Information Security Manager

Cushman & Wakefield

Sydney

On-site

AUD 180,000 - 260,000

Full time

7 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Cushman & Wakefield in Australia is seeking an experienced Information Security Manager to lead the ISMS program in line with ISO 27001, IRAP, and government requirements across client-facing environments.

You will own audits, risk management, governance, and incident response in collaboration with application owners and global policy teams to strengthen controls and compliance. The role requires 5–7+ years in IT risk or IT audit and Australian citizenship.

Qualifications

  • Strong knowledge of ISO 27001, IRAP, and Australian Government ISM.
  • Experience in risk management, audit coordination, and compliance within multinational or regulated environments.
  • Excellent communication, stakeholder management, and leadership.
  • Skilled at managing multiple priorities and collaborating across teams.
  • Preferred certifications: CISM, CISSP, ISO 27001 Lead Implementer/Auditor.
  • Strong team-building and relationship skills, especially during change.
  • Ability to align business goals with partners.
  • Familiar with risk assessment, IT policies, standards, and training.
  • Broad IT expertise across distributed computing, networks, security, and business recovery.
  • 5–7+ years in IT Risk and/or IT Audit.

Responsibilities

  • Own and maintain the Australia ISMS, including documentation and review schedules.
  • Manage ISO 27001 audits and implement corrective actions.
  • Lead biannual ISMS management reviews and annual internal audits.
  • Oversee quarterly control monitoring and maintain compliance and risk registers.
  • Coordinate local vendor risk assessments and ensure alignment with global standards.
  • Support incident management, BCP planning, and ISMS testing.
  • Conduct regular security and physical checks.
  • Oversee data retention and deletion in line with regulations.
  • Provide quarterly leadership reports and manage ISMS communications.
  • Participate in global policy and standard review.
  • Define assessment boundaries and scope based on Australian government services.
  • Maintain compliance with Authority to Operate (ATO) requirements, assessing risks for deviations.
  • Review documentation and controls per the Australian Government ISM.
  • Ensure alignment with ASD’s IRAP CAF.
  • Develop and update required security artifacts (e.g., SSP, SoA, SRMP).
  • Oversee technical configuration reviews, evidence collection, and IRAP reporting.
  • Document and address residual risks.
  • Work with application owners on vulnerability remediation and reporting.
  • Manage cyber security incident notification and client communications.
  • Support local IT and service line teams with compliance and audit requests.
  • Participate in client security audits and responses to auditor timelines.

Skills

ISO 27001 & IRAP
Risk management
Audit coordination
Stakeholder leadership
Cross-functional collaboration
IT policies & training
Leadership & governance
Certifications: CISM/CISSP
IT risk/IT audit experience

Job description

Job Title

Information Security Manager

Job Description Summary

We are seeking an experienced Client IT Security Manager to lead the ongoing management and enhancement of our Information Security Management System (ISMS) in alignment with ISO 27001, IRAP, and Australian Government security requirements. In this key role, you will oversee audits, risk management, compliance activities, and security governance across our client facing environments.

Job Description

Must be an Australian citizen due to account requirements.

Sydney or Melbourne based

ISO 27001 Responsibilities
  • Own and maintain the Australia ISMS, including documentation and review schedules.
  • Manage ISO 27001 audits and implement corrective actions.
  • Lead biannual ISMS management reviews and annual internal audits.
  • Oversee quarterly control monitoring and maintain compliance and risk registers.
  • Coordinate local vendor risk assessments and ensure alignment with global standards.
  • Support incident management, BCP planning, and ISMS testing.
  • Conduct regular security and physical checks.
  • Oversee data retention and deletion in line with regulations.
  • Provide quarterly leadership reports and manage ISMS communications.
  • Participate in global policy and standard review.
IRAP Responsibilities
  • Define assessment boundaries and scope based on Australian government services.
  • Maintain compliance with Authority to Operate (ATO) requirements, assessing risks for any deviations.
  • Review documentation and controls per the Australian Government Information Security Manual (ISM).
  • Ensure alignment with ASD’s IRAP Common Assessment Framework.
  • Develop and update required security artifacts (e.g., System Security Plan, Statement of Applicability, Security Risk Management Plan).
  • Oversee technical configuration reviews, evidence collection, and IRAP assessment reporting.
  • Document and address residual risks
Additional Responsibilities
  • Work with application owners on vulnerability remediation and reporting.
  • Manage cyber security incident notification and communication between internal teams and clients.
  • Support local IT and service line teams with compliance requirements, client tender submissions, and audit requests.
  • Participate in client security audits and support document requests to meet auditor's timeline.
Required Skills & Experience
  • Strong knowledge of ISO 27001, IRAP, and Australian Government ISM.
  • Experience in risk management, audit coordination, and compliance within multinational or regulated environments.
  • Excellent communication, stakeholder management, and leadership.
  • Skilled at managing multiple priorities and collaborating across teams.
  • Preferred certifications: CISM, CISSP, ISO 27001 Lead Implementer/Auditor.
  • Strong team-building and relationship skills, especially during change.
  • Ability to align business goals with partners.
  • Familiar with risk assessment, IT policies, standards, and training.
  • Broad IT expertise (e.g., distributed computing, networks, financial applications, security, business recovery).
  • 5–7+ years in IT Risk and/or IT Audit.
Equal Opportunity Statement

As an equal opportunity employer, Cushman & Wakefield encourages Aboriginal and Torres Strait Islander and female candidates to apply.

Cushman & Wakefield promotes safety at all times.

INCO

INCO: “Cushman & Wakefield”

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Manager
Information Security Manager

Cushman & Wakefield • City of Melbourne

On-site
AUD 140,000 - 210,000
ISMS Lead - ISO 27001 & IRAP Security Manager
ISMS Lead - ISO 27001 & IRAP Security Manager

Cushman & Wakefield • City of Melbourne

On-site
AUD 140,000 - 210,000
ISMS & IRAP Security Leader (InfoSec Manager)
ISMS & IRAP Security Leader (InfoSec Manager)

Cushman & Wakefield • Sydney

On-site
AUD 180,000 - 260,000
Head of Information Security
Head of Information Security

Emmbr • City of Melbourne

On-site
AUD 180,000 - 240,000
Senior Information Technology Specialist
Senior Information Technology Specialist

Decipher Bureau • City of Brisbane

Hybrid
AUD 90,000 - 130,000
Cyber Security Manager
Cyber Security Manager

Stadium Scene • City of Melbourne

On-site
AUD 120,000 - 180,000
Assessment and Authorisation
Assessment and Authorisation

Accenture Australia • Sydney

On-site
AUD 120,000 - 150,000
Parental leave
Career development program
Flexible work arrangements
+1
IRAP Assessor — Cybersecurity Compliance & Government Impact
IRAP Assessor — Cybersecurity Compliance & Government Impact

Excelium Pty Ltd • Canberra

Hybrid
IRAP Assessor
IRAP Assessor

Excelium • Canberra

Hybrid
AUD 110,000 - 150,000
Day‑one mentoring from IRAPpractitione
Hybrid working arrangements
Professional development support
+2
Security Analyst
Security Analyst

Bridge IT Engineering • Canberra

On-site
AUD 90,000 - 120,000