Senior Security Engineer II – IRAP Program Lead

Job not on LinkedIn

🔥 0 minutes ago

🇺🇸 United States – Remote

💵 $175k - $245k / year

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

🦅 H1B Visa Sponsor

info
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Smartsheet

Smartsheet

1001 - 5000 employees

Founded 2005

💼 Consulting

🏥 Healthcare

📣 Marketing

Consulting • Healthcare • Marketing

Smartsheet is a platform designed to manage projects, automate workflows, and build solutions at scale. It offers a wide range of features including automation, team collaboration, dashboards and reporting, and integrations, allowing businesses to streamline their operations. The platform caters to diverse use cases such as project management, IT portfolio management, marketing management, and more, serving various industries including government, finance, and healthcare. Smartsheet also emphasizes security and data protection, ensuring users' data privacy. Additionally, it offers professional services like consulting, training, and implementation support to maximize the platform's capabilities.

📋 Description

• Own IRAP (Australia) program strategy and execution, including assessment coordination, remediation, and authorization maintenance • Own ISMAP (Japan) program strategy and execution, including registration, certification assessment, and registry status • Coordinate with ASD-endorsed IRAP assessors, JASA-registered ISMAP assessors, government agencies, and compliance authorities • Design and maintain IRAP System Security Plans and ISMAP Management Standards documentation • Map Smartsheet architecture to IRAP/ISM and ISMAP control requirements • Manage continuous monitoring, quarterly updates, and evidence of ongoing compliance • Lead POA&M and remediation management, including findings, timelines, and evidence collection • Coordinate significant changes and system modifications with product and engineering teams • Build evidence libraries, audit trails, and control-to-implementation traceability • Automate compliance workflows and improve evidence collection efficiency

🎯 Requirements

• 5+ years of hands-on experience with government security compliance frameworks, with direct involvement in at least two of IRAP, ISMAP, FedRAMP, or equivalent national frameworks • Deep knowledge of Australia’s Information Security Manual (ISM) control framework • Knowledge of the Essential Eight Maturity Model • Knowledge of the Protective Security Policy Framework (PSPF) • Deep knowledge of Japan’s ISMAP framework and approximately 1200 control requirements • Understanding of ISMAP-LIU variant and Japanese government procurement context • Experience coordinating assessments in multiple regulatory environments • Experience working through assessment findings and translating recommendations into remediation plans • Familiarity with Australian and Japanese government compliance contexts • Working knowledge of AWS, Azure, or GCP • Knowledge of cloud security controls, infrastructure-as-code, logging, incident response, and compliance-relevant architectures • Understanding of continuous monitoring and evolving framework requirements • Excellent compliance documentation and communication skills • Legally eligible to work in the U.S. on an ongoing basis • Bachelor’s degree in Computer Science, Engineering, or a related field, or equivalent practical experience • Nice-to-have: bilingual or multilingual capability • Nice-to-have: CISSP, CISM, CISA, or ISO 27001 Lead Auditor certification • Nice-to-have: experience with FedRAMP, CMMC, or other national programs • Nice-to-have: cloud service provider compliance or SaaS security background in APAC markets

🏖️ Benefits

• Employer subsidized medical/vision and dental coverage for full-time employees • 401k Match: 50% of your contribution up to the first 6% of your eligible pay • Monthly stipend to support your work and productivity • Flexible Time Away Program • Sick Time Off • Employer-sponsored life insurance • Short-term disability plan • Long-term disability plan • 12 paid holidays per year • Up to 24 weeks of Parental Leave • Personal paid Volunteer Day • Professional growth and development opportunities • Access to Udemy online courses • Counseling membership • Local retail discounts • Personal Smartsheet account • Teleworking options from any registered location in the U.S. (role specific) • Market competitive incentive opportunity

Apply Now

Similar Jobs

🔥 20 minutes ago

Rocket Mortgage

10,000+ employees

💸 Finance

💳 Fintech

🏠 Real Estate

Residential security specialist protecting Rocket Companies executives, private residences, and families. Coordinating executive protection assignments and mitigating physical security risks.

🔥 46 minutes ago

SmarterDx

11 - 50

🏥 Healthcare

💼 Consulting

⚖️ Legal

Senior Security Engineer securing SmarterDx’s clinical AI platform and AWS cloud remotely within the U.S. Building detections, investigating alerts, and improving cloud security operations, automation, and incident response.

🔥 49 minutes ago

AssemblyAI

51 - 200

💼 Consulting

📣 Marketing

📦 Logistics

Senior Security Engineer securing AssemblyAI’s Voice AI models, infrastructure, and compliance program. Owning application security, vulnerability management, audits, and security operations.

🔥 1 hour ago

CrowdStrike

5001 - 10000

🔒 Cybersecurity

☁️ SaaS

🤖 Artificial Intelligence

Security researcher tracking South Asia, Latin America, and North Africa cyber threat actors for CrowdStrike’s cybersecurity intelligence platform. Conducting advanced OSINT and producing contextualized threat intelligence reports.

🗣️🇮🇳 Hindi Required

🔥 3 hours ago

Keeper Security, Inc.

501 - 1000

🔒 Cybersecurity

☁️ SaaS

🏢 Enterprise

Senior Datadog engineer scaling detection engineering and security observability for Keeper Security’s cybersecurity platform. Building SIEM rules, telemetry pipelines, dashboards, and monitoring across AWS environments.