Head of Security & Compliance Engineering · Sydney · Full time · Hybrid

Checkbox

Sydney

Hybrid

AUD 180,000 - 240,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Hybrid working
CBD Sydney office
Learning & development budget
Team socials

Job summary

Checkbox is a Series A, Sequoia-backed technology start-up redefining how in-house legal teams operate with an AI-first SaaS platform. We are seeking a hands-on Head of Security & Compliance to own application, cloud and infrastructure security, SIEM, vulnerability management and compliance initiatives as we scale.

You will collaborate with Product, Engineering and Legal to embed practical security controls, drive remediation and ensure trust with customers during rapid growth and AI adoption.

Qualifications

  • Strong experience in application security, infrastructure security, cloud security or security engineering roles.
  • Experience securing modern SaaS web applications, APIs and cloud-based platforms.
  • Strong AWS experience, with good understanding of Kubernetes and containerisation technologies.
  • Experience with SIEM ownership, detection engineering, incident response or security monitoring.
  • Experience leading vulnerability management, penetration testing programs and remediation efforts.
  • Strong understanding of SAST, DAST, secure SDLC practices and practical application security controls.
  • Extensive experience with compliance frameworks and audits, including internal and external audits.
  • Experience supporting SOC 2, ISO 27001, ISO 27017 or ISO 27018 certification from early preparation through to audit completion.
  • Experience preparing, reviewing and maintaining security policies, evidence and control documentation.
  • Experience with GRC platforms such as Vanta, Drata or similar.
  • Experience with infrastructure-as-code tools such as Terraform, OpenTofu, CloudFormation or Ansible.
  • Proficiency in at least one modern programming language such as Go or TypeScript
  • Strong scripting capability, with Bash as a minimum
  • Understanding of CI/CD tooling such as GitHub Actions, ArgoCD or equivalent technologies
  • Familiarity with modern AI tooling such as Copilot, Claude or Cursor for AI-assisted daily work
  • Strong communication skills and the credibility to lead customer-facing security conversations
  • Proven ability to lead security initiatives end to end, align multiple stakeholders and help others improve their security practices
  • Comfortable working in dynamic start-up or scale-up environments where priorities evolve quickly
  • Hands-on, pragmatic and comfortable moving between strategy, implementation, remediation and customer conversations

Responsibilities

  • Lead application and infrastructure security across Checkbox, incl. secure development, cloud, API security, and security reviews.
  • Own the company SIEM from detection through to response, including alerting, investigation workflows and remediation.
  • Lead vulnerability management across detection, triage, prioritisation, patching and remediation, incl. external tests.
  • Evaluate, introduce and optimise security tooling, including SAST, DAST, SIEM, vulnerability management and other controls.
  • Lead compliance initiatives, audits and recertifications across SOC 2, ISO 27001, ISO 27017, ISO 27018.
  • Own security policies, evidence, controls, audit documentation, trust centre and related customer trust projects.
  • Act as the point person for customer security queries, including questionnaires, reviews and security meetings.
  • Build practical AI security guardrails for internal teams using Copilot, Claude, Cursor and other AI-assisted workflows.
  • Partner with Product, Engineering, Platform, Identity, IT, Sales, Customer Success and Legal to embed security into the business.

Skills

Application security
Infrastructure security
Cloud security
SIEM ownership
Vulnerability management
Compliance audits
AI security
Security tooling
Go/TypeScript
CI/CD tooling
Bash scripting
GRC platforms
Terraform/OpenTofu
CloudFormation
Ansible

Tools

Terraform
OpenTofu
CloudFormation
Ansible
Vanta
Drata
GitHub Actions
ArgoCD

Job description

Full-time | Hybrid | Sydney

The Company

Checkbox is a Series A, Sequoia-backed technology start-up with a mission to enable meaningful work for all. We are building an AI-first platform that is transforming how in-house legal teams operate, from how work enters legal through to how it is understood, routed, managed and resolved.

Our customers include leading in-house legal teams at companies such as SAP, Coca-Cola, Allianz, BMW, Elastic and Stryker.

We are now expanding beyond workflow automation into AI-powered intake, matter management, triage and work orchestration. Our vision is to become the Legal Service Hub for modern organisations, responsible for how legal work is raised, allocated, managed and resolved.

As we scale our product, customers and AI capabilities, security and trust are becoming even more critical to how we build. This role sits at the centre of that.

The Role

We are looking for a hands-on Head of Security & Compliance to own application security, cloud and infrastructure security, SIEM, vulnerability management, customer trust and compliance initiatives as Checkbox scales its AI-first SaaS platform.

This is a high-impact role for someone who can operate across technical security, compliance and customer-facing trust. You will be the subject matter expert for security across our application, infrastructure and internal engineering practices, while also leading key compliance initiatives including SOC 2, ISO 27001, ISO 27017 and ISO 27018.

You will work closely with Product, Engineering, Platform, Identity, IT and customer-facing teams to ensure security is embedded into how we design, build, deploy and operate software. You will also play a key role in shaping the guardrails for how AI is used safely across the company.

This is not a policy-only or process-only role. We need someone who is engineering-fluent and genuinely hands-on, able to read, write, review and ship practical security improvements, drive remediation and help teams move quickly without compromising trust.

