Information Security Manager

Posted One Month Ago
Be an Early Applicant
2 Locations
In-Office
Senior level
Real Estate
The Role
Lead the Australian Information Security Management System, overseeing ISO 27001 and IRAP compliance, audits, risk registers, control monitoring, vendor assessments, incident management, security artifacts, vulnerability remediation, and stakeholder reporting. The role supports Australian Government security requirements, client audits, business continuity planning, and compliance activities across local and global teams.
Summary Generated by Built In

Job Title

Information Security Manager

Job Description Summary

We are seeking an experienced Client IT Security Manager to lead the ongoing management and enhancement of our Information Security Management System (ISMS) in alignment with ISO 27001, IRAP, and Australian Government security requirements. In this key role, you will oversee audits, risk management, compliance activities, and security governance across our client facing environments.

Job Description

Must be an Australian citizen due to account requirements. 

Sydney or Melbourne based

Key Responsibilities

ISO 27001 Responsibilities 

  • Own and maintain the Australia ISMS, including documentation and review schedules. 

  • Manage ISO 27001 audits and implement corrective actions. 

  • Lead biannual ISMS management reviews and annual internal audits. 

  • Oversee quarterly control monitoring and maintain compliance and risk registers. 

  • Coordinate local vendor risk assessments and ensure alignment with global standards. 

  • Support incident management, BCP planning, and ISMS testing. 

  • Conduct regular security and physical checks. 

  • Oversee data retention and deletion in line with regulations. 

  • Provide quarterly leadership reports and manage ISMS communications. 

  • Participate in global policy and standard review. 

IRAP Responsibilities 

  • Define assessment boundaries and scope based on Australian government services. 

  • Maintain compliance with Authority to Operate (ATO) requirements, assessing risks for any deviations. 

  • Review documentation and controls per the Australian Government Information Security Manual (ISM). 

  • Ensure alignment with ASD’s IRAP Common Assessment Framework. 

  • Develop and update required security artifacts (e.g., System Security Plan, Statement of Applicability, Security Risk Management Plan). 

  • Oversee technical configuration reviews, evidence collection, and IRAP assessment reporting. 

  • Document and address residual risks  

Additional Responsibilities 

  • Work with application owners on vulnerability remediation and reporting. 

  • Manage cyber security incident notification and communication between internal teams and clients. 

  • Support local IT and service line teams with compliance requirements, client tender submissions, and audit requests. 

  • Participate in client security audits and support document requests to meet auditor's timeline. 

Required Skills & Experience 

  • Strong knowledge of ISO 27001, IRAP, and Australian Government ISM. 

  • Experience in risk management, audit coordination, and compliance within multinational or regulated environments. 

  • Excellent communication, stakeholder management, and leadership. 

  • Skilled at managing multiple priorities and collaborating across teams. 

  • Preferred certifications: CISM, CISSP, ISO 27001 Lead Implementer/Auditor. 

  • Strong team-building and relationship skills, especially during change. 

  • Ability to align business goals with partners. 

  • Familiar with risk assessment, IT policies, standards, and training. 

  • Broad IT expertise (e.g., distributed computing, networks, financial applications, security, business recovery). 

  • 5–7+ years in IT Risk and/or IT Audit. 

If you’re ready to take ownership of a critical security function and work collaboratively across a global organisation, we’d love to hear from you.










As an equal opportunity employer, Cushman & Wakefield encourages Aboriginal and Torres Strait Islander and female candidates to apply. Cushman & Wakefield promotes safety at all times.

INCO: “Cushman & Wakefield”

Skills Required

  • Australian citizenship due to account requirements
  • Based in Sydney or Melbourne
  • Strong knowledge of ISO 27001, IRAP, and the Australian Government Information Security Manual
  • Experience in risk management, audit coordination, and compliance within multinational or regulated environments
  • Excellent communication, stakeholder management, and leadership skills
  • Ability to manage multiple priorities and collaborate across teams
  • Strong team-building and relationship skills, especially during change
  • Ability to align business goals with partners
  • Familiarity with risk assessment, IT policies, standards, and training
  • Broad IT expertise, including distributed computing, networks, financial applications, security, and business recovery
  • 5-7 or more years of experience in IT risk and/or IT audit
  • CISM, CISSP, or ISO 27001 Lead Implementer/Auditor certification

Cushman & Wakefield Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Cushman & Wakefield and has not been reviewed or approved by Cushman & Wakefield.

  • Retirement Support — A 401(k) with company match is consistently referenced as part of the package. Feedback suggests this provides a solid baseline for long‑term savings across many U.S. roles.
  • Leave & Time Off Breadth — Paid time off and company holidays are regularly highlighted and described as a meaningful part of the offering. Feedback suggests time‑off benefits add tangible value alongside base pay.
  • Parental & Family Support — Paid parental leave for primary and secondary caregivers, plus backup care and wellbeing resources, are described as available. These offerings indicate a supportive approach to family needs in many roles.

Cushman & Wakefield Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Chicago, IL
53,000 Employees
Year Founded: 1917

What We Do

Cushman & Wakefield (NYSE: CWK) is a leading global real estate services firm that delivers exceptional value for real estate occupiers and owners. Cushman & Wakefield is among the largest real estate services firms with approximately 53,000 employees in 400 offices and 60 countries. In 2019, the firm had revenue of $8.8 billion across core services of property, facilities and project management, leasing, capital markets, valuation and other services.

Similar Jobs

Hybrid
Surrey Hills South, Victoria, AUS
15200 Employees
Remote or Hybrid
3 Locations
175633 Employees

Pfizer Logo Pfizer

Manager, Incentive Compensation

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Remote or Hybrid
32 Locations
121990 Employees

Pfizer Logo Pfizer

Marketing Channel Delivery Manager, EM MISP Cluster Markets

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Remote or Hybrid
4 Locations
121990 Employees

Similar Companies Hiring

Findigs, Inc. Thumbnail
Fintech • Real Estate • Software • PropTech
New York, New York
50 Employees
Runwise Thumbnail
Greentech • Hardware • Real Estate • Software • Energy • PropTech
New York, NY
199 Employees
Agora RE Thumbnail
Fintech • Real Estate • PropTech
Tel Aviv, IL
200 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account