Sr. Security Engineer II - IRAP Program Lead (Remote Eligible)

Smartsheet Inc.
Bellevue, WA, United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$175,000.0 - $245,000.0
Working hours
Regular working hours
Languages
English, Japanese
Job source

Tech stack

Microsoft Azure Cloud Computing Security Cloud Engineering Cyber Security Cloud Services Smartsheet Data Logging Google Cloud Information Technology Plan of Action and Milestones

Job description

  • Own IRAP (Australia) program strategy and execution: Lead the overall roadmap for obtaining and maintaining IRAP authorizations, including assessment coordination, remediation, and authorization maintenance.
  • Own ISMAP (Japan) program strategy and execution: Lead registration and compliance for Japan’s government cloud certification program, managing the certification assessment process and maintaining registry status.
  • Coordinate with regional assessors and government agencies: Manage relationships with ASD-endorsed IRAP assessors (Australia) and JASA-registered ISMAP assessors (Japan). Serve as the primary contact for government agencies and compliance authorities in both regions.
  • Design and maintain IRAP System Security Plans (SSP) and ISMAP Management Standards documentation: Develop comprehensive compliance documentation that maps Smartsheet’s architecture to both IRAP (ISM control framework) and ISMAP (~1200 controls) requirements.
  • Manage continuous monitoring and quarterly updates: Operate continuous assurance programs for both frameworks. Track ISM quarterly updates (Australia) and ISMAP framework evolution (Japan). Maintain evidence of ongoing compliance.
  • Lead POA&M and remediation management: Identify, prioritize, track, and remediate findings from both IRAP and ISMAP assessments. Manage timelines and evidence collection for remediation closure.
  • Coordinate significant changes and system modifications: Work with product and engineering teams to assess and obtain approval for changes that impact IRAP authorization or ISMAP registration status.
  • Build evidence libraries and assessment readiness: Design processes for collecting, organizing, and maintaining compliance evidence for both frameworks. Ensure audit trails and traceability from controls to implementation.
  • Drive automation and efficiency: Identify opportunities to automate compliance workflows, reduce manual effort, and improve evidence collection efficiency while maintaining rigor and auditability across both programs.

Requirements

  • 5+ years of hands-on experience with government security compliance frameworks, with direct involvement in at least two of: IRAP (Australia), ISMAP (Japan), FedRAMP (US), or equivalent national frameworks.
  • Deep knowledge of IRAP and ISM: Fluency with Information Security Manual (ISM) control framework, Essential Eight Maturity Model, Protective Security Policy Framework (PSPF), and how controls map to cloud architecture.
  • Deep knowledge of ISMAP: Understanding of ISMAP framework (based on ISO/IEC 27001), ~1200 control requirements, ISMAP-LIU (Low-Impact-Use) variant, and Japanese government procurement context.
  • Proven experience coordinating with regional assessors: You’ve managed assessments in multiple regulatory environments, worked through assessment findings, and translated recommendations into remediation plans.
  • Understanding of APAC government compliance contexts: Familiarity with how Australian and Japanese government agencies evaluate security, make risk-based decisions, and maintain ongoing compliance obligations.
  • Technical foundation in cloud architecture and security: Working knowledge of AWS/Azure/GCP, cloud security controls, infrastructure-as-code, logging, incident response, and compliance-relevant architectures.
  • Experience with continuous monitoring and evolving framework requirements: Understanding of how to maintain compliance in dynamic regulatory environments where frameworks and standards update regularly.
  • Excellent documentation and communication skills: Ability to write clear compliance documentation, develop control narratives, and communicate technical concepts to both Australian and Japanese government audiences.
  • Legally eligible to work in the U.S. on an ongoing basis
  • A degree in Computer Science, Engineering, or a related field or equivalent practical experience

Nice to Have

  • Bilingual or multilingual capability (English + Japanese, or English + Australian government context familiarity).
  • Professional security certifications: CISSP, CISM, CISA, ISO 27001 Lead Auditor, or equivalent.
  • Experience with multiple government compliance frameworks (FedRAMP, CMMC, or other national programs).
  • Background in cloud service provider compliance or SaaS security in APAC markets.

Benefits & conditions

3.63.6 out of 5 stars Bellevue, WA Remote $175,000 - $245,000 a year

About the company

For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. Now, in our most ambitious chapter yet, we are uniting human teams with AI agents. By orchestrating the work agents do best, automating manual tasks and uncovering insights at scale, we create the space for people to focus on what truly matters: judgment, creativity, and big thinking. That is magic at work, and it’s what we show up for every day.

Smartsheet’s expansion into Asia-Pacific government markets depends on mastering two critical compliance frameworks: Australia’s Information Security Registered Assessors Program (IRAP) and Japan’s Information System Security Management and Assessment Program (ISMAP). Both are essential gatekeepers for federal/national government adoption in their respective markets. We’re seeking a Sr. Security Engineer II to own both programs end-to-end-managing IRAP assessments and continuous assurance in Australia, and ISMAP registration and compliance in Japan. This is a specialized, high-impact role for someone with deep expertise in both frameworks and comfort operating within government compliance ecosystems across two distinct cultures and regulatory environments. You’ll be the authority on APAC government security standards at Smartsheet, the trusted interface with assessors and government agencies, and the architect of compliance processes that keep us ahead of evolving requirements. This role is critical for capturing high-value government business across the Asia-Pacific region., At Smartsheet, your ideas are heard, your potential is supported, and your contributions have real impact. You’ll have the freedom to explore, push boundaries, and grow beyond your role. We welcome diverse perspectives and nontraditional paths-because we know that impact comes from individuals who care deeply and challenge thoughtfully. When you’re doing work that stretches you, excites you, and connects you to something bigger, that’s magic at work. Let’s build what’s next, together.

Equal Opportunity Employer:

Smartsheet is an Equal Opportunity (EEO) employer committed to fostering an inclusive environment with the best employees. It is our policy to provide equal employment opportunities to all qualified applicants in accordance with applicable laws in the US, UK, Australia, Germany, Costa Rica, Japan, Bulgaria, India, and Singapore. All qualified applicants will receive consideration without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status, or genetic information.

If there are preparations we can make to help ensure you have a comfortable and positive interview experience, please let us know.

LI-Remote

You must create an Indeed account before continuing to the company website to apply

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:10 min

Unlocking free learning credits via Google Cloud Innovators

Asrar Asrar · World Congress 2024

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · World Congress 2026 Europe

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

4:42 min

Container hosting options available on Google Cloud Platform

Federico Fregosi · World Congress 2022

1:56 min

Discovering incidents using logs, metrics, and traces

Nele Uhlemann · World Congress 2023

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

Videos

See all

Related articles

See all