Skip to main content
AfterDuty

Group Information Security Officer

TANDA · Brisbane, Queensland

Type
Full-time
Posted
266 days ago

Overview

Your experience with regulatory frameworks (PACE, RIPA, CPIA) and evidence-handling discipline gives you a strong foundation for managing compliance processes like SOC-2 audits and security documentation. However, the hands-on technical requirements—reading Ruby on Rails code, managing a bug bounty programme, and QAing infrastructure-as-code—demand deep software engineering skills that most policing roles do not develop, making direct entry unlikely without significant retraining.

About this role

Tanda is seeking a Group Information Security Officer to lead its security and compliance initiatives. In this role, you’ll manage SOC-2 audits, maintain up-to-date security documentation, and ensure Tanda’s controls align with company policies and privacy laws. You’ll also deliver internal training, oversee the HackerOne bug bounty program, and respond to customer security inquiries.

This is a hands-on position suited to someone who can balance ensuring our internal security controls are correct and verifying our application is secure too. You’ll play a key role in strengthening Tanda’s security posture and fostering a culture of trust and compliance across the organisation. This is an on-site position located at our Brisbane headquarters.

Core responsibilities:*

  • Manage and oversee the SOC-2 audit process, working with external auditors to ensure Tanda’s SOC-2 audits remain compliant and are completed in a timely way
  • Manage and update Tanda’s information security documentation to provide customers and prospects up to date information on Tanda’s security practices
  • Ensure Tanda’s information security controls are being implemented and managed in accordance with Tanda’s information security policies and privacy law
  • Facilitate internal information security training to Tanda personnel
  • Respond to customer and prospect privacy inquiries, including RFP security questionnaires
  • Manage Tanda’s bug bounty program run through HackerOne. Ensure critical findings are ticketed and fixed
  • The capability to be hands on and read code (with the help of AI) to find answers to questions that are not documented. This includes Ruby on Rails, as well as infrastructure-as-code written in Terraform
  • The capability to QA changes made and verify fixes are implemented correctly

The traits we value at all levels are:*

  • Curiosity - you like to learn, and don’t make the same mistakes twice.
  • Initiative - within reason, you are self-driven and always looking to make an impact. The more senior you get, the more we expect you to be manager of one.
  • Problem solving - you are methodical in your approach to breaking apart problems and figuring out how to solve them in the best way possible under the constraints you face.

About you:*

  • 2+ years experience in a similar role, or equivalent demonstrated technical aptitude and career background

Why Apply?*

See your impact*

We’re a small team, but our product is global. You can personally have a huge impact on our customers’ productivity.

Experience amazing opportunities*

We recognise when people are exceptional, and as a scale-up, we’re flexible enough to give people new opportunities to excel, both in existing teams and in new teams/roles.

Solve deep and interesting problems*

Workforce management is an innovative industry, and creative solutions are a necessity to thrive.

A genuinely great company culture*

Enjoy fully stocked food and beverage fridges, book club, monthly “demo days” where everyone celebrates their best work, board game nights, and much more!

Further Benefits*

✓ Real projects: We hire based on real demand, not based on arbitrary hiring rounds

✓ Experience: You won’t be shielded from customers or responsibility

✓ Culture: You will be part of a team that is passionate about what they do and don’t suffer boredom easily

✓ Team retreat: a full company retreat usually held at a coastal location for two nights

About Tanda*

Tanda is an established, fast-growing tech company. We are on a mission to build Australia’s leading all-in-one workforce management platform. Our vision is to eliminate employment friction for shift and hourly workers, reducing the world’s unemployment rate. Our main activities centre around engineering, marketing, sales, research, and supporting functions. We build software that helps businesses manage their rostering, time & attendance, staffing optimisation, employee engagement, payroll, and labour compliance.

We service thousands of Australian clients from our Brisbane headquarters and globally with offices in Chicago and London.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Brisbane

Why this fits a police background

  • Working to legislation & regulation

More cyber security & digital forensics jobs for ex-police

  • Your background running operational units and coordinating multi-agency responses maps directly onto leading national support functions and ensuring consistent, secure operations across multiple sites. You're used to setting clear accountabilities, managing risk, and driving continuous improvement, which is exactly what this role requires. Your experience with compliance and governance, from PACE to internal procedures, means you can bring structure and discipline from day one.

    Posted 2 days ago

  • Full-time

    Your experience working to strict regulatory frameworks like PACE and CPIA gives you a natural grounding in compliance and assurance, which is exactly what this cyber security GRC role demands. You've spent years maintaining accurate records, managing risk registers, and engaging with diverse stakeholders under pressure, so coordinating audits and driving adherence to standards like ISO 27001 will feel familiar. The role is a development opportunity, so your proven attention to detail and process-oriented mindset will let you build the specific cyber security knowledge on the job.

    Posted 5 days ago

  • Integrity and Security Analyst

    NSW Government · Sydney

    Full-time

    A$133,348 – A$146,945Estimated

    This role directly leverages your operational intelligence experience from policing — you'll produce intelligence products that identify security risks and inform frontline decisions, just as you did under the National Intelligence Model. Your ability to assess threats, manage multi-agency coordination, and apply legislative frameworks like PACE or RIPA is exactly what the NSW Electoral Commission needs to safeguard election integrity. The requirement for 10+ years in law enforcement confirms this is a role built for your background, not a sideways move into a completely new field.

    Posted 5 days ago

  • Full-time

    Your investigative experience from policing—evidence handling, chain of custody, case file management, and conducting structured interviews—maps directly onto the core responsibilities of this insider threat role. You are used to working with sensitive information, maintaining confidentiality, and producing defensible reports for multiple stakeholders, which is exactly what this position demands. The analytical and risk-assessment skills you developed through intelligence-led policing and managing complex investigations will let you hit the ground running in identifying and mitigating insider

    Posted 7 days ago