- Location
- Sydney, Melbourne or Hobart · Sydney, New South Wales, Australia
- Department
- Risk & Compliance
- Seniority
- Lead
- Clearance
- Required
- Source
- Greenhouse
Description
Firmus Technologies
Firmus Technologies is a global leader pioneering the development and operation of efficient AI infrastructure across Asia Pacific.
Founded in Australia in 2019, our mission is to create the most efficient AI infrastructure by combining cutting-edge technology with a steadfast commitment to sustainability.
At Firmus, we are unique in our approach. We design, build, and operate a new class of digital infrastructure – the AI Factory. Through our model-to-grid technology approach, we have pushed the boundaries of multi-generational liquid cooling systems, energy management, AI software orchestration, and construction. For our customers, this approach allows us to make every watt count and deliver low-cost AI tokens globally.
Firmus AI Cloud
Our large-scale GPU cloud platform, Firmus AI Cloud, is purpose-built to deliver energy-efficient AI compute at scale to customers.
It empowers developers, enterprises, educational institutions, and government users to train and deploy AI models with unmatched efficiency and cost savings. With an ever-growing suite of services and applications, we are committed to delivering a cloud experience that is market-leading, proprietary, and built to scale.
Why Firmus?
As an NVIDIA Cloud and Engineering partner in Asia Pacific, you will gain skills, experience, and exposure across the AI industry and be part of shaping what this industry looks like for decades to come.
We are founder-led, not a big corporate. Decisions happen fast, our leaders are accessible, and there's minimum bureaucracy between you and the work. Ownership comes early. Whatever your role, you will have a direct line to outcomes, helping shape how the business grows as we scale nationally across a long-term, large-scale roadmap.
Work alongside founders and experts in AI infrastructure, energy systems and next-generation compute.
What we build here has impact beyond the business. Our AI Factories are designed to operate as assets to the energy grid to actively strengthen the communities and regions they operate in rather than drawing from them.
Considering applying? You don't need a perfect background to join our team. If you're driven and curious, there's a path for you. We back our people to grow into new domains and take on challenges beyond their previous experience.
Role Summary
FIRMUS are looking for an experienced Information Security and GRC specialist to lead the Firmus information security and GRC compliance function within the Firmus’ Group Risk & Compliance business unit.
The Information Security & GRC Lead will be part of the senior compliance team and be responsible for helping to design, build and manage delivery of the whole-of-organisation GRC and informations security posture in relation to internal, domestic, and international standards and certifications. You will be required to provide advice, guidance, and strategy to functional heads across the organisation. Ensuring adequate management systems, processes, controls and policy arrangements are implemented across the organisation.
As the Lead, you will also take on the responsibilities for the development and implementation of information and cyber security policy requirements and for managing our information and cyber security risks, as well as maintaining certifications such as ISO27001, ISO 27701, SOC2, NIST, Essential 8, and the Defence / Australian Protective Security Policy Framework (PSPF).
Key Responsibilities
- Management of existing risk and compliance (GRC) processes and accreditations such as ISO27001, ISO 27701, SOC2, DISP and obtaining further accreditations such as CSA STAR, NIST 800-53 / CSF 2.0.
- Development of new InfoSec and GRC processes for global projects.
- Lead the InfoSec and GRC audit (internal and external) program utilising internal platforms including DRATA, including conducting internal audit.
- Lead the development of group GRC policy and frameworks, including Governance, ESG, and Information Security and Privacy of Information Management.
- Provision of InfoSec and GRC compliance advice to functional areas / business units.
- Coordination of annual policy reviews and development of policies for company certifications.
- Act as the Group Data Protection Officer across the relevant operating jurisdictions.
- Lead the InfoSec / Cyber Security compliance working groups and committees.
- Support functional areas / business units develop and implement compliant systems and processes across InfoSec, GRC and Business Continuity.
- Develop guidance and information security / cyber security alerts and notices and communicate across the Group.
- Acting as the focal point for external certification audits, penetration testing and new product evaluation.
- Monitor internal compliance of information / cyber security platforms.
- Development and ongoing promulgation of security/cyber policies, standards and guidelines.
Skills & Experience
Required Skills
- Senior technical experience in a risk & compliance role, ideally with time spent in one or more technology-focussed businesses.
- Management system and certification auditing (ISO 27001, 27701, 22301).
- Advanced DRATA or similar platform experience.
- CISA/CRISC/CISM or CISSP certifications prefered.
- Information Security / Cyber Security: endpoint security management, SIEM, SOC planning and compliance.
- Certification compliance management: SOC 2 (Type 1 & 2), ISO27001, ISO 27701, NIST, ASD Essential 8.
- Sound knowledge of the InfoSec and GRC compliance challenges that technology-focussed businesses face.
- Deep metrics, measurements and executive reporting capability
- Exceptional stakeholder management skills and ability to influence and challenge constructively.
- Vendor/stakeholder management experience
- Highly refined written and verbal communication skills.
- Holds Australian Government or Defence security clearance to a minimum of baseline with ability to obtain clearance to NV1.
Desirable Experience
- Experience with international compliance frameworks and working with multinational technology companies.
- Experience and familiarity with modern AI tools and technologies
- Project and delivery management
- Enterprise information security tools (SIEM, EDR/XDR, vulnerability management/scanning).
- Exposure to security appliance vendors such as Fortinet, Palo Alto, and others.
Location & Reporting
- Location: This role has the opportunity to be based out of Sydney, Melbourne or Hobart, Australia.
- Reports to: Head of Risk & Compliance
Employment Basis
Permanent full-time
Diversity
At Firmus, we are committed to building a diverse and inclusive workplace. We encourage applications from candidates of all backgrounds who are passionate about creating a more sustainable future through innovative engineering solutions.
Join us in our mission to revolutionise the AI industry through sustainable practices and cutting-edge engineering. Apply now to be part of shaping the future of sustainable AI infrastructure.