Key Responsibilities
  • Lead application security and infrastructure security practices across Checkbox, including secure development, cloud security, SaaS application security, API security and security reviews for new architectures and product capabilities

  • Own the company SIEM from detection through to response, including alerting, investigation workflows, response processes and continuous improvement of security visibility

  • Lead vulnerability management across detection, triage, prioritisation, patching and remediation, including coordination of internal and external penetration tests

  • Evaluate, introduce and optimise security tooling, including SAST, DAST, SIEM, vulnerability management and other controls that support secure engineering at scale

  • Lead compliance initiatives, audits and recertifications across SOC 2, ISO 27001, ISO 27017, ISO 27018 and related trust programs

  • Own security policies, evidence, controls, audit documentation, the company trust centre and related customer trust projects

  • Act as the point person for customer security queries, including questionnaires, customer reviews, prospect security assessments and customer-facing security meetings

  • Build practical AI security guardrails for internal teams using tools such as Copilot, Claude, Cursor and other AI-assisted workflows

  • Partner closely with Product, Engineering, Platform, Identity, IT, Sales, Customer Success and Legal to ensure security is practical, scalable and embedded into how the business operates

About You
  • Strong experience in application security, infrastructure security, cloud security or security engineering roles

  • Experience securing modern SaaS web applications, APIs and cloud-based platforms

  • Strong AWS experience, with good understanding of Kubernetes and containerisation technologies

  • Experience with SIEM ownership, detection engineering, incident response or security monitoring

  • Experience leading vulnerability management, penetration testing programs and remediation efforts

  • Strong understanding of SAST, DAST, secure SDLC practices and practical application security controls

  • Extensive experience with compliance frameworks and audits, including internal and external audits

  • Experience supporting SOC 2, ISO 27001, ISO 27017 or ISO 27018 certification from early preparation through to audit completion

  • Experience preparing, reviewing and maintaining security policies, evidence and control documentation

  • Experience with GRC platforms such as Vanta, Drata or similar

  • Experience with infrastructure-as-code tools such as Terraform, OpenTofu, CloudFormation or Ansible


  • Proficiency in at least one modern programming language such as Go or TypeScript

  • Strong scripting capability, with Bash as a minimum

  • Understanding of CI/CD tooling such as GitHub Actions, ArgoCD or equivalent technologies

  • Familiarity with modern AI tooling such as Copilot, Claude or Cursor for AI-assisted daily work

  • Strong communication skills and the credibility to lead customer-facing security conversations

  • Proven ability to lead security initiatives end to end, align multiple stakeholders and help others improve their security practices

  • Comfortable working in dynamic start-up or scale-up environments where priorities evolve quickly

  • Hands-on, pragmatic and comfortable moving between strategy, implementation, remediation and customer conversations

Bonus Points
  • Experience in enterprise B2B SaaS, legal technology, workflow automation or regulated industries

  • Experience building or improving company trust centres

  • Experience designing security controls for AI products, agentic systems or internal AI adoption

  • Experience mentoring security engineers or acting as a senior technical owner for security practices

  • Experience working with distributed teams across Australia, Asia and the United States

What We Offer
  • Competitive salary and equity

  • Hybrid working with team days in our Sydney CBD office

  • High ownership over a critical security and trust function

  • Direct impact on application security, cloud security, compliance and customer trust

  • Opportunity to help shape AI security practices for an AI-first SaaS company

  • Personal learning and development budget

  • Flexible leave policy

  • Expense policy and salary sacrifice options

  • CBD start-up hub with snacks, drinks, premium coffee and team socials

  • Company-wide social events and annual off-sites

  • Transparent, flat culture where questions and feedback are welcomed

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Head of Security & Compliance
Head of Security & Compliance

Checkbox • Sydney

On-site
AUD 180,000 - 260,000
Hybrid work in Sydney CBD
Competitive salary and equity
Learning budget
+3
Security & Compliance Lead — AI SaaS (Hybrid Sydney)
Security & Compliance Lead — AI SaaS (Hybrid Sydney)

Checkbox • Sydney

Hybrid
AUD 180,000 - 260,000
Hybrid work in Sydney CBD
Competitive salary and equity
Learning budget
+3
Principal Engineer Engineering · Sydney · Full time · Hybrid
Principal Engineer Engineering · Sydney · Full time · Hybrid

Checkbox • Sydney

Hybrid
AUD 230,000 - 350,000
Hybrid work
Sydney CBD office
Learning budget
+3
Principal Software Engineer
Principal Software Engineer

Checkbox • Sydney

Hybrid
AUD 180,000 - 240,000
Hybrid work
Architecture ownership
Direct impact
+6
Staff Data Engineer Engineering · Sydney · Full time · Hybrid
Staff Data Engineer Engineering · Sydney · Full time · Hybrid

Checkbox • Sydney

Hybrid
AUD 180,000 - 280,000
Hybrid working
Learning budget
Flexible leave
+2
Senior Software Engineer, Golang Engineering · Sydney · Full time · Hybrid
Senior Software Engineer, Golang Engineering · Sydney · Full time · Hybrid

Checkbox • Sydney

Hybrid
AUD 140,000 - 190,000
Hybrid working arrangements
Learning budget
Open culture
+2
Senior Technical Product Manager, AI Products
Senior Technical Product Manager, AI Products

Checkbox AI • Sydney

Hybrid
AUD 180,000 - 230,000
Hybrid Sydney office
Equity
Learning budget
+2
Senior Software Engineer, AI Engineering · Sydney · Full time · Hybrid
Senior Software Engineer, AI Engineering · Sydney · Full time · Hybrid

Checkbox • Sydney

Hybrid
AUD 150,000 - 190,000
Competitive salary & equity
Hybrid Sydney office
High ownership & impact
+2
Senior Software Engineer, AI
Senior Software Engineer, AI

Checkbox • Sydney

Hybrid
AUD 140,000 - 190,000
Competitive salary and equity
Hybrid working from Sydney office
High ownership and direct impact
Senior Technical Product Manager, AI Products Product · Sydney · Full time · Hybrid
Senior Technical Product Manager, AI Products Product · Sydney · Full time · Hybrid

Checkbox • Sydney

Hybrid
AUD 180,000 - 240,000
Hybrid work from Sydney office
Competitive salary
Equity