Post a job

Senior Compliance Manager, IRAP

Box logo

AU and GB

Job Description

Box is the world’s leading Content Cloud. We are trusted by more than 115K organizations around the world today, including nearly 70% of the Fortune 500 and leaders across deeply regulated industries (such as AstraZeneca, JLL, and Nationwide), to protect their data, fuel collaboration, and power critical workflows with secure, enterprise AI.

By joining Box, you will have the unique opportunity to continue driving our platform forward. Content powers how we work. It’s the billions of files and information flowing across teams, departments, and key business processes every single day: contracts, invoices, employee records, financials, product specs, marketing assets, and more. Our mission is to bring intelligence to the world of content management and empower our customers to completely transform workflows across their organizations. With the combination of AI and enterprise content, the opportunity has never been greater to transform how the world works together and at Box you will be on the front lines of this massive shift.

Founded in 2005, Box is headquartered in Redwood City, CA, and we have offices across the United States, Europe, and Asia.


We are looking for an experienced and driven Sr. Compliance manager who is looking to put their auditing experience, technical expertise, and information security knowledge to plan, execute and deliver on existing and strategic new Compliance certifications. As our Sr. Compliance manager, you are a government expect with extensive experience providing services to global government agencies. The Sr. Compliance Manager is responsible for working with government stakeholders, building out the IRAP program and working closely with public sector certifications, engineering and product teams to ensure we achieve and maintain our certifications.

You will work with all functions of this fast-paced, rapidly changing business, and directly with key stakeholders to drive continuous improvement, communication and education with Box's internal and external customers. The right person be excellent at communicating vertically and horizontally across the company and will be comfortable explaining Box's compliance posture to both internal and external customers, working cross-functionally and providing technical and creative guidance to technical teams.


  • Own and drive the Information Security Registered Assessors Program (IRAP) Compliance program

  • Support the Global Public Sector Compliance team with a specific focus on Australia and New Zealand

  • Interface with government customers and third-party assessment organizations (3PAOs) during assessments

  • Gather and Access evidence to support Compliance requirements

  • Provide compliance guidance on new applicability of requirements from government frameworks which may include changes to product features, deviations, and in the infrastructure

  • Monitor, identify and validate compliance issues and follow-up

  • Drive improvements in existing processes and develop new innovative and efficient solutions

  • Communicate gaps to management and coordinate cross functional team meetings to remediate and close the control gaps

  • Collaborate and build relationships with cross-functional teams internally and external stakeholders

  • Accurately and effectively communicate our compliance position and programs to auditors and customers


  • BS degree in Business or Management Information Systems or related field OR equivalent work experience

  • 7+ years experience in an equivalent technology risk and compliance related role

  • Technical understanding of GCP cloud platforms, including how services are used and secured against FedRAMP High DOD IL4/5, ISMAP and IRAP controls

  • Direct Australian Government experience or related certifications as plus

  • Experience working with GRC tools and processes

  • Extensive knowledge of at least 2 or more of the following compliance frameworks (NIST 800-53, PCI, SOC, ISO 27001, Australian Information Security Manual)

  • Excellent written, verbal communication and presentation skills

  • Big 4 Experience or Management Consulting Experience preferred

  • Willingness to wear different hats and work on areas where needed

  • Amazing organizational skills with a drive to succeed in a fast-paced environment

  • Ability to hustle, get stuff done, and has strong integrity - make mom proud!

Box lives its values, with community and in-person collaboration being a core part of our culture. Boxers are expected to work from their assigned office a minimum of 2 days per week, with a focus on Tuesdays and Thursdays. Your Recruiter will share more about how we work and company culture during the hiring process.

Head-over-heels about this role — but not sure you meet all the requirements? Apply anyway! Studies have shown that women and people of color are less likely to apply to jobs unless they meet every single qualification. At Box, we take a big-picture approach to hiring that fosters authenticity, diversity, and inclusion. If you're passionate about this opportunity, chances are, you shine pretty bright.


Visit this webpage to check out all of our exciting benefits:


We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, disability, and any other protected ground of discrimination under applicable human rights legislation. Box strives to respect the dignity and ‎‎independence of people with disabilities and is committed to giving them the same ‎‎opportunity to succeed as all other employees. Inclusiveness is core to our culture at Box, and we strive to ensure you get the most from your interview experience.

Box makes reasonable accommodations for applicants with disabilities. If a reasonable accommodation is needed to participate in the job application or interview process, please complete this form. Reasonable accommodations may include scheduling adjustments, document dictation and beyond.

Advice from our career coach

A successful applicant for the Senior Compliance Manager position at Box should have a strong background in auditing, technical expertise, information security knowledge, and experience working with government agencies. To stand out as an applicant, consider the following tips:

  • Highlight your experience in working with compliance certifications, especially within the government sector.
  • Showcase your ability to communicate effectively with internal and external stakeholders.
  • Demonstrate your experience in driving continuous improvement and developing innovative solutions.
  • Emphasize your technical understanding of GCP cloud platforms and familiarity with compliance frameworks such as NIST 800-53, PCI, SOC, ISO 27001, and the Australian Information Security Manual.
  • Include any relevant certifications, like direct Australian Government experience or Big 4 experience, to enhance your profile.
  • Show your organizational skills, willingness to adapt to different tasks, and ability to work in a fast-paced environment.

Apply for this job


Please let Box know you found this job with This helps us grow!

About the job

Jul 10, 2024


  1. AU Australia
  2. GB United Kingdom

More remote jobs at Box mascot