Director, Governance, Risk & Compliance
Posted 9hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Director of Governance, Risk & Compliance at CompassMSP leading compliance programs like SOC 2 and HITRUST. Overseeing risk management and team development in a managed services context.
Responsibilities:
- The enterprise policy and ISMS framework. Control mapped, maintained in Vanta, and governed by a formal annual review and approval cycle.
- The enterprise risk register, the scoring methodology behind it, and quarterly risk reporting to the executive team and the board.
- The certification roadmap. SOC 2 Type II, then HITRUST CSF and PCI DSS, with ISO 27001 to follow. You select the auditors, run the programs, and deliver the opinions.
- The third party risk program, and a centralized response capability for inbound client security questionnaires across SIG Lite, CAIQ, and custom formats.
- Compliance-as-a-Service. A tiered, recurring compliance offering for our client base, from SOC 2 readiness at the SMB end through multi framework managed compliance at the enterprise end. You design it, launch it, and grow it.
- Compliance program support to our CMMC practice, which serves defense industrial base clients and is pursuing C3PAO authorization.
- A seat on the Security Steering Committee alongside the CEO, CFO, CTO, and VP of Operations.
Requirements:
- Eight or more years in security, risk, or compliance, with at least three leading a GRC function or multi framework program.
- Compliance program experience inside an MSP, MSSP, or another multi tenant service provider. This one matters. Service provider compliance is a different discipline from single enterprise compliance, and we are looking for someone who already knows the difference.
- At least one SOC 2 Type II taken from readiness to clean opinion with you owning it.
- Real depth in two or more of: HITRUST CSF, PCI