It & Security Manager (Melbourne)

It & Security Manager (Melbourne)

09 Oct
|
Rippling
|
Melbourne

09 Oct

Rippling

Melbourne

Location: Melbourne or Brisbane (Hybrid)
Employment Type: Full-Time
To be considered for this role, you must be based in Melbourne or Brisbane and have unrestricted working rights in Australia on a permanent, full-time basis.
About Open Point
Open Point is a leading global digital engagement company that develops software to help organisations manage their entire community and stakeholder engagement process, from initial discovery to final delivery.
We serve government clients and organisations throughout the United States, Canada, Australia, New Zealand, and Europe.
Our product Open Point, is a centralised stakeholder relationship management platform that helps organisations better understand stakeholder sentiment, engage strategically, and build stronger relationships, all within a single source of truth.
We hold ISO *****, ISO **** and SOC 2 Type II certifications.
Our customers are public sector organisations whose own accountability depends on ours, and they hold us to a high standard.
The Opportunity
We are hiring an IT & Security Manager to own two things most companies split: the internal technology our people rely on, and the security and compliance posture our customers assess us on.
You will work alongside a counterpart in Canada on IT support coverage, while holding full ownership of security and compliance for Open Point.
This role suits someone who has run IT or information security in a SaaS business and wants complete ownership of the security and compliance function, plus a shared role in internal support.
You will report to the Chief Product & Technology Officer and work closely with the Engineering Manager, Principal Engineer, your Canada-based IT Manager counterpart, and our sales and customer teams.
You will be the person a government procurement team's security questions ultimately land with, and the person our executive relies on to know where our real risks sit.
Because this role both operates controls and reports on their effectiveness, we deliberately build in independent checks.
Access reviews, control testing, and audit findings are signed off outside the IT function, penetration testing and control assessment are performed by independent third parties, and you report risk directly to the executive.
We would rather design this properly than explain it to an auditor later, and we expect you to hold us to it.
Why Join Open Point?
Flexible hybrid working arrangement
Unlimited coffee tab at the local café
Paid birthday leave annually
Annual wellness reimbursement
One-off home office allowance
Generous paid parental leave options
What You'll Do




IT support (shared with your Canada counterpart
)
Run identity and access management across our SaaS estate, including joiner, mover, and leaver processes that hold up under audit
Own endpoint management, device compliance, and patching across a distributed workforce, coordinating coverage with your Canada counterpart
Manage SaaS administration, licensing, and technology spend, with a view on consolidation and cost
Own internal support, escalation paths, and the tooling that makes both faster, with shared on-call handover across time zones
Security and compliance (owned by this role)
Own ISO *****, ISO ****, and SOC 2 Type II: scope, surveillance audits, recertification, and the annual calendar
Maintain the ISMS, risk register, policy set, and evidence base as a live system rather than an annual scramble
Run internal audits, management review, and corrective actions, and manage our certification bodies and external auditors
Own security questionnaires, RFP security schedules, and privacy impact assessments from customers, and the trust documentation behind them
Operate and improve the AI assisted workflow used to draft questionnaire responses, and hold accountability for the accuracy of what goes out
Maintain the enterprise risk register and report on it to the executive and the board
Own security incident response: the plan, the drills, and the coordination when something real happens
Provide governance over product security, reviewing that secure development practices, dependency management, vulnerability handling, and cloud configuration standards are followed and effective
Commission and manage independent penetration testing, and track findings to closure
Own data residency and support access controls, and make sure public commitments match operational reality
Run security awareness, phishing simulation, and onboarding training
Support sales and customer teams in security conversations, including joining customer calls when needed
Our Environment Cloud & Infrastructure:
Azure & AWS, Terraform, CI/CD pipelines Observability: Azure App Services, Datadog, OpenTelemetry Product Stack: .
NET (C#), React + TypeScript, MSSQL Identity & Endpoint: [Microsoft Entra ID / Google Workspace],



[MDM platform] Compliance & Assurance: ISO *****, ISO ****, SOC 2 Type II, [GRC platform] AI Tooling: Claude and AI-assisted workflows across engineering and operations
Skills & Experience
8+ years in IT or information security, ideally in a SaaS or technology business selling to government or regulated sectors
Demonstrated ownership of ISO ***** and SOC 2 certification cycles, not just participation in them
Strong grasp of identity and access management, endpoint security and cloud security fundamentals in AWS or Azure
Experience responding to customer security assessments, with the judgement to know what to commit to and what to qualify
Able to explain technical risk to a non-technical executive audience and to a sceptical government procurement officer
Comfortable being the accountable owner rather than an escalation point
Nice to Have ISO ***** Lead Implementer or Lead Auditor, CISSP, CISM or equivalent certification
Experience with privacy regimes across multiple jurisdictions, particularly the Australian Privacy Principles and GDPR
Exposure to ISO **** or other quality management systems
Experience in a private equity backed business, or through a due diligence process
Experience supporting a distributed workforce across several time zones
Experience using AI tools to automate compliance evidence, documentation or questionnaire response
What We Value
Collaboration and Teamwork: Successful outcomes are never achieved alone.
You need to work well with others and be accountable for your work.
We also expect you to communicate often, be honest and take initiative when appropriate.
You will be working openly using modern cooperative platforms.
Passion for Learning: You need to love what you do.
We expect you to always be motivated, challenge yourself and continuously learn without having to push you into it.
This will include learning things outside your area of expertise and making others around you better.
Talent and Courage: We aim to produce great outcomes.
When solving problems, we expect creativity and a focus on the end user.
We want you to have tough conversations if things are not right and the courage to ask when you don't know.
At Open Point, we believe that diversity drives success.
We are an equal opportunity employer that provides a safe and supportive environment where everyone and anyone can grow.
If you require any accommodations or adjustments to participate in the recruitment process, please let us know by including your request in your application.
#J-*****-Ljbffr

📌 It & Security Manager (Melbourne)
🏢 Rippling
📍 Melbourne

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: it & security manager (melbourne) / melbourne

Subscribe to this job alert:

Get the latest job offers by email for: it & security manager (melbourne) / melbourne