Sr. Irap Compliance Program Manager

Details of the offer

Smartsheet is a tech company with a human story to tell. We're here to empower teams to manage projects, automate workflows, and rapidly build new secure solutions, using simple no-code tools. We're revolutionaries – so for us changing the way the world works is all in a day's work.
Location: Canberra or Sydney
Smartsheet is a leading platform for enterprise work management, empowering organizations to plan, capture, manage, automate, and report on work at scale, resulting in more efficient processes and better business outcomes. With headquarters in Bellevue, Washington, Smartsheet serves customers worldwide, enabling them to achieve more.
This is an exciting role where you'll be leading and managing the IRAP compliance program for our organization, including interpreting the requirements defined in the Australian Signals Directorate's Information Security Manual, determining the scope of those requirements, assessing compliance with those requirements, liaising with an external IRAP assessor, and implementing or remediating requirements not fully implemented. Your mission is to get Smartsheet IRAP compliant as soon as possible, and then maintain that compliance thereafter.
You Will: Compliance Management: Interpretation and Implementation: The Sr. Manager will independently interpret and apply IRAP and other control frameworks (e.g., NIST SP 800-53), ensuring that all technical controls meet security and compliance standards. This includes creating and maintaining technical standards, developing Assessment Procedures for controls, and managing the overall IRAP Assessment Package.Control Implementation: Oversee the implementation of compliance controls with a focus on optimizing risk reduction, cost efficiency, and business agility, rather than just achieving basic compliance.Challenge Assertions: Independently evaluate and challenge Control Owner assertions related to control implementation, ensuring they align with company policy and regulatory requirements.Liaison with External Assessors: Act as the primary point of contact with external IRAP assessors, coordinating the assessment process and ensuring all necessary documentation is provided.Performance and Program Measurement: Evaluation and Monitoring: Develop criteria to measure program performance, conduct evaluations, and verify data and reports for completeness and correctness. Monitor and analyze project progress, recommending improvements or corrective actions where necessary.Problem Resolution: Proactively identify and address issues in the IRAP compliance program, recommending solutions and adjustments to ensure continuous improvement.Program Management: Operational Oversight: Gain a thorough understanding of the company's operations and integrate this knowledge into the management of the IRAP program. This includes resolving stakeholder issues, managing program budgets, and analyzing program data for improvements.Risk Management: Identify potential risks to the IRAP program, develop effective risk management strategies, and track progress in mitigating or managing those risks. Ensure compliance with relevant regulations and policies.Project Management: Execution and Monitoring: Oversee the execution of IRAP-related projects, ensuring milestones and deliverables are achieved on time and within budget. Adjust project plans and resources based on shifting priorities or unforeseen challenges.Schedule and Scope Management: Monitor and manage the program's schedule and scope to ensure alignment with strategic goals and operational needs. Make necessary adjustments to resources, timelines, or objectives.Requirements Management: Develop clear, actionable compliance requirements and manage changes or updates to these requirements, ensuring they remain feasible and verifiable throughout the lifecycle of the program.Stakeholder Management: Expectation Management: Establish clear expectations with stakeholders and provide a mechanism for ongoing feedback and engagement. Develop an effective stakeholder management plan that addresses both high-level and day-to-day stakeholder needs.Issue Resolution: Proactively resolve any issues raised by stakeholders and maintain strong relationships by managing expectations and driving consensus on program goals and deliverables.You Have: Must-Haves: Bachelor's degree in IT/TechnologyExpert-level knowledge of the Australian Signal Directorate's Information Security Manual2+ years of experience creating IRAP authorization packages at the "Protected" Level or aboveKnowledge and experience with IRAP assessment methodology and requirements2+ years of experience mapping and translating requirements from one control framework (such as IRAP) to another (such as NIST SP 800-53)Basic understanding of NIST SP 800-53Basic understanding of Service Oriented Architecture and how DevOps impacts a compliance program7+ years of experience in program management, with at least 3+ years specifically in compliance program managementNice-to-Haves (listed in order of value): Past experience in compliance-based roles for SaaS companiesIRAP Assessor CertificationExperience implementing or using a GRC toolA security- or compliance-related certification, such as Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), and/or Certified Information Security Manager (CISM)This role at Smartsheet provides an exciting opportunity to lead and shape the company's security and privacy initiatives in a dynamic environment. If you are a compliance-minded leader with a strong sense of integrity and expertise in information security and data privacy, we encourage you to apply and be part of our mission to empower organizations to achieve more.
#J-18808-Ljbffr


Nominal Salary: To be agreed

Source: Talent2_Ppc

Job Function:

Requirements

Grill'D | Restaurant Manager

Are you a passionate leader who thrives on community? Join the Grill'd family, where your development is priority, & the opportunities are limitless. About ...


Tideri Jobbörse - Australian Capital Territory

Published 4 days ago

Complex Procurement Manager

Defence is committed to supporting workplace flexibility. Please contact the contact officer for further details. Learn how a merit list or pool may be usedA...


Department Of Defence - Australian Capital Territory

Published 4 days ago

Australian Department Of Home Affairs | Assistant Director, National Coordination Mechanism

Non-ongoing opportunities may be offered for an initial period of up to 12 months. Learn how a merit list or pool may be used Applicants suitable for the ro...


Tideri Jobbörse - Australian Capital Territory

Published 4 days ago

Australian Public Service Commission | Deputy Director Infrastructure Works Coordination

Defence is committed to supporting workplace flexibility. Please contact the contact officer for further details. Learn how a merit list or pool may be used...


Tideri Jobbörse - Australian Capital Territory

Published 4 days ago

Built at: 2025-01-08T18:30:05.839Z