedness, remediation initiatives, and ongoing compliance enhancements.
• Maintain mappings of IRAP controls against Cisco CCF controls, including applicability, implementation status, ownership, evidence sources, and compensating controls.
• Oversee the complete IRAP assessment lifecycle, which includes scope definition, assessor interaction, evidence collection, assessment logistics, report evaluation, and tracking of post-assessment remediation.
• Convert IRAP findings into prioritized engineering requirements, risk treatment strategies, exceptions, and executive-level status updates.
• Examine IRAP assessment reports, completion letters, and customer-facing assurance documents for technical accuracy and coherence.
• Bachelor’s degree in Computer Science, Engineering, Information Security, or a related field, or equivalent practical experience.
• 3-7 years of experience in security engineering, cloud/infrastructure engineering, security assurance, or technical compliance.
• Solid understanding of cloud infrastructure, networking, system architecture, identity and access management, encryption, logging, vulnerability management, and the implementation of security controls.
• Experience in supporting security assessments or compliance frameworks such as IRAP, ASD ISM, ISO 27001, SOC 2, PCI DSS, FedRAMP, or similar.
• Capability to interpret security control requirements and translate them into technical evidence, architectural narratives, remediation plans, and engineering specifications.
• Proficient in clearly articulating complex technical and compliance subjects to engineers, assessors, customers, auditors, and non-technical stakeholders.
• Experience in coordinating cross-functional efforts with Security, Compliance, Engineering, Legal, Product, and customer-facing teams.
• Familiarity with ASD ISM, IRAP assessment procedures, the Essential Eight, or Australian government cloud security expectations.
• Background in cloud compliance programs for government or regulated clientele.
• Experience working with global or multinational technology firms.
• Skilled in creating or maintaining system security plans, control matrices, architecture diagrams, data flow diagrams, or customer-facing security documentation.
• Relevant certifications such as CISSP, CCSP, CISM, CISA, ISO 27001 Lead Implementer/Auditor, AWS/Azure/GCP security certifications, or equivalent.
• Flexible work arrangements
• Professional development opportunities
Lime
Threatscape
GFT Technologies
BeyondTrust
Get handpicked remote jobs straight to your inbox weekly.