I'm looking for a senior role where security, governance, and automation intersect — ideally at a technology company where those functions are taken seriously rather than treated as overhead. Remote-first is important. I want a broad remit and real ownership, working with a team that values both technical depth and clear thinking about risk.
Japheth Thomson
@japheth
Security & GRC leader who builds compliance programmes, automates governance workflows, and translates risk into decisions executives can act on.
What I'm looking for
I'm a security and compliance leader focused on risk governance, automation, and analytics-driven decision-making. I help organisations enhance their risk posture, reduce manual compliance overhead, and build security operations that align with business objectives.
At Firmus Technologies, I lead the full GRC function for technically complex compute environments. I inherited two concurrent audits and delivered clean outcomes for both ISO 27001:2022 surveillance and SOC 2 Type II, built an n8n-based compliance automation platform that reduced manual evidence collection significantly, and developed AI-augmented workflows for policy drafting, risk assessment, and compliance documentation.
Previously, as Head of Technology Risk & Compliance at GoDaddy (Pagely), I led Pagely's first SOC 2 Type 2 audit, achieving clean reports in 2023 and 2024, and implemented Drata for continuous compliance monitoring. Earlier, as Director of Cloud Operations at Human Made, I owned cloud security and resilience for an enterprise managed platform on AWS, leading infrastructure modernisation from EC2 to containerised deployment and establishing observability and incident response capability across a globally distributed engineering team.
Experience
Work history, roles, and key accomplishments
Information Security & GRC Lead
Firmus Technologies
May 2025 - Present (1 year 1 month)
Built and operated Firmus’s security and compliance programmes for energy-efficient AI infrastructure, owning risk assessments, policy, audit management, and compliance automation. Delivered clean outcomes for ISO 27001:2022 surveillance and SOC 2 Type II within the first months, while reducing manual evidence collection to near zero using n8n automation.
Head of Technology Risk & Compliance
GoDaddy (Pagely)
Nov 2021 - Mar 2025 (3 years 4 months)
Led technology risk management and compliance initiatives to strengthen Pagely’s security posture within GoDaddy, driving SOC 2 Type II compliance and automation-first evidence workflows. Implemented Drata for compliance monitoring, built a security maturity score framework for C-level reporting, and supported cost-efficiency initiatives while aligning cloud security policies with engineering and
Head of Technology Risk & Compliance
Pagely
Mar 2021 - Mar 2025 (4 years)
Established Pagely’s compliance program from scratch as the first Compliance Manager and led the company through its first-ever SOC 2 Type II audit with clean reports in 2023 and 2024. Developed security controls and risk governance, automated compliance workflows using Drata, and strengthened vendor risk management to maintain ongoing audit readiness.
Director of Cloud Operations
Human Made
Aug 2014 - Mar 2021 (6 years 7 months)
Led the Cloud Operations team for Altis, a high-performance AWS-based enterprise DXP serving millions of users daily, focusing on security, resilience, and operational efficiency. Drove cloud security governance and automation, including migrating from EC2 to containerization (ECS/ECR), improving scalability and deployment efficiency while enhancing observability and incident management for high-t
WordPress R&D Engineer
X-Team / Stream
Apr 2014 - Aug 2014 (4 months)
Worked on cloud-based security, automation, and analytics for Stream’s WordPress activity logging and monitoring service. Built AWS infrastructure with Ansible-based automation, implemented Elasticsearch indexing for searchable logs, and integrated WordPress JSON REST API with logging and security monitoring pipelines.
WordPress Evangelist
Envato
Sep 2011 - Apr 2014 (2 years 7 months)
Drove WordPress and Envato community engagement by delivering presentations and creating educational content that clarified complex technical topics for diverse audiences. Supported cross-functional community initiatives and sponsorships while building a trusted personal brand as a WordPress advocate.
Site Editor
Wptuts+
Jan 2012 - Jan 2014 (2 years)
Managed editorial operations for Wptuts+, commissioning, editing, and publishing WordPress tutorials and best-practice content. Coordinated with writers and experts and supported community engagement through social media and consistent editorial oversight.
Programmer / Technologist
AdditionalView Pty Ltd
Sep 2007 - Aug 2008 (11 months)
Led web development in a small team, delivering websites and web applications while supporting internal and external network infrastructure. Provided technological advisement on projects and contributed to core engineering execution.
Marketing Systems Administrator
Aurora Energy
Jun 2007 - Sep 2007 (3 months)
Performed web development across multiple sites and coordinated stakeholders and outside contractors on a project-by-project basis. Communicated analytics to marketing staff regularly and supported implementation of marketing strategies.
IT Support Officer
Hobart City Council
Oct 2000 - Nov 2005 (5 years 1 month)
Provided general desktop support across a network of 400+ workstations and multiple sites, including basic network and backup administration. Performed systems and backup troubleshooting, assisted with web development, and trained other IT staff.
Senior Developer / Team Leader
Ionata Web Solutions
Led a small development team and delivered web applications by planning work with wireframes, specifications, and ER diagrams. Customized themes and developed plugins, including retiring a custom CMS and standardizing on WordPress as the platform.
Technical Director
Fearless Media
Owned technological direction of the business, including migrating from a custom CMS to WordPress as the standard platform. Led development and trained students in web technologies from HTML/CSS through PHP/MySQL while setting up and maintaining internal and external network infrastructure.
Senior Developer
Engine Creative
Led web development for client projects, including building web sites and web applications. Customized CMS implementations and developed plugins while advising stakeholders to standardize on WordPress.
Support Engineer Consultant
WebFaction
Troubleshot customer issues with a focus on high-load problem diagnosis and restoring service from backups. Updated online documentation and provided WordPress-focused support via forums to ensure timely, accurate resolutions.
Education
Degrees, certifications, and relevant coursework
Japheth hasn't added their education
Don't worry, there are 90k+ talented remote workers on Himalayas
Tech stack
Software and tools used professionally
AWS IAM
Microsoft Azure
Google Cloud Platform
Amazon CloudWatch
Amazon S3
GitHub
Cloudflare
MySQL
SQLite
Amazon Route 53
Microsoft SharePoint
Intercom
Workday
Node.js
Google Analytics
Slack
Zendesk
Jira Service Desk
Redis
AWS CloudFormation
Jira
Linear
JavaScript
PHP
JSON
AWS Elastic Load Balancing ...
AWS CloudTrail
Loki
HubSpot
Grafana
Prometheus
PM2
Ubuntu
Linux
New Relic
Datadog
Microsoft Office 365
Palo Alto Networks
WordPress
AWS Lambda
Amazon RDS
Git
Docker
Discord
NGINX
WebFaction
Amazon Web Services (AWS)
npm
Microsoft Intune
Ollama
Portainer
OpenAI API
Anthropic Claude API
Cursor
N8N
Drata
Model Context Protocol (MCP)
Claude Code
HiBob
Availability
Location
Authorized to work in
Salary expectations
Social media
Job categories
Interested in hiring Japheth?
You can contact Japheth and 90k+ other talented remote workers on Himalayas.
Message JaphethFind your dream job
Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!
