Cushman & Wakefield Logo

Cushman & Wakefield

Information Security Manager

Posted 23 Days Ago
Be an Early Applicant
In-Office
Melbourne, Victoria, AUS
Senior level
In-Office
Melbourne, Victoria, AUS
Senior level
Lead the Australian Information Security Management System, overseeing ISO 27001 and IRAP compliance, audits, risk registers, control monitoring, vendor assessments, incident management, security artifacts, vulnerability remediation, and stakeholder reporting. The role supports Australian Government security requirements, client audits, business continuity planning, and compliance activities across local and global teams.
The summary above was generated by AI

Job Title

Information Security Manager

Job Description Summary

We are seeking an experienced Client IT Security Manager to lead the ongoing management and enhancement of our Information Security Management System (ISMS) in alignment with ISO 27001, IRAP, and Australian Government security requirements. In this key role, you will oversee audits, risk management, compliance activities, and security governance across our client facing environments.

Job Description

Must be an Australian citizen due to account requirements. 

Sydney or Melbourne based

Key Responsibilities

ISO 27001 Responsibilities 

  • Own and maintain the Australia ISMS, including documentation and review schedules. 

  • Manage ISO 27001 audits and implement corrective actions. 

  • Lead biannual ISMS management reviews and annual internal audits. 

  • Oversee quarterly control monitoring and maintain compliance and risk registers. 

  • Coordinate local vendor risk assessments and ensure alignment with global standards. 

  • Support incident management, BCP planning, and ISMS testing. 

  • Conduct regular security and physical checks. 

  • Oversee data retention and deletion in line with regulations. 

  • Provide quarterly leadership reports and manage ISMS communications. 

  • Participate in global policy and standard review. 

IRAP Responsibilities 

  • Define assessment boundaries and scope based on Australian government services. 

  • Maintain compliance with Authority to Operate (ATO) requirements, assessing risks for any deviations. 

  • Review documentation and controls per the Australian Government Information Security Manual (ISM). 

  • Ensure alignment with ASD’s IRAP Common Assessment Framework. 

  • Develop and update required security artifacts (e.g., System Security Plan, Statement of Applicability, Security Risk Management Plan). 

  • Oversee technical configuration reviews, evidence collection, and IRAP assessment reporting. 

  • Document and address residual risks  

Additional Responsibilities 

  • Work with application owners on vulnerability remediation and reporting. 

  • Manage cyber security incident notification and communication between internal teams and clients. 

  • Support local IT and service line teams with compliance requirements, client tender submissions, and audit requests. 

  • Participate in client security audits and support document requests to meet auditor's timeline. 

Required Skills & Experience 

  • Strong knowledge of ISO 27001, IRAP, and Australian Government ISM. 

  • Experience in risk management, audit coordination, and compliance within multinational or regulated environments. 

  • Excellent communication, stakeholder management, and leadership. 

  • Skilled at managing multiple priorities and collaborating across teams. 

  • Preferred certifications: CISM, CISSP, ISO 27001 Lead Implementer/Auditor. 

  • Strong team-building and relationship skills, especially during change. 

  • Ability to align business goals with partners. 

  • Familiar with risk assessment, IT policies, standards, and training. 

  • Broad IT expertise (e.g., distributed computing, networks, financial applications, security, business recovery). 

  • 5–7+ years in IT Risk and/or IT Audit. 

If you’re ready to take ownership of a critical security function and work collaboratively across a global organisation, we’d love to hear from you.










As an equal opportunity employer, Cushman & Wakefield encourages Aboriginal and Torres Strait Islander and female candidates to apply. Cushman & Wakefield promotes safety at all times.

INCO: “Cushman & Wakefield”

Similar Jobs

3 Days Ago
Hybrid
Surrey Hills South, Victoria, AUS
Senior level
Senior level
Food
Owns the organization-wide information security program across cloud platforms, digital products, payment systems, identity infrastructure, and franchise restaurants. Responsibilities include security risk assessments, security tooling, fraud management, SIEM detection, incident response, breach notifications, PCI DSS compliance, penetration testing, security awareness, third-party assessments, and AI security. Leads a small team and shared on-call response while partnering with executives, Legal, engineering, and franchise stakeholders.
Top Skills: Acsc Essential EightAntivirusAWSCloud Security Posture ManagementFirewallsIamIds/IpsIso 27001Microsoft Entra IdNist Cybersecurity FrameworkOktaPci DssPrivileged Access ManagementSIEM
Yesterday
In-Office
Melbourne, Victoria, AUS
Senior level
Senior level
Aerospace • Artificial Intelligence • Machine Learning • Robotics • Software
Lead the architecture, development, integration, and deployment of distributed real-time and faster-than-real-time simulation systems for uncrewed aircraft autonomy programs. Build high-performance C++ and Python solutions, integrate defense simulation frameworks, deploy containerized environments with Docker and Kubernetes, and connect simulation with autonomy, perception, hardware interfaces, and automated testing. Provide technical and project leadership across multidisciplinary engineering teams while supporting customer programs and internal research.
Top Skills: AfsimC++Ci/CdDockerHwilKubernetesLinuxNgtsPythonSwil
Yesterday
In-Office
Melbourne, Victoria, AUS
Entry level
Entry level
Aerospace • Artificial Intelligence • Machine Learning • Robotics • Software
Test software across the SDLC by developing and executing test cases, conducting regression and integration testing, implementing automation, validating performance and requirements, documenting results, and supporting release approvals. Prepare hardware and software test environments across Windows and Linux, including device flashing and installation. Collaborate with engineering teams to improve software quality and conduct operational testing during flights around Melbourne.
Top Skills: AgileAutomated Testing FrameworksFault Tracking SystemsHardware-In-The-Loop (Hil)LinuxReal-Time Embedded SoftwareSoftware-In-The-Loop (Sil)Windows

What you need to know about the Melbourne Tech Scene

Home to 650 biotech companies, 10 major research institutes and nine universities, Melbourne is among one of the top cities for biotech. In fact, some of the greatest medical advancements were conceptualized and developed here, including Symex Lab's "lab-on-a-chip" solution that monitors hormones to predict ovulation for conception, and Denteric's vaccine for periodontal gum disease. Yet, the thousands of people working in the city's healthtech sector are just getting started, to say nothing of the tech advancements across all other sectors.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account