ISMS & IRAP Security Leader (InfoSec Manager)

Cushman & Wakefield

Sydney

On-site

AUD 180,000 - 260,000

Full time

7 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Cushman & Wakefield in Australia is seeking an experienced Information Security Manager to lead the ISMS program in line with ISO 27001, IRAP, and government requirements across client-facing environments.

You will own audits, risk management, governance, and incident response in collaboration with application owners and global policy teams to strengthen controls and compliance. The role requires 5–7+ years in IT risk or IT audit and Australian citizenship.

Qualifications

  • Strong knowledge of ISO 27001, IRAP, and Australian Government ISM.
  • Experience in risk management, audit coordination, and compliance within multinational or regulated environments.
  • Excellent communication, stakeholder management, and leadership.
  • Skilled at managing multiple priorities and collaborating across teams.
  • Preferred certifications: CISM, CISSP, ISO 27001 Lead Implementer/Auditor.
  • Strong team-building and relationship skills, especially during change.
  • Ability to align business goals with partners.
  • Familiar with risk assessment, IT policies, standards, and training.
  • Broad IT expertise across distributed computing, networks, security, and business recovery.
  • 5–7+ years in IT Risk and/or IT Audit.

Responsibilities

  • Own and maintain the Australia ISMS, including documentation and review schedules.
  • Manage ISO 27001 audits and implement corrective actions.
  • Lead biannual ISMS management reviews and annual internal audits.
  • Oversee quarterly control monitoring and maintain compliance and risk registers.
  • Coordinate local vendor risk assessments and ensure alignment with global standards.
  • Support incident management, BCP planning, and ISMS testing.
  • Conduct regular security and physical checks.
  • Oversee data retention and deletion in line with regulations.
  • Provide quarterly leadership reports and manage ISMS communications.
  • Participate in global policy and standard review.
  • Define assessment boundaries and scope based on Australian government services.
  • Maintain compliance with Authority to Operate (ATO) requirements, assessing risks for deviations.
  • Review documentation and controls per the Australian Government ISM.
  • Ensure alignment with ASD’s IRAP CAF.
  • Develop and update required security artifacts (e.g., SSP, SoA, SRMP).
  • Oversee technical configuration reviews, evidence collection, and IRAP reporting.
  • Document and address residual risks.
  • Work with application owners on vulnerability remediation and reporting.
  • Manage cyber security incident notification and client communications.
  • Support local IT and service line teams with compliance and audit requests.
  • Participate in client security audits and responses to auditor timelines.

Skills

ISO 27001 & IRAP
Risk management
Audit coordination
Stakeholder leadership
Cross-functional collaboration
IT policies & training
Leadership & governance
Certifications: CISM/CISSP
IT risk/IT audit experience

Job description

Cushman & Wakefield in Australia is seeking an experienced Information Security Manager to lead the ISMS program in line with ISO 27001, IRAP, and government requirements across client-facing environments.

You will own audits, risk management, governance, and incident response in collaboration with application owners and global policy teams to strengthen controls and compliance. The role requires 5–7+ years in IT risk or IT audit and Australian citizenship.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

ISMS Lead - ISO 27001 & IRAP Security Manager
ISMS Lead - ISO 27001 & IRAP Security Manager

Cushman & Wakefield • City of Melbourne

On-site
AUD 140,000 - 210,000
Information Security Manager
Information Security Manager

Cushman & Wakefield • Sydney

On-site
AUD 180,000 - 260,000
Information Security Manager
Information Security Manager

Cushman & Wakefield • City of Melbourne

On-site
AUD 140,000 - 210,000
Senior ISMS & Cyber Risk Lead
Senior ISMS & Cyber Risk Lead

Pyramid Global Technologies • New South Wales

On-site
AUD 120,000 - 160,000
Senior IRAP Consultant - National, Mentorship & Strategy
Senior IRAP Consultant - National, Mentorship & Strategy

RGIT Australia • Canberra

Remote
AUD 170,000 - 230,000
Information Security Manager | Risk, Governance & Assurance
Information Security Manager | Risk, Governance & Assurance

JobRadars - AU • Western Australia

Hybrid
AUD 120,000 - 160,000
Growth-focused culture
Career advancement
Flexible hours and hybrid options
+3
Principal IRAP & Cyber Security Specialist
Principal IRAP & Cyber Security Specialist

Centorrino Technologies Pty Ltd. • Canberra

Hybrid
AUD 100,000 - 120,000
Hybrid working model
Extensive training and development opportunities
Team events and culture-building activities
IRAP Lead & Cyber Security Specialist
IRAP Lead & Cyber Security Specialist

ClearCompany • City of Melbourne

Hybrid
AUD 100,000 - 140,000
Hybrid working model
Extensive training opportunities
Various employee discounts
+2
Cyber Security Assurance Analyst – IRAP & Cloud Compliance
Cyber Security Assurance Analyst – IRAP & Cloud Compliance

Bridge IT Engineering • Canberra

On-site
AUD 90,000 - 120,000
Principal IRAP & Cyber Security Specialist
Principal IRAP & Cyber Security Specialist

Centorrino Technologies • Canberra

Hybrid
AUD 100,000 - 130,000
Extensive training and development opportunities
Hybrid working
Discounts and benefits
+2