InfoSec Governance Risk and Compliance Lead

3 weeks, 5 days ago
Full-time
Senior
Cybersecurity
UpGuard

UpGuard

UpGuard is a cybersecurity ratings platform based in Sydney, Australia, specializing in third-party risk management and attack surface monitoring to prevent data breaches and enhance IT security.

Professional Services
51-250
Founded 2012
$47M raised

Description

  • Lead the development, maturity, and execution of UpGuard’s InfoSec Governance, Risk, and Compliance function with primary ownership of technology and cybersecurity risk.
  • Partner with procurement, legal, and business stakeholders to embed security reviews into the purchasing lifecycle and lead third-party risk management evaluations for vendors.
  • Review security exhibits, Data Processing Agreements, and security questionnaires during procurement negotiations.
  • Partner with the CISO on enterprise and operational risk matters to support a unified risk management approach.
  • Architect, maintain, improve, and report on the technology and security components of the risk management process.
  • Own the technology and security control components of the annual SOC 2 Type II audit cycle and coordinate remediations from prior audits, post-mortems, and internal assessments.
  • Work cross-functionally with Product to develop public-facing trust documentation and identify control gaps in the product development life cycle.
  • Draft, implement, and maintain info-sec policies, standards, processes, and guidelines.
  • Design and deliver company-wide security awareness and compliance training programs using MindTickle.
  • Support the scaling of GRC and vendor security processes alongside UpGuard’s growth.

Requirements

  • 4+ years of dedicated experience in Information Security, IT Audit, or GRC within a technical, cloud-based environment.
  • Deep familiarity with modern technology risk management frameworks, GRC platforms, and third-party risk management tools.
  • Experience partnering with procurement, legal, and privacy teams across regions, including GDPR/CCPA and anti-corruption considerations.
  • Ability to translate complex technical risks into clear business impacts for stakeholders, customers, and vendors.
  • Ability to work independently, take initiative, manage details, and balance execution with long-term strategy.
  • Strong problem-solving ability and comfort navigating ambiguity and legal/business risk trade-offs.
  • High ethical standards, meticulous attention to detail, and a team-first mindset.
  • 6+ years of experience, including at least 2 years in a dedicated lead or senior-level role within a fast-growing B2B SaaS environment (preferred).
  • Experience leading complex, multi-stakeholder security audits from scratch, especially SOC 2 Type II, ISO 27001, or NIST frameworks (preferred).
  • Professional certifications such as CISA, CRISC, CISM, or CISSP (preferred).

Benefits

  • Monthly lifestyle subsidy for financial, physical, and mental well-being.
  • WFH setup allowance within the first 3 months.
  • $1,500 USD annual learning and development allowance.
  • Annual leave plus two additional UpGuardian leave days.
  • 18 weeks of paid parental leave for all parenting roles.
  • Personal leave allowance, including sick and carer’s leave.
  • Fully remote working environment with no compulsory office attendance.
  • Top-spec laptop and paid subscriptions to generative AI tools.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Technology Operations Support Analyst

Facet 251-1K Capital Markets

Facet is hiring an IT/Security Operations Analyst to support internal users, manage access and endpoint operations, and help secure the company’s systems in a fast-growing fintech environment.

Cybersecurity JIRA macOS Salesforce
15 hours, 20 minutes ago

Security Analyst, Bug Bounty

Stripe 5K-10K Diversified Financial Services

Stripe is hiring a Security Analyst for its Vulnerability Management team to triage bug bounty reports, coordinate remediation, and improve the effectiveness of its vulnerability response process.

AWS Burp Suite GCP Python Ruby
1 day, 14 hours ago

Associate, Vulnerability Assessment

Coalfire 251-1K Internet Software & Services

Coalfire is hiring a Vulnerability Assessment Associate to identify, analyze, and report security vulnerabilities across systems, networks, and applications while supporting remediation and risk reduction efforts for clients.

AWS Azure Bash Cybersecurity GCP HIPAA PowerShell Python SOC
1 day, 15 hours ago

Information Security Analyst

Media.Monks 5K-10K Media

Monks is hiring an Information Security Analyst to protect customer and company data and support the organization’s security and compliance posture across a global business.

AWS Azure Cybersecurity Encryption GCP Linux macOS OpenID Connect SAML
1 day, 15 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers