About the Role
Power Tech Consulting operates a cloud-native AI and ERP platform serving enterprise clients across Australia. We are pursuing dual certification under ISO 27001 (Information Security) and ISO 42001 (AI Management Systems) and need a technically grounded administrator who can keep our systems running, own evidence collection, and drive our compliance programme to audit readiness.
This is a hands-on role — you will be working directly inside Azure, Odoo, and GitHub, not managing vendor relationships at arm's length.
Key Responsibilities
Systems Administration
- Manage and monitor Azure infrastructure: Container Apps, Key Vault, APIM, VNets, ACR, and managed identities across production, development, and AI/ML environments
- Administer Odoo ERP (projects, helpdesk, timesheets, user access, integrations)
- Manage GitHub organisation access, branch protection rules, and CI/CD pipeline health
- Maintain user provisioning and deprovisioning across all platforms (Azure AD, GitHub, Odoo, Telegram bots)
- Triage and resolve operational alerts from LiteLLM, Container Apps, and automated monitoring systems
- Maintain backup schedules, verify restore procedures, and document recovery runbooks
ISO 27001 Compliance
- Own the ISMS evidence library — collect, organise, and maintain artefacts mapped to ISO 27001:2022 Annex A controls
- Conduct and document periodic access reviews, privilege audits, and asset inventory updates
- Track open control gaps, assign owners, and drive remediation to closure
- Support internal audits and coordinate with external auditors during certification and surveillance cycles
- Maintain risk register, risk treatment plans, and Statement of Applicability
- Write and review information security policies and procedures
ISO 42001 Compliance
- Build and maintain the AI Management System (AIMS) documentation: AI policy, AI risk register, model inventory, and impact assessments
- Map the organisation's AI systems (LiteLLM, OpenClaw, PowerEA, Commander) to ISO 42001 controls
- Collect evidence of responsible AI practices: model governance, data handling, human-in-the-loop controls, and audit logging
- Support supplier and third-party AI risk assessments (AWS Bedrock, Azure OpenAI, Anthropic)
- Assist with preparing for ISO 42001 gap assessments and certification audits
Security Operations
- Monitor security alerts, review logs, and escalate incidents in line with the incident response procedure
- Conduct vulnerability assessments and track remediation
- Manage NSG rules, private endpoint configurations, and network access controls in line with hub-and-spoke topology and ISO 27001 A.8 requirements
- Ensure secrets management hygiene (Key Vault rotation schedules, no credentials in code)
Required Skills & Experience
- 3+ years in a systems administration, cloud operations, or IT security role
- Hands-on Azure experience: Container Apps or AKS, VNet/NSG configuration, Key Vault, managed identities, RBAC
- Familiarity with ISO 27001 — ideally has worked through at least one audit cycle (internal or external)
- Comfortable writing policy documents, control evidence narratives, and risk registers — not just filling in templates
- Experience with GitHub (branch protection, Actions, access management)
- Able to work independently and manage competing priorities without close supervision
Desirable
- Exposure to ISO 42001 or AI governance frameworks (NIST AI RMF, EU AI Act)
- Experience with Odoo or similar ERP administration
- Python scripting for automation and reporting tasks
- Familiarity with APIM, private DNS zones, or hub-and-spoke Azure networking
- ISO 27001 Lead Implementer or Lead Auditor certification
What We Offer
- Direct exposure to a production AI platform serving real enterprise clients
- Genuine ownership of the compliance programme — not a support role
- Hybrid work arrangement from Melbourne
- Opportunity to be named as ISMS/AIMS process owner in a dual-certification effort