Security & Compliance Lead (New South Wales)

Security & Compliance Lead (New South Wales)

02 Aug
|
Nexl
|
New South Wales

02 Aug

Nexl

New South Wales

Nexl is a rapid-growing LegalTech company on a mission to elevate the business of law.
The company builds an AI-driven CRM and growth intelligence platform that brings a firm's internal and external data together so lawyers, marketing teams, and business development teams can collaborate, spot opportunities, and grow revenue.Nexl has been recognised by the Financial Times, Deloitte, and the Australian Financial Review as one of the fastest-growing companies in the region, is trusted by 150+ law firms globally, and recently closed a $23M USD Series B led by Tidemark Capital.The OpportunityNexl is looking for its first dedicated Security & Compliance Lead to build and own the security and compliance program from the ground up.
Our clients are law firms, and they trust us with sensitive client relationship data.
Security is core to our product promise and our commercial licence to operate.This is a dual-track role.
You'll run operational security (identity and access controls, endpoint and email protection, SIEM-based detection and incident response) while simultaneously owning our compliance certifications: SOC 2 Type 2 (ongoing) and the ISO ***** roadmap.
On the application security side, you'll govern the program in partnership with Engineering rather than doing hands-on code review yourself.You'll report to the Head of Engineering and work closely with the CPTO and VP of Strategy & Operations, interface directly with enterprise law firm clients on security matters, and produce board-level reporting.
You'll be Nexl's first dedicated security hire, which means genuine ownership and visibility.
This is a greenfield role with executive sponsorship from the CPTO.




You'll have input into tooling decisions and budget conversations from day one.What You'll Own & Do:Policy & Security AwarenessBuild and maintain Nexl's security policy framework: acceptable use, data classification, access control, BCDR, and incident response policiesOwn the security awareness training program, including curriculum, delivery cadence, and phishing simulation campaigns across the organisationDrive a security-first culture that is practical and embedded, not compliance theatreIdentity & AccessOwn Microsoft 365 and Entra ID security posture: conditional access policies, phishing-resistant MFA (passkeys), OAuth application governance, and legacy protocol deprecationManage privileged access controls and the joiners / movers / leavers processServe as Nexl's internal subject matter expert for the Microsoft security stackSecurity OperationsSelect, deploy, and govern the SIEM and EDR stack, defining detection rules, alert thresholds, and escalation pathsOwn alert triage and incident detection, working with external SOC or MSSP partners where appropriateOwn the incident response lifecycle end-to-end: detection, containment, communication, post-incident review, and registry updatesMaintain the security risk register and report material risks to leadership and the board on a regular cadenceOwn Nexl's SOC 2 Type 2, ISO***** and ISO***** programs: control monitoring, evidence collection, auditor liaison, and annual renewalRespond to customer security questionnaires and enterprise due diligence requests - a high-frequency,



revenue-relevant activity at Nexl's customer tierMaintain alignment with Privacy Act (Australia), GDPR, and applicable US data protection requirementsApplication SecurityOwn the annual penetration testing program: scope, vendor management, findings review, and remediation SLA trackingDefine and maintain the vulnerability disclosure policy and responsible disclosure processSet SAST/DAST tooling standards and adoption requirements for the engineering pipeline in partnership with the Head of EngineeringCustomer & Regulatory TrustAct as the primary point of contact for enterprise and law firm clients on all security and compliance mattersProduce board-level security reporting: incident summaries, risk posture updates, certification statusManage third-party vendor security assessments and the vendor review processProvide practical guidance across Privacy Act, GDPR, and cyber insurance obligationsWhat We're Looking For:Must haves:5-8 years across security operations and GRC, ideally in a SaaS or cloud-native environmentHands-on experience with Microsoft 365 and Entra ID security configuration, not just familiarity with configurationDemonstrated ownership of a SOC 2 Type 2 program, ISO ***** experience and willing to help us navigate a roadmap to ISO*****Practical SIEM experience and EDR tooling in a real-world environmentExperience managing or commissioning penetration testing programs and translating findings into engineering-facing remediation plansAble to write a policy, triage a SIEM alert, and brief a C-Suite in the same weekComfortable operating as Nexl's sole security function - you build programs that run without you personally touching everythingWorking knowledge of Privacy Act (Australia) and GDPR
#J-*****-Ljbffr

📌 Security & Compliance Lead (New South Wales)
🏢 Nexl
📍 New South Wales

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: security & compliance lead (new south wales) / new south wales

Subscribe to this job alert:

Get the latest job offers by email for: security & compliance lead (new south wales) / new south wales