Security & Compliance Lead (New South Wales)

Security & Compliance Lead (New South Wales)

02 Aug
|
Nexl
|
New South Wales

02 Aug

Nexl

New South Wales

Nexl is a fast-growing LegalTech company on a mission to elevate the business of law. The company builds an AI-driven CRM and growth intelligence platform that brings a firm's internal and external data together so lawyers, marketing teams, and business development teams can collaborate, spot opportunities, and grow revenue.
Nexl has been recognised by the Financial Times, Deloitte, and the Australian Financial Review as one of the fastest-growing companies in the region, is trusted by 150+ law firms globally, and recently closed a $23M USD Series B led by Tidemark Capital.
The Opportunity
Nexl is looking for its first dedicated Security & Compliance Lead to build and own the security and compliance program from the ground up. Our clients are law firms, and they trust us with sensitive client relationship data. Security is core to our product promise and our commercial licence to operate.
This is a dual-track role. You'll run operational security (identity and access controls, endpoint and email protection, SIEM-based detection and incident response) while simultaneously owning our compliance certifications: SOC 2 Type 2 (ongoing) and the ISO ***** roadmap. On the application security side, you'll govern the program in partnership with Engineering rather than doing hands-on code review yourself.
You'll report to the Head of Engineering and work closely with the CPTO and VP of Strategy & Operations, interface directly with enterprise law firm clients on security matters, and produce board-level reporting. You'll be Nexl's first dedicated security hire, which means genuine ownership and visibility. This is a greenfield role with executive sponsorship from the CPTO. You'll have input into tooling decisions and budget conversations from day one.
What You'll Own & Do:
Policy & Security Awareness




Build and maintain Nexl's security policy framework: acceptable use, data classification, access control, BCDR, and incident response policies
Own the security awareness training program, including curriculum, delivery cadence, and phishing simulation campaigns across the organisation
Drive a security-first culture that is practical and embedded, not compliance theatre
Identity & Access
Own Microsoft 365 and Entra ID security posture: conditional access policies, phishing-resistant MFA (passkeys), OAuth application governance, and legacy protocol deprecation
Manage privileged access controls and the joiners / movers / leavers process
Serve as Nexl's internal subject matter expert for the Microsoft security stack
Security Operations
Select, deploy, and govern the SIEM and EDR stack, defining detection rules, alert thresholds, and escalation paths
Own alert triage and incident detection, working with external SOC or MSSP partners where appropriate
Own the incident response lifecycle end-to-end: detection, containment, communication, post-incident review, and registry updates
Maintain the security risk register and report material risks to leadership and the board on a regular cadence
Own Nexl's SOC 2 Type 2, ISO***** and ISO***** programs: control monitoring, evidence collection, auditor liaison, and annual renewal
Respond to customer security questionnaires and enterprise due diligence requests - a high-frequency,



revenue-relevant activity at Nexl's customer tier
Maintain alignment with Privacy Act (Australia), GDPR, and applicable US data protection requirements
Application Security
Own the annual penetration testing program: scope, vendor management, findings review, and remediation SLA tracking
Define and maintain the vulnerability disclosure policy and responsible disclosure process
Set SAST/DAST tooling standards and adoption requirements for the engineering pipeline in partnership with the Head of Engineering
Customer & Regulatory Trust
Act as the primary point of contact for enterprise and law firm clients on all security and compliance matters
Produce board-level security reporting: incident summaries, risk posture updates, certification status
Manage third-party vendor security assessments and the vendor review process
Provide practical guidance across Privacy Act, GDPR, and cyber insurance obligations
What We're Looking For:
Must haves:
5-8 years across security operations and GRC, ideally in a SaaS or cloud-native setting
Hands-on experience with Microsoft 365 and Entra ID security configuration, not just familiarity with configuration
Demonstrated ownership of a SOC 2 Type 2 program, ISO ***** experience and willing to help us navigate a roadmap to ISO*****
Practical SIEM experience and EDR tooling in a real-world environment
Experience managing or commissioning penetration testing programs and translating findings into engineering-facing remediation plans
Able to write a policy, triage a SIEM alert, and brief a C-Suite in the same week
Comfortable operating as Nexl's sole security function - you build programs that run without you personally touching everything
Working knowledge of Privacy Act (Australia) and GDPR
#J-*****-Ljbffr

📌 Security & Compliance Lead (New South Wales)
🏢 Nexl
📍 New South Wales

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: security & compliance lead (new south wales) / new south wales