Information Security Manager
Core
Lead the Information Security Management System (ISMS) for client-facing environments, ensuring compliance with ISO 27001, IRAP, and Australian Government security requirements.
Role type
Senior IC Information Security Manager
Builds
Compliance artifacts, security governance frameworks, and audit readiness for client environments
Domain
Information Security / Compliance / Australian Government Standards
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
ISO 27001 management, IRAP compliance, risk management, audit coordination, incident management, BCP planning, vendor risk assessment, data retention governance, stakeholder management, leadership
Preferred skills
CISM, CISSP, ISO 27001 Lead Implementer/Auditor, vulnerability remediation, IT policy development, security training
Technologies
ISO 27001, IRAP, Australian Government Information Security Manual (ISM), ASD Common Assessment Framework
Responsibilities
Own and maintain the Australia ISMS documentation and review schedules; Manage ISO 27001 audits and implement corrective actions; Lead biannual ISMS management reviews and annual internal audits; Oversee quarterly control monitoring and maintain compliance and risk registers; Coordinate local vendor risk assessments; Define IRAP assessment boundaries and maintain ATO compliance; Develop and update security artifacts (System Security Plan, Statement of Applicability); Work with application owners on vulnerability remediation; Manage cyber security incident notification and communication; Support client security audits and tender submissions
Seniority
Senior, hands-on IC