
Senior Security Engineer II – IRAP Program Lead
Posted Aug 5

Posted Aug 5
This is a fully remote position, open to applicants in United States.
• Take ownership of the IRAP (Australia) program strategy and its execution, encompassing assessment coordination, remediation efforts, and the maintenance of authorization.
• Lead the strategy and implementation of the ISMAP (Japan) program, which includes registration, certification assessments, and tracking registry status.
• Collaborate with ASD-endorsed IRAP assessors, JASA-registered ISMAP assessors, government entities, and compliance authorities.
• Develop and manage the documentation for IRAP System Security Plans and ISMAP Management Standards.
• Align Smartsheet architecture with the control requirements of IRAP/ISM and ISMAP.
• Oversee continuous monitoring, conduct quarterly updates, and maintain evidence of sustained compliance.
• Direct the management of Plans of Action and Milestones (POA&M) and remediation efforts, including identifying findings, setting timelines, and collecting evidence.
• Coordinate substantial changes and system modifications alongside product and engineering teams.
• Create evidence libraries, audit trails, and ensure traceability from controls to implementation.
• Streamline compliance workflows and enhance the efficiency of evidence collection.
• A minimum of 5 years of practical experience with government security compliance frameworks, including direct involvement in at least two of IRAP, ISMAP, FedRAMP, or similar national frameworks.
• In-depth understanding of Australia’s Information Security Manual (ISM) control framework.
• Familiarity with the Essential Eight Maturity Model.
• Knowledge of the Protective Security Policy Framework (PSPF).
• Extensive knowledge of Japan’s ISMAP framework and its approximately 1200 control requirements.
• Awareness of the ISMAP-LIU variant and the context of Japanese government procurement.
• Experience in coordinating assessments across various regulatory environments.
• Proven ability to address assessment findings and convert recommendations into actionable remediation plans.
• Understanding of the compliance contexts in Australia and Japan.
• Proficient in AWS, Azure, or GCP platforms.
• Knowledge of cloud security controls, infrastructure-as-code, logging, incident response, and architectures relevant to compliance.
• Comprehension of continuous monitoring and the evolving requirements of frameworks.
• Exceptional skills in compliance documentation and communication.
• Must be legally authorized to work in the U.S. on a continuous basis.
• Bachelor’s degree in Computer Science, Engineering, or a related discipline, or equivalent practical experience.
• Nice-to-have: bilingual or multilingual skills.
• Nice-to-have: certifications such as CISSP, CISM, CISA, or ISO 27001 Lead Auditor.
• Nice-to-have: experience with FedRAMP, CMMC, or other national programs.
• Nice-to-have: background in cloud service provider compliance or SaaS security within APAC markets.
• Employer-subsidized medical, vision, and dental insurance for full-time employees.
• 401k Match: 50% of your contribution up to the first 6% of your eligible pay.
• Monthly stipend to enhance your work and productivity.
• Flexible Time Away Program.
• Sick Time Off.
• Employer-sponsored life insurance coverage.
• Short-term disability insurance.
• Long-term disability insurance.
• 12 paid holidays each year.
• Up to 24 weeks of Parental Leave.
• A personal paid Volunteer Day.
• Opportunities for professional growth and development.
• Access to Udemy online courses.
• Membership for counseling services.
• Discounts at local retailers.
• Personal Smartsheet account.
• Teleworking options available from any registered location in the U.S. (dependent on role).
• Competitive incentive opportunities in line with market standards.
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.