Sr. Security Engineer II - IRAP Program Lead
Job description
Sr. Security Engineer II - IRAP Program Lead at Smartsheet.
About the role
Smartsheet is looking for a Senior Security Engineer II to lead its IRAP certification program. In this role you will own the end-to-end strategy for achieving and maintaining IRAP accreditation across the organization's cloud platform. You will work closely with engineering, compliance, and leadership teams to ensure that all security controls meet the requirements of the Australian Government Information Security Registered Assessors Program. The position is fully remote and based in the United States, allowing you to contribute from anywhere in the country. You will report to the security leadership team and help shape the direction of Smartsheet's overall security posture. Your work will directly impact how the company meets government and regulatory security standards for its products and services.
Key facts
What you'll do
Lead the planning and execution of Smartsheet's IRAP certification program from start to finish
Coordinate with internal engineering teams to identify gaps in security controls and remediation plans
Prepare and submit all required documentation for IRAP assessment and accreditation processes
Manage ongoing relationships with external IRAP assessors and relevant government stakeholders
Develop and maintain a continuous monitoring framework for IRAP-aligned security controls
Drive security architecture reviews to ensure cloud services meet IRAP protection profiles
Create and update IRAP policies, procedures, and evidence packages for audit readiness
Track program milestones and report status to senior leadership and compliance officers
Collaborate with the product team to embed security requirements into the development lifecycle
Mentor junior security engineers and build a center of excellence around IRAP practices
Requirements
Bachelor's degree in computer science, information technology, or a closely related technical field
8 or more years of progressive experience in information security or a closely related discipline
Proven track record leading a security certification or accreditation program such as IRAP, C5, or an equivalent framework
Deep and thorough knowledge of the Australian Government Information Security Manual (ISM) and IRAP assessment methodology
Hands-on experience working with cloud service providers and cloud security frameworks including CSA STAR and ISO 27001
Strong understanding of security controls implementation, testing, validation, and evidence collection for government-level assessments
Excellent written and verbal communication skills for engaging effectively with both technical and non-technical audiences
Ability to work independently in a remote setting while managing multiple priorities and meeting tight deadlines
Experience collaborating with cross-functional teams including engineering, product, legal, and compliance to drive security initiatives forward
Nice to have
Experience with the Australian Signals Directorate (ASD) and its cybersecurity frameworks and assessment guidelines
Prior exposure to government or defense sector clients and their specific security requirements and procurement processes
Certified Information Systems Security Professional (CISSP) or an equivalent industry-recognized professional certification
Familiarity with DevSecOps practices and automated security testing integrated into continuous integration and delivery pipelines
Background in SaaS or cloud-native product companies with a focus on enterprise security operations
Skills & tools
Proficiency in security control frameworks such as ISO 27001, NIST, and the Australian Government Information Security Manual
Hands-on experience with major cloud platforms including AWS, Azure, or GCP and their respective native security services
Deep knowledge of identity and access management, network security, and data protection controls in cloud environments
Familiarity with governance risk and compliance tools for tracking compliance evidence and managing audit artifacts
Strong ability to write clear, structured reports and thorough assessment documentation for internal and external review
Solid project management skills with demonstrated experience coordinating cross-functional security initiatives across multiple teams
Experience with security testing methodologies including vulnerability assessments, penetration testing, and configuration audits
Working knowledge of software development lifecycles and how security integrates into each phase of development
Practical notes
a full-time remote position based in the United States with no requirement to work from a specific office or physical location
The role involves regular collaboration with global teams across different time zones and regions around the world
Candidates should expect to engage frequently with external assessors and government representatives as part of the ongoing IRAP process
Smartsheet offers a competitive benefits package and a fully remote-first work culture designed to support all employees
The position may require occasional travel to client sites or industry events as business needs dictate
About the company
Looking for a remote job? Remote OK® is the #1 Remote Job Platform and has 1,131,503+ remote jobs as a Developer, Designer, Copywriter, Customer Support Rep, Sales Professional, Project Manager and more! Find a career where you can work remotely from anywhere.