Skip to main content
HimalayasHimalayas logo
JT
Looking for a job

Japheth Thomson

@japheth

Security & GRC leader who builds compliance programmes, automates governance workflows, and translates risk into decisions executives can act on.

Australia
Message

What I'm looking for

I'm looking for a senior role where security, governance, and automation intersect — ideally at a technology company where those functions are taken seriously rather than treated as overhead. Remote-first is important. I want a broad remit and real ownership, working with a team that values both technical depth and clear thinking about risk.

I'm a security and compliance leader focused on risk governance, automation, and analytics-driven decision-making. I help organisations enhance their risk posture, reduce manual compliance overhead, and build security operations that align with business objectives.

At Firmus Technologies, I lead the full GRC function for technically complex compute environments. I inherited two concurrent audits and delivered clean outcomes for both ISO 27001:2022 surveillance and SOC 2 Type II, built an n8n-based compliance automation platform that reduced manual evidence collection significantly, and developed AI-augmented workflows for policy drafting, risk assessment, and compliance documentation.

Previously, as Head of Technology Risk & Compliance at GoDaddy (Pagely), I led Pagely's first SOC 2 Type 2 audit, achieving clean reports in 2023 and 2024, and implemented Drata for continuous compliance monitoring. Earlier, as Director of Cloud Operations at Human Made, I owned cloud security and resilience for an enterprise managed platform on AWS, leading infrastructure modernisation from EC2 to containerised deployment and establishing observability and incident response capability across a globally distributed engineering team.

Experience

Work history, roles, and key accomplishments

FT
Current

Information Security & GRC Lead

Firmus Technologies

May 2025 - Present (1 year 1 month)

Built and operated Firmus’s security and compliance programmes for energy-efficient AI infrastructure, owning risk assessments, policy, audit management, and compliance automation. Delivered clean outcomes for ISO 27001:2022 surveillance and SOC 2 Type II within the first months, while reducing manual evidence collection to near zero using n8n automation.

GP

Head of Technology Risk & Compliance

GoDaddy (Pagely)

Nov 2021 - Mar 2025 (3 years 4 months)

Led technology risk management and compliance initiatives to strengthen Pagely’s security posture within GoDaddy, driving SOC 2 Type II compliance and automation-first evidence workflows. Implemented Drata for compliance monitoring, built a security maturity score framework for C-level reporting, and supported cost-efficiency initiatives while aligning cloud security policies with engineering and

PA

Head of Technology Risk & Compliance

Pagely

Mar 2021 - Mar 2025 (4 years)

Established Pagely’s compliance program from scratch as the first Compliance Manager and led the company through its first-ever SOC 2 Type II audit with clean reports in 2023 and 2024. Developed security controls and risk governance, automated compliance workflows using Drata, and strengthened vendor risk management to maintain ongoing audit readiness.

HM

Director of Cloud Operations

Human Made

Aug 2014 - Mar 2021 (6 years 7 months)

Led the Cloud Operations team for Altis, a high-performance AWS-based enterprise DXP serving millions of users daily, focusing on security, resilience, and operational efficiency. Drove cloud security governance and automation, including migrating from EC2 to containerization (ECS/ECR), improving scalability and deployment efficiency while enhancing observability and incident management for high-t

XS

WordPress R&D Engineer

X-Team / Stream

Apr 2014 - Aug 2014 (4 months)

Worked on cloud-based security, automation, and analytics for Stream’s WordPress activity logging and monitoring service. Built AWS infrastructure with Ansible-based automation, implemented Elasticsearch indexing for searchable logs, and integrated WordPress JSON REST API with logging and security monitoring pipelines.

EN

WordPress Evangelist

Envato

Sep 2011 - Apr 2014 (2 years 7 months)

Drove WordPress and Envato community engagement by delivering presentations and creating educational content that clarified complex technical topics for diverse audiences. Supported cross-functional community initiatives and sponsorships while building a trusted personal brand as a WordPress advocate.

Education

Degrees, certifications, and relevant coursework

Japheth hasn't added their education

Don't worry, there are 90k+ talented remote workers on Himalayas

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan