Director, Governance, Risk & Compliance

Posted 9hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Director of Governance, Risk & Compliance at CompassMSP leading compliance programs like SOC 2 and HITRUST. Overseeing risk management and team development in a managed services context.

Responsibilities:

  • The enterprise policy and ISMS framework. Control mapped, maintained in Vanta, and governed by a formal annual review and approval cycle.
  • The enterprise risk register, the scoring methodology behind it, and quarterly risk reporting to the executive team and the board.
  • The certification roadmap. SOC 2 Type II, then HITRUST CSF and PCI DSS, with ISO 27001 to follow. You select the auditors, run the programs, and deliver the opinions.
  • The third party risk program, and a centralized response capability for inbound client security questionnaires across SIG Lite, CAIQ, and custom formats.
  • Compliance-as-a-Service. A tiered, recurring compliance offering for our client base, from SOC 2 readiness at the SMB end through multi framework managed compliance at the enterprise end. You design it, launch it, and grow it.
  • Compliance program support to our CMMC practice, which serves defense industrial base clients and is pursuing C3PAO authorization.
  • A seat on the Security Steering Committee alongside the CEO, CFO, CTO, and VP of Operations.

Requirements:

  • Eight or more years in security, risk, or compliance, with at least three leading a GRC function or multi framework program.
  • Compliance program experience inside an MSP, MSSP, or another multi tenant service provider. This one matters. Service provider compliance is a different discipline from single enterprise compliance, and we are looking for someone who already knows the difference.
  • At least one SOC 2 Type II taken from readiness to clean opinion with you owning it.
  • Real depth in two or more of: HITRUST CSF, PCI DSS, NIST CSF, NIST SP 800-171 and CMMC, ISO 27001.
  • Hands on with a compliance automation platform. Vanta preferred, and you should be the person who configures the integrations, not the person who watches someone else do it.
  • Fluency with formal risk methodology and a track record of running a risk register that executives actually use to make decisions.
  • The ability to sit in front of a CEO or a board and explain risk as a business decision rather than a compliance demand.
  • Leadership experience. You have hired and developed analysts and you want to build a team, not just a program.
  • Nice to have****
  • CISA, CRISC, CISM, or CISSP. HITRUST CCSFP. PCI ISA or QSA. CMMC RP or CCP.
  • You have built a compliance service that clients paid for, not only a program that satisfied auditors.
  • Private equity backed growth environment experience, including diligence support.

Benefits:

  • Competitive pay
  • Quarterly Bonuses
  • Progressive PTO
  • Medical/Dental/Vision/Life/Disability available
  • Tax deferred retirement plan with company match
  • Career Development and Coaching
  • Fun work environment!