Smartsheet

Sr. Security Engineer II - IRAP Program Lead (Remote Eligible)

Smartsheet$175K — $245K *
US-AnywhereRemote in United States
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience with government security compliance frameworks, particularly IRAP and ISMAP.
  • In-depth understanding of Australia's Information Security Manual (ISM) and its control frameworks.
  • Strong knowledge of ISMAP framework and its specific requirements.
  • Experience coordinating with assessors across different regulatory environments.
  • Familiarity with APAC government compliance and risk evaluation processes.
  • Technical background in cloud platforms like AWS, Azure, or GCP, focusing on security controls.
  • Excellent documentation and verbal communication skills, able to convey complex information to diverse audiences.

Responsibilities

  • Lead the strategy and execution of the IRAP program in Australia.
  • Manage ISMAP program strategy and compliance for Japan's government certification.
  • Serve as the primary contact for assessors and government agencies in both regions.
  • Develop and maintain security documentation to ensure compliance with IRAP and ISMAP.
  • Implement continuous monitoring programs, tracking updates and compliance evidence.
  • Identify, prioritize, and remediate compliance findings from assessments.
  • Collaborate with product teams on changes affecting compliance status.

Benefits

  • Employer-subsidized medical, vision, and dental coverage for full-time employees.
  • 401k Match to enhance retirement savings.
  • Monthly stipend for work-related expenses.
  • Flexible time off, including sick leave and parental leave.
  • Life insurance and disability plans provided by Smartsheet.
  • Twelve paid holidays per year.
  • Personal paid Volunteer Day for community service.
  • Access to professional development resources, including Udemy courses.
  • Teleworking options available for this role.
Full Job Description
Smartsheet's expansion into Asia-Pacific government markets depends on mastering two critical compliance frameworks: Australia's Information Security Registered Assessors Program (IRAP) and Japan's Information System Security Management and Assessment Program (ISMAP). Both are essential gatekeepers for federal/national government adoption in their respective markets. We're seeking a Sr. Security Engineer II to own both programs end-to-end-managing IRAP assessments and continuous assurance in Australia, and ISMAP registration and compliance in Japan. This is a specialized, high-impact role for someone with deep expertise in both frameworks and comfort operating within government compliance ecosystems across two distinct cultures and regulatory environments. You'll be the authority on APAC government security standards at Smartsheet, the trusted interface with assessors and government agencies, and the architect of compliance processes that keep us ahead of evolving requirements. This role is critical for capturing high-value government business across the Asia-Pacific region. You will: • Own IRAP (Australia) program strategy and execution: Lead the overall roadmap for obtaining and maintaining IRAP authorizations, including assessment coordination, remediation, and authorization maintenance. • Own ISMAP (Japan) program strategy and execution: Lead registration and compliance for Japan's government cloud certification program, managing the certification assessment process and maintaining registry status. • Coordinate with regional assessors and government agencies: Manage relationships with ASD-endorsed IRAP assessors (Australia) and JASA-registered ISMAP assessors (Japan). Serve as the primary contact for government agencies and compliance authorities in both regions. • Design and maintain IRAP System Security Plans (SSP) and ISMAP Management Standards documentation: Develop comprehensive compliance documentation that maps Smartsheet's architecture to both IRAP (ISM control framework) and ISMAP (~1200 controls) requirements. • Manage continuous monitoring and quarterly updates: Operate continuous assurance programs for both frameworks. Track ISM quarterly updates (Australia) and ISMAP framework evolution (Japan). Maintain evidence of ongoing compliance. • Lead POA&M and remediation management: Identify, prioritize, track, and remediate findings from both IRAP and ISMAP assessments. Manage timelines and evidence collection for remediation closure. • Coordinate significant changes and system modifications: Work with product and engineering teams to assess and obtain approval for changes that impact IRAP authorization or ISMAP registration status. • Build evidence libraries and assessment readiness: Design processes for collecting, organizing, and maintaining compliance evidence for both frameworks. Ensure audit trails and traceability from controls to implementation. • Drive automation and efficiency: Identify opportunities to automate compliance workflows, reduce manual effort, and improve evidence collection efficiency while maintaining rigor and auditability across both programs. You Have: • 5+ years of hands-on experience with government security compliance frameworks, with direct involvement in at least two of: IRAP (Australia), ISMAP (Japan), FedRAMP (US), or equivalent national frameworks. • Deep knowledge of IRAP and ISM: Fluency with Information Security Manual (ISM) control framework, Essential Eight Maturity Model, Protective Security Policy Framework (PSPF), and how controls map to cloud architecture. • Deep knowledge of ISMAP: Understanding of ISMAP framework (based on ISO/IEC 27001), ~1200 control requirements, ISMAP-LIU (Low-Impact-Use) variant, and Japanese government procurement context. • Proven experience coordinating with regional assessors: You've managed assessments in multiple regulatory environments, worked through assessment findings, and translated recommendations into remediation plans. • Understanding of APAC government compliance contexts: Familiarity with how Australian and Japanese government agencies evaluate security, make risk-based decisions, and maintain ongoing compliance obligations. • Technical foundation in cloud architecture and security: Working knowledge of AWS/Azure/GCP, cloud security controls, infrastructure-as-code, logging, incident response, and compliance-relevant architectures. • Experience with continuous monitoring and evolving framework requirements: Understanding of how to maintain compliance in dynamic regulatory environments where frameworks and standards update regularly. • Excellent documentation and communication skills: Ability to write clear compliance documentation, develop control narratives, and communicate technical concepts to both Australian and Japanese government audiences. • Legally eligible to work in the U.S. on an ongoing basis • A degree in Computer Science, Engineering, or a related field or equivalent practical experience Nice to Have • Bilingual or multilingual capability (English + Japanese, or English + Australian government context familiarity). • Professional security certifications: CISSP, CISM, CISA, ISO 27001 Lead Auditor, or equivalent. • Experience with multiple government compliance frameworks (FedRAMP, CMMC, or other national programs). • Background in cloud service provider compliance or SaaS security in APAC markets. Current US Perks & Benefits: • Employer subsidized medical/vision and dental coverage for full-time employees • 401k Match to help you save for your future (50% of your contribution up to the first 6% of your eligible pay) • Monthly stipend to support your work and productivity • Flexible Time Away Program, plus Sick Time Off • US employees are automatically covered under Smartsheet-sponsored life insurance, short-term, and long-term disability plans • US employees receive 12 paid holidays per year • Up to 24 weeks of Parental Leave • Personal paid Volunteer Day to support our community • Opportunities for professional growth and development including access to Udemy online courses • Company Funded Perks, including a counseling membership, local retail discounts, and your own personal Smartsheet account • Teleworking options from any registered location in the U.S. (role specific) Smartsheet provides a competitive base salary range for roles that may be hired in different geographic areas we are licensed to operate our business from. Actual compensation is determined by several factors including, but not limited to, level of professional, educational experience, skills, and specific candidate location. In addition, this role will be eligible for a market competitive incentive opportunity. US Base Salary Pay Range $175,000-$245,000 USD

About Smartsheet

Smartsheet is a software as a service (SaaS) company that provides businesses with collaboration and work management tools. The company's platform allows teams to manage and automate workflows, projects, and processes. Smartsheet's software is used by over 90% of the Fortune 100 companies and has over 15 million registered users. The company was founded in 2005 and is headquartered in Bellevue, Washington.
Learn more about Smartsheet
Size
2,539 employees
Market Cap
$4.9 billion
Industry
Net Income
-$114.4 million
Founded
2005
5 Year Trend
+52.4%
Revenue
$354.1 million
NASDAQ

Similar Jobs

More Jobs at Smartsheet

More Information Technology Jobs

Find similar Sr. Security Engineer II - IRAP Program Lead (Remote Eligible) jobs: