Confirmed on the employer's own hiring board on Oct 8, 2026. First seen by Alion on Oct 7, 2026.
Location: Melbourne or Brisbane (Hybrid)
Employment Type: Full-Time
To be considered for this role, you must be based in Melbourne or Brisbane and have unrestricted working rights in Australia on a permanent, full-time basis.
About Open Point
Open Point is a leading global digital engagement company that develops software to help organisations manage their entire community and stakeholder engagement process, from initial discovery to final delivery. We serve government clients and organisations throughout the United States, Canada, Australia, New Zealand, and Europe.
Our product Open Point, is a centralised stakeholder relationship management platform that helps organisations better understand stakeholder sentiment, engage strategically, and build stronger relationships, all within a single source of truth.
We hold ISO 27001, ISO 9001 and SOC 2 Type II certifications. Our customers are public sector organisations whose own accountability depends on ours, and they hold us to a high standard.
The Opportunity
We are hiring an IT & Security Manager to own two things most companies split: the internal technology our people rely on, and the security and compliance posture our customers assess us on. You will work alongside a counterpart in Canada on IT support coverage, while holding full ownership of security and compliance for Open Point.
This role suits someone who has run IT or information security in a SaaS business and wants complete ownership of the security and compliance function, plus a shared role in internal support.
You will report to the Chief Product & Technology Officer and work closely with the Engineering Manager, Principal Engineer, your Canada-based IT Manager counterpart, and our sales and customer teams. You will be the person a government procurement team's security questions ultimately land with, and the person our executive relies on to know where our real risks sit.
Because this role both operates controls and reports on their effectiveness, we deliberately build in independent checks. Access reviews, control testing, and audit findings are signed off outside the IT function, penetration testing and control assessment are performed by independent third parties, and you report risk directly to the executive. We would rather design this properly than explain it to an auditor later, and we expect you to hold us to it.
Why Join Open Point?
- Flexible hybrid working arrangement
- Unlimited coffee tab at the local café
- Paid birthday leave annually
- Professional development reimbursement
- Annual wellness reimbursement
- One-off home office allowance
- Generous paid parental leave options
What You'll Do
IT support (shared with your Canada counterpart)
- Run identity and access management across our SaaS estate, including joiner, mover, and leaver processes that hold up under audit
- Own endpoint management, device compliance, and patching across a distributed workforce, coordinating coverage with your Canada counterpart
- Manage SaaS administration, licensing, and technology spend, with a view on consolidation and cost
- Own internal support, escalation paths, and the tooling that makes both faster, with shared on-call handover across time zones
Security and compliance (owned by this role)
- Own ISO 27001, ISO 9001, and SOC 2 Type II: scope, surveillance audits, recertification, and the annual calendar
- Maintain the ISMS, risk register, policy set, and evidence base as a live system rather than an annual scramble
- Run internal audits, management review, and corrective actions, and manage our certification bodies and external auditors
- Own security questionnaires, RFP security schedules, and privacy impact assessments from customers, and the trust documentation behind them
- Operate and improve the AI assisted workflow used to draft questionnaire responses, and hold accountability for the accuracy of what goes out
- Maintain the enterprise risk register and report on it to the executive and the board
- Own security incident response: the plan, the drills, and the coordination when something real happens
- Provide governance over product security, reviewing that secure development practices, dependency management, vulnerability handling, and cloud configuration standards are followed and effective
- Commission and manage independent penetration testing, and track findings to closure
- Own data residency and support access controls, and make sure public commitments match operational reality
- Run security awareness, phishing simulation, and onboarding training
- Support sales and customer teams in security conversations, including joining customer calls when needed
Our Environment Cloud & Infrastructure:
Azure & AWS, Terraform, CI/CD pipelines Observability: Azure App Services, Datadog, OpenTelemetry Product Stack: .NET (C#), React + TypeScript, MSSQL Identity & Endpoint: [Microsoft Entra ID / Google Workspace], [MDM platform] Compliance & Assurance: ISO 27001, ISO 9001, SOC 2 Type II, [GRC platform] AI Tooling: Claude and AI-assisted workflows across engineering and operations
Skills & Experience
8+ years in IT or information security, ideally in a SaaS or technology business selling to government or regulated sectors
- Demonstrated ownership of ISO 27001 and SOC 2 certification cycles, not just participation in them
- Strong grasp of identity and access management, endpoint security and cloud security fundamentals in AWS or Azure
- Experience responding to customer security assessments, with the judgement to know what to commit to and what to qualify
- Able to explain technical risk to a non-technical executive audience and to a sceptical government procurement officer
- Comfortable being the accountable owner rather than an escalation point
- Nice to Have ISO 27001 Lead Implementer or Lead Auditor, CISSP, CISM or equivalent certification
- Experience with privacy regimes across multiple jurisdictions, particularly the Australian Privacy Principles and GDPR
- Exposure to ISO 9001 or other quality management systems
- Experience in a private equity backed business, or through a due diligence process
- Experience supporting a distributed workforce across several time zones
- Experience using AI tools to automate compliance evidence, documentation or questionnaire response
What We Value
Collaboration and Teamwork: Successful outcomes are never achieved alone. You need to work well with others and be accountable for your work. We also expect you to communicate often, be honest and take initiative when appropriate. You will be working openly using modern collaborative platforms.
Passion for Learning: You need to love what you do. We expect you to always be motivated, challenge yourself and continuously learn without having to push you into it. This will include learning things outside your area of expertise and making others around you better.
Talent and Courage: We aim to produce great outcomes. When solving problems, we expect creativity and a focus on the end user. We want you to have tough conversations if things are not right and the courage to ask when you don't know.
At Open Point, we believe that diversity drives success. We are an equal opportunity employer that provides a safe and supportive environment where everyone and anyone can grow. If you require any accommodations or adjustments to participate in the recruitment process, please let us know by including your request in your application.

