Skip to main content
Smartsheet

Sr. Security Engineer II – IRAP Program Lead

RemoteUnited States only
Published
Role
Security
Experience
Senior
Employment
Full-time
Company size
Enterprise
$175k–$245k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Senior security compliance engineer to lead IRAP and ISMAP programs end-to-end for APAC government markets. Needs 5+ years with government security compliance frameworks, deep IRAP/ISM and ISMAP expertise, cloud security knowledge, and ongoing U.S. work eligibility.

Core skills

IRAP/ISMAP/FedRAMPCloud Security

Required skills

ISMEssential Eight Maturity ModelPSPFISO/IEC 27001ISMAP-LIUAWSAzureGCPInfrastructure as Code

Optional skills

CISSPCISMCISAISO 27001 Lead AuditorFedRAMPCMMC

Optional languages

EnglishJapanese

What you'll do

  • Own IRAP (Australia) program strategy and execution: Lead the overall roadmap for obtaining and maintaining IRAP authorizations, including assessment coordination, remediation, and authorization maintenance.
  • Own ISMAP (Japan) program strategy and execution: Lead registration and compliance for Japan's government cloud certification program, managing the certification assessment process and maintaining registry status.
  • Coordinate with regional assessors and government agencies: Manage relationships with ASD-endorsed IRAP assessors (Australia) and JASA-registered ISMAP assessors (Japan).
  • Serve as the primary contact for government agencies and compliance authorities in both regions.
  • Design and maintain IRAP System Security Plans (SSP) and ISMAP Management Standards documentation: Develop comprehensive compliance documentation that maps Smartsheet's architecture to both IRAP (ISM control framework) and ISMAP (~1200 controls) requirements.
  • Manage continuous monitoring and quarterly updates: Operate continuous assurance programs for both frameworks.
  • Track ISM quarterly updates (Australia) and ISMAP framework evolution (Japan).
  • Maintain evidence of ongoing compliance.
  • Lead POA&M and remediation management: Identify, prioritize, track, and remediate findings from both IRAP and ISMAP assessments.
  • Manage timelines and evidence collection for remediation closure.
  • Coordinate significant changes and system modifications: Work with product and engineering teams to assess and obtain approval for changes that impact IRAP authorization or ISMAP registration status.
  • Build evidence libraries and assessment readiness: Design processes for collecting, organizing, and maintaining compliance evidence for both frameworks.
  • Ensure audit trails and traceability from controls to implementation.
  • Drive automation and efficiency: Identify opportunities to automate compliance workflows, reduce manual effort, and improve evidence collection efficiency while maintaining rigor and auditability across both programs.

What they require

  • 5+ years of hands-on experience with government security compliance frameworks, with direct involvement in at least two of: IRAP (Australia), ISMAP (Japan), FedRAMP (US), or equivalent national frameworks.
  • Deep knowledge of IRAP and ISM: Fluency with Information Security Manual (ISM) control framework, Essential Eight Maturity Model, Protective Security Policy Framework (PSPF), and how controls map to cloud architecture.
  • Deep knowledge of ISMAP: Understanding of ISMAP framework (based on ISO/IEC 27001), ~1200 control requirements, ISMAP-LIU (Low-Impact-Use) variant, and Japanese government procurement context.
  • Proven experience coordinating with regional assessors: You've managed assessments in multiple regulatory environments, worked through assessment findings, and translated recommendations into remediation plans.
  • Understanding of APAC government compliance contexts: Familiarity with how Australian and Japanese government agencies evaluate security, make risk-based decisions, and maintain ongoing compliance obligations.
  • Technical foundation in cloud architecture and security: Working knowledge of AWS/Azure/GCP, cloud security controls, infrastructure-as-code, logging, incident response, and compliance-relevant architectures.
  • Experience with continuous monitoring and evolving framework requirements: Understanding of how to maintain compliance in dynamic regulatory environments where frameworks and standards update regularly.
  • Excellent documentation and communication skills: Ability to write clear compliance documentation, develop control narratives, and communicate technical concepts to both Australian and Japanese government audiences.
  • Legally eligible to work in the U.S. on an ongoing basis
  • A degree in Computer Science, Engineering, or a related field or equivalent practical experience
  • Preferred: Bilingual or multilingual capability (English + Japanese, or English + Australian government context familiarity).
  • Preferred: Professional security certifications: CISSP, CISM, CISA, ISO 27001 Lead Auditor, or equivalent.
  • Preferred: Experience with multiple government compliance frameworks (FedRAMP, CMMC, or other national programs).
  • Preferred: Background in cloud service provider compliance or SaaS security in APAC markets.

Benefits

  • Employer subsidized medical/vision and dental coverage for full-time employees
  • 401k Match to help you save for your future (50% of your contribution up to the first 6% of your eligible pay)
  • Monthly stipend to support your work and productivity
  • Flexible Time Away Program, plus Sick Time Off
  • US employees are automatically covered under Smartsheet-sponsored life insurance, short-term, and long-term disability plans
  • US employees receive 12 paid holidays per year
  • Up to 24 weeks of Parental Leave
  • Personal paid Volunteer Day to support our community
  • Opportunities for professional growth and development including access to Udemy online courses
  • Company Funded Perks, including a counseling membership, local retail discounts, and your own personal Smartsheet account
  • Teleworking options from any registered location in the U.S. (role specific)
  • Eligible for a market competitive incentive opportunity
SoftwareEnterprisesmartsheet.com

Details

Posting languageEnglish
Apply routeGreenhouse
$175k–$245k/yr