About Aegentra
Aegentra is a cybersecurity and governance consultancy with teams based in Melbourne and Sydney, supporting businesses across Australia. Our work includes information security, AI governance, management-system consulting and internal audits.
We are looking for an experienced Lead Auditor who can take ownership of client audit engagements, exercise sound judgement and explain findings in language people can act on.
The role
You will lead scoped internal audits and supplier audits against ISO/IEC 27001:2022 and ISO/IEC 42001:2023. Projects may cover one standard or both, depending on the client's needs. Separately scoped readiness reviews may also form part of an engagement.
You will own the work from planning and evidence review through to the closing meeting, final report and agreed follow-up. Success means a well-run audit, findings supported by evidence, clear limitations and a complete handover delivered within the agreed scope and timeframe.
This is a project-based opportunity, with assignments agreed according to client requirements, your availability and the expertise needed for each engagement.
What you will do
- Plan the audit. Confirm objectives, scope, criteria, relevant standard amendments, responsibilities, timetable and evidence access. Develop an audit plan and a proportionate sampling approach using current ISO 19011 guidance.
- Lead the engagement. Run opening and closing meetings, interview stakeholders, examine records and test whether the management system operates as described. Coordinate other auditors or specialists where the scope requires them.
- Assess information security. Review the ISMS scope, risk assessment and treatment, Statement of Applicability, relevant controls, performance evaluation and improvement. Evaluate control design and operation using evidence appropriate to the client's risks.
- Assess AI governance. Review the AIMS scope, the organisation's role in developing or using AI, AI systems in scope, risk and impact assessments, data and lifecycle controls, human oversight, supplier dependencies and monitoring.
- Report defensible findings. Link each finding to the audit criteria and supporting evidence. Distinguish nonconformities from observations and improvement opportunities. Explain significance, sampling limitations and unresolved issues clearly.
- Complete agreed follow-up. Review corrective-action evidence, verify closure where included in scope, maintain the audit record and hand over outstanding actions. Escalate access problems, conflicts and scope changes promptly.
- Protect client information. Use approved systems, handle sensitive evidence carefully and follow agreed confidentiality, access, retention and secure-closeout requirements.
What you need to bring
- Current, verifiable professional Lead Auditor certification in both ISO/IEC 27001 and ISO/IEC 42001, from PECB or an equivalent personnel certification or auditor-registration scheme with relevant standard coverage and Lead Auditor grade. Course attendance, an exam pass, a provisional auditor credential or Lead Implementer certification alone does not meet this requirement.
- Demonstrable audit delivery experience across both standards. You can explain audits you personally led, your responsibilities, the evidence examined and how you reached your conclusions. Certification alone is not sufficient.
- Practical technical understanding. You can discuss information security controls and AI governance with operational teams, distinguish policy from implementation and recognise when specialist input is needed.
- Clear writing and client communication. You can produce concise audit reports, explain difficult findings respectfully and lead meetings with technical teams and management.
- Professional judgement and independence. You disclose conflicts, protect confidential information and maintain objective findings under pressure. You can plan and deliver the agreed work reliably.
- Australia-based availability. You can attend agreed client meetings during Australian business hours. Any on-site work or travel is agreed before you accept an assignment.
Experience auditing SaaS, cloud environments, growing businesses or integrated management systems is useful. Additional security, privacy or AI-governance qualifications are welcome, but do not replace the two required Lead Auditor credentials.
Audit independence
You must disclose prior implementation work, employment, consulting relationships and other potential conflicts before accepting an assignment. You will not audit your own work. Each engagement requires appropriate independence arrangements and objective, evidence-based findings. Assignments are accepted only where conflicts can be managed appropriately.
This role covers internal audits, supplier audits and separately identified readiness reviews. It does not authorise you to issue accredited management-system certification or promise a certification outcome.