Head Of Security & Compliance (New South Wales)

Head Of Security & Compliance (New South Wales)

05 Aug
|
Checkbox
|
New South Wales

05 Aug

Checkbox

New South Wales

Checkbox is a Series A, Sequoia-backed technology start-up with a mission to enable meaningful work for all.
We are building an AI-first platform that is transforming how in-house legal teams operate, from how work enters legal through to how it is understood, routed, managed and resolved.Our customers include leading in-house legal teams at companies such as SAP, Coca-Cola, Allianz, BMW, Elastic and Stryker.We are now expanding beyond workflow automation into AI-powered intake, matter management, triage and work orchestration.
Our vision is to become the Legal Service Hub for modern organisations, responsible for how legal work is raised, allocated, managed and resolved.As we scale our product, customers and AI capabilities, security and trust are becoming even more critical to how we build.
This role sits at the centre of that.Full time | Hybrid | SydneyThe CompanyCheckbox is a Series A, Sequoia-backed technology start-up with a mission to enable meaningful work for all.
We are building an AI-first platform that is transforming how in-house legal teams operate, from how work enters legal through to how it is understood, routed, managed and resolved.Our customers include leading in-house legal teams at companies such as SAP, Coca-Cola, Allianz, BMW, Elastic and Stryker.We are now expanding beyond workflow automation into AI-powered intake, matter management, triage and work orchestration.
Our vision is to become the Legal Service Hub for up-to-date organisations, responsible for how legal work is raised, allocated, managed and resolved.As we scale our product, customers and AI capabilities, security and trust are becoming even more critical to how we build.
This role sits at the centre of that.The RoleWe are looking for a hands‐on Head of Security & Compliance to own application security, cloud and infrastructure security, SIEM, vulnerability management, customer trust and compliance initiatives as Checkbox scales its AI‐first SaaS platform.This is a high‐impact role for someone who can operate across technical security, compliance and customer‐facing trust.
You will be the subject matter expert for security across our application, infrastructure and internal engineering practices, while also leading key compliance initiatives including SOC 2, ISO *****, ISO ***** and ISO *****.You will work closely with Product, Engineering, Platform, Identity, IT and customer‐facing teams to ensure security is embedded into how we design, build, deploy and operate software.




You will also play a key role in shaping the guardrails for how AI is used safely across the company.This is not a policy‐only or process‐only role.
We need someone who is engineering‐fluent and genuinely hands‐on, able to read, write, review and ship practical security improvements, drive remediation and help teams move quickly without compromising trust.Key ResponsibilitiesLead application security and infrastructure security practices across Checkbox, including secure development, cloud security, SaaS application security, API security and security reviews for new architectures and product capabilitiesOwn the company SIEM from detection through to response, including alerting, investigation workflows, response processes and continuous improvement of security visibilityLead vulnerability management across detection, triage, prioritisation, patching and remediation, including coordination of internal and external penetration testsEvaluate, introduce and optimise security tooling, including SAST, DAST, SIEM, vulnerability management and other controls that support secure engineering at scaleLead compliance initiatives, audits and recertifications across SOC 2, ISO *****, ISO *****, ISO ***** and related trust programsOwn security policies, evidence, controls, audit documentation, the company trust centre and related customer trust projectsAct as the point person for customer security queries, including questionnaires, customer reviews, prospect security assessments and customer‐facing security meetingsBuild practical AI security guardrails for internal teams using tools such as Copilot, Claude, Cursor and other AI‐assisted workflowsPartner closely with Product, Engineering, Platform, Identity, IT, Sales, Customer Success and Legal to ensure security is practical, scalable and embedded into how the business operatesAbout YouStrong experience in application security, infrastructure security, cloud security or security engineering rolesExperience securing modern SaaS web applications, APIs and cloud‐based platformsStrong AWS experience, with good understanding of Kubernetes and containerisation technologiesExperience with SIEM ownership, detection engineering, incident response or security monitoringExperience leading vulnerability management, penetration testing programs and remediation effortsStrong understanding of SAST, DAST,



secure SDLC practices and practical application security controlsExtensive experience with compliance frameworks and audits, including internal and external auditsExperience supporting SOC 2, ISO *****, ISO ***** or ISO ***** certification from early preparation through to audit completionExperience preparing, reviewing and maintaining security policies, evidence and control documentationExperience with GRC platforms such as Vanta, Drata or similarExperience with infrastructure‐as‐code tools such as Terraform, OpenTofu, CloudFormation or AnsibleProficiency in at least one modern programming language such as Go or TypeScriptStrong scripting capability, with Bash as a minimumUnderstanding of CI/CD tooling such as GitHub Actions, ArgoCD or equivalent technologiesFamiliarity with modern AI tooling such as Copilot, Claude or Cursor for AI‐assisted daily workStrong communication skills and the credibility to lead customer‐facing security conversationsProven ability to lead security initiatives end to end, align multiple stakeholders and help others improve their security practicesComfortable working in dynamic start‐up or scale‐up environments where priorities evolve quicklyHands‐on, pragmatic and comfortable moving between strategy, implementation, remediation and customer conversationsBonus PointsExperience in enterprise B2B SaaS, legal technology, workflow automation or regulated industriesExperience building or improving company trust centresExperience designing security controls for AI products, agentic systems or internal AI adoptionExperience mentoring security engineers or acting as a senior technical owner for security practicesExperience working with distributed teams across Australia, Asia and the United StatesWhat We OfferCompetitive salary and equityHybrid working with team days in our Sydney CBD officeHigh ownership over a critical security and trust functionDirect impact on application security, cloud security, compliance and customer trustOpportunity to help shape AI security practices for an AI‐first SaaS companyPersonal learning and development budgetFlexible leave policyExpense policy and salary sacrifice optionsCBD start‐up hub with snacks, drinks, premium coffee and team socialsCompany‐wide social events and annual off‐sitesTransparent, flat culture where questions and feedback are welcomedBe careful - Don't provide your bank or credit card details when applying for jobs.
Don't transfer any money or complete suspicious online surveys.
If you see something suspicious, report this job ad .
#J-*****-Ljbffr

📌 Head Of Security & Compliance (New South Wales)
🏢 Checkbox
📍 New South Wales

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: head of security & compliance (new south wales) / new south wales

Subscribe to this job alert:

Get the latest job offers by email for: head of security & compliance (new south wales) / new south wales