Jobgether

Sr. Security Engineer II – IRAP Program Lead

Jobgether · United States · $175K–$245K/yr

Internet Marketplace Platforms · 11-50 employees

7 h ago
Remote Senior (5-10 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Sr. Security Engineer II will lead end-to-end government security compliance programs, including roadmap development, assessment coordination, and ongoing authorization maintenance. They will serve as the primary point of contact for external assessors and government agencies while driving automation to improve compliance workflows.

What they look for

IRAP FedRAMP Cloud security Regulatory compliance Risk management Security assessments Audit readiness Governance Cloud architecture AWS Azure GCP Infrastructure-as-code Incident response Security documentation Compliance frameworks

Requirements

Candidates must have 5+ years of hands-on experience with government security compliance frameworks such as IRAP, ISMAP, or FedRAMP. A strong technical foundation in cloud architecture and excellent communication skills are required to translate complex security concepts for diverse stakeholders.

Benefits

Medical coverage Vision coverage Dental coverage 401(k) matching Monthly remote work stipend Flexible time away program Paid sick leave Life insurance Short-term disability coverage Long-term disability coverage 12 paid holidays Parental leave Paid volunteer day Professional development resources Wellness resources Employee discounts

Full description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Sr. Security Engineer II – IRAP Program Lead based in United States.

This role offers the opportunity to lead critical security compliance initiatives supporting government adoption across Asia-Pacific markets.The position focuses on managing complex regulatory programs, including security assessments, continuous assurance, and compliance operations across multiple regions.You will serve as a subject matter expert for government security frameworks, working with assessors, agencies, and internal technical teams.The role combines cybersecurity expertise, compliance leadership, and strategic program ownership in a global technology environment.You will design scalable processes that strengthen security posture, improve audit readiness, and support business growth in regulated markets.This is an impactful opportunity for an experienced security professional passionate about cloud security, governance, and international compliance standards.

\n

Accountabilities: The Sr. Security Engineer II – IRAP Program Lead will own the strategy, execution, and ongoing management of key government security compliance programs. This role requires deep expertise in regulatory frameworks, strong technical understanding, and the ability to collaborate across engineering, compliance, and external stakeholder teams.

  • Lead end-to-end security compliance programs, including roadmap development, assessment coordination, remediation activities, and ongoing authorization maintenance.
  • Manage government compliance initiatives across international frameworks, ensuring alignment with evolving regulatory requirements.
  • Serve as the primary point of contact for external assessors, government agencies, and compliance stakeholders.
  • Develop and maintain detailed security documentation, including system security plans, control mappings, evidence repositories, and compliance narratives.
  • Coordinate continuous monitoring activities, quarterly updates, and ongoing assurance processes to maintain compliance readiness.
  • Own remediation planning by identifying findings, prioritizing risks, tracking corrective actions, and ensuring timely closure of compliance gaps.
  • Partner with product, engineering, and security teams to evaluate system changes and determine compliance impacts.
  • Build efficient evidence collection processes and maintain audit trails demonstrating security control effectiveness.
  • Drive automation initiatives that improve compliance workflows, reduce manual processes, and increase operational efficiency.
  • Translate complex technical and security concepts into clear documentation for both technical teams and government audiences.
  • Monitor changes in security frameworks and industry standards to proactively improve compliance strategies.
  • Support broader security initiatives and contribute to strengthening organizational security practices.

Requirements:

The ideal candidate has significant experience managing government security compliance programs, with strong knowledge of cloud security, regulatory frameworks, and audit processes. This role requires technical depth, excellent communication skills, and the ability to operate effectively across global and cross-functional environments.

  • 5+ years of hands-on experience with government security compliance frameworks, including direct experience with programs such as IRAP, ISMAP, FedRAMP, or comparable national security frameworks.
  • Strong knowledge of government security standards, control frameworks, risk management practices, and cloud compliance requirements.
  • Experience managing security assessments, working with external auditors, and translating findings into remediation plans.
  • Understanding of international government compliance environments and risk-based security evaluation processes.
  • Technical foundation in cloud architecture and security, including experience with AWS, Azure, or GCP environments.
  • Knowledge of cloud security controls, infrastructure-as-code, logging, incident response, and compliance-focused architectures.
  • Experience operating continuous monitoring programs and maintaining compliance in evolving regulatory environments.
  • Strong documentation skills with the ability to create security plans, control narratives, and audit-ready materials.
  • Excellent written and verbal communication skills, with the ability to explain technical concepts to diverse audiences.
  • Degree in Computer Science, Engineering, or a related field, or equivalent practical experience.
  • Ability to work legally in the United States on an ongoing basis.

Nice to have:

  • Professional security certifications such as CISSP, CISM, CISA, ISO 27001 Lead Auditor, or equivalent.
  • Experience with multiple government compliance frameworks, including FedRAMP, CMMC, or other national programs.
  • Familiarity with cloud service provider compliance or SaaS security operations in international markets.
  • Japanese language skills or experience working within Australian or Japanese government security environments.

Benefits:

  • Competitive base salary range of $175,000 - $245,000 USD, depending on experience, skills, and location.
  • Market-competitive incentive opportunities.
  • Employer-subsidized medical, vision, and dental coverage.
  • 401(k) matching program to support long-term financial planning.
  • Monthly stipend to support remote work and productivity.
  • Flexible Time Away Program and paid sick leave.
  • Company-paid life insurance and short-term and long-term disability coverage.
  • 12 paid holidays annually.
  • Up to 24 weeks of parental leave.
  • Paid volunteer day to support community initiatives.
  • Access to professional development resources, including online learning opportunities.
  • Company-funded perks, wellness resources, and employee discounts.
  • Remote work flexibility from registered locations within the United States.

\nHow Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1