SlipstreamJobsFresh Startup & VC-Backed Jobs

Head of Security & Compliance

Checkbox - Sydney, NSW, Australia - Hybrid - posted 2026-08-03

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Checkbox is a Series A, Sequoia-backed AI-first legal tech platform transforming how in-house legal teams operate. The company serves leading enterprises including SAP, Coca-Cola, Allianz, BMW, Elastic and Stryker, and is expanding into AI-powered intake, matter management, triage and work orchestration. You will be the Head of Security & Compliance, owning all aspects of security and trust as the platform scales. This is a hands-on, high-impact role requiring deep technical security expertise combined with compliance leadership and customer-facing credibility. Key responsibilities include: leading application and infrastructure security practices; owning the company SIEM from detection through response; managing vulnerability detection, triage, prioritization and remediation; evaluating and optimizing security tooling (SAST, DAST, SIEM); leading SOC 2, ISO 27001, ISO 27017 and ISO 27018 compliance initiatives; maintaining security policies, evidence and control documentation; serving as the point person for customer security queries and assessments; building AI security guardrails for internal teams; and partnering with Product, Engineering, Platform, Identity, IT, Sales and Legal to embed security into operations. You will need strong experience in application security, infrastructure security, cloud security or security engineering. Required expertise includes: modern SaaS web application and API security; AWS, Kubernetes and containerization; SIEM ownership, detection engineering and incident response; vulnerability management and penetration testing; SAST/DAST and secure SDLC practices; compliance frameworks and audit experience; SOC 2, ISO 27001, ISO 27017 and ISO 27018 certification support; security policy and control documentation; GRC platforms (Vanta, Drata); infrastructure-as-code tools (Terraform, CloudFormation, Ansible); proficiency in Go or TypeScript; strong Bash scripting; CI/CD tooling (GitHub Actions, ArgoCD); and familiarity with modern AI tools (Copilot, Claude, Cursor). Bonus experience includes enterprise B2B SaaS, legal tech, workflow automation, regulated industries, trust centre design, AI security controls, security team mentoring, and distributed team management across Australia, Asia and the US.

Similar roles