Security Specialist
Our purpose
To create a world withmore founders
We believe in creating a world with more founders by helping SaaS businesses accelerate their product development. Kinde was created by founders and engineers to help businesses generate more revenue, reduce costs and make lifelong loyal customers – in one place. Every day, Kinde gives our community of founders and partners across the globe, the infrastructure they need to build anything they can imagine.
About the role
Key responsibilities
The Security Specialist will lead and support key cyber security governance, risk and compliance (GRC) activities across Kinde. This is a permanent, full-time role based in Australia, remote or from agreed locations.
You'll be responsible for developing and maintaining security policies and controls, managing cyber security risks, coordinating security audits and compliance assessments, and supporting Kinde's ongoing SOC 2 and ISO 27001 certification and assurance activities.
Working across engineering, technology, operations, and business teams, you'll translate security, regulatory, and compliance requirements into practical controls and processes that protect Kinde's systems, platform, customer information, and business operations.
Most of the time you will work on the stuff listed below:
- Develop, implement, maintain and continuously improve cyber security policies, procedures, standards and guidelines in line with regulatory requirements, industry standards and recognised security practices.
- Lead cyber security risk management activities, including identifying, assessing and prioritising risks, maintaining risk assessments, developing risk treatment and mitigation plans, and reporting security risks to relevant stakeholders.
- Lead the planning, preparation and execution of security certification and assurance activities, including SOC 2 and ISO 27001, coordinating audits, evidence collection, documentation, remediation and ongoing compliance.
- Conduct security audits, compliance assessments and control reviews to identify security gaps, evaluate control effectiveness and recommend improvements.
- Identify and assess security vulnerabilities and control weaknesses across systems, applications and infrastructure, evaluate their associated business risk and coordinate risk-based remediation with engineering and technology teams.
- Build and maintain Kinde's cyber security governance framework, including security policies, procedures, controls, risk management processes and supporting documentation.
- Develop and maintain appropriate information and system classification requirements to support the prioritisation and implementation of security controls and risk mitigation activities.
- Collaborate with engineering, technology, operations and other cross-functional teams to embed security and compliance requirements throughout systems, products and development processes.
- Monitor security risks, incidents and control deficiencies, coordinate remediation activities and support security incident investigations and post-incident reporting where required.
- Provide practical cyber security guidance to employees and stakeholders and develop security awareness and training initiatives covering security policies, best practices and incident response.
- Conduct compliance assessments and support alignment with applicable cyber security, privacy, data protection and regulatory requirements.
- Assess privacy risk associated with new and existing systems, products and data processing activities and recommend appropriate security and privacy controls.
- Prepare clear security governance, risk, audit and compliance reports for management and relevant stakeholders, including findings, risk treatment activities and recommendations for continuous improvement.
- Assess cyber security and privacy risk associated with third-party providers and services and recommend appropriate risk treatment measures.
Don't fret, you won't be working on these tasks alone. Some of the people you'll work alongside include:
- Our CEO and Founders
- Growth team
- Support team
- Software Engineers
- Product managers
About you
Experience
As a Security Specialist at Kinde, you'll work across governance, risk, compliance, and assurance. As a growing company, there's lots to do and everyone pitches in. We know you'll have a range of skills and experience that you can use to help us in our mission, but below are just a few of the main ones that we're looking for:
-
Demonstrated professional experience in Cyber Security Governance, Risk and Compliance (GRC), including security risk assessments, risk treatment and mitigation, compliance assessments and security governance.
-
Experience developing, implementing and maintaining cyber security policies, procedures, standards and controls aligned with regulatory requirements and recognised industry practices.
-
Demonstrated experience supporting or leading security audits, assurance and certification activities, particularly ISO/IEC 27001 and SOC 2.
-
Strong knowledge of cyber security and risk management frameworks, including ISO/IEC 27001 and NIST Cybersecurity Framework, with the ability to translate framework requirements into practical organisational controls.
-
Experience assessing security control effectiveness, identifying security and compliance gaps and coordinating appropriate remediation activities.
-
Knowledge and practical experience in privacy, data protection and regulatory compliance, with the ability to translate legal and regulatory requirements into practical information security controls, policies and processes.
-
Experience developing security governance documentation and providing practical cyber security guidance and awareness to technical and non-technical stakeholders.
-
Strong stakeholder management and communication skills, with the ability to work collaboratively across engineering, technology, operations and business teams.
-
Relevant tertiary qualifications in Cyber Security, Information Technology, Information Security, Risk Management, Data Protection, or a related discipline.
Bonus points for
-
Experience within a SaaS, technology or cloud-based environment
-
Experience conducting privacy or data protection risk assessments
-
Relevant professional certification or training in ISO 27001, cyber security, risk, audit or privacy
About showing up
When you work here you understand that our values are lived here – not just spoken about. That we care deeply about creating an environment where people can do their life's best work. A place where we show human kindness and gentle manners towards each other, and are free of prejudice of any kind.
We believe that every distinct voice moves us forward, and that only through this can we create a company of giants. The way up is open to everybody, regardless ofreligion, race, gender, or sexual preference.
About the perks
Our benefits are more than benefits. They are the fundamentals of giving a sh*t about each other. They’re how we show up when things are good and most importantly, when they’re not.
Equity for all
When you work at Kinde, you’ll have skin in the game.
Flexible working
Be there for school pick up, walk your dog, make that hot yoga class. When we say flexible, we mean it. We value impact, not screen time.
Flexible public holidays
Recognizing the diversity of cultures and religions here at Kinde, employees can swap a public holiday for another day that’s important to them.
Compassionate leave
15 days leave to support our employees through difficult times including illness or death in the family, miscarriage, and abortion.
Volunteer leave
3 days every year to work with the organizations you love. Giving back moves everyone forward.
Parental leave
12 weeks paid leave for all genders, family constructs and paths to parenthood with an additional 4 weeks for the birthing parent. We also offer a 4 week return to work plan, allowing parents to work 1 less day per week than normal, but still paid in full.
Ready to apply?
Send through your CV to careers@kinde.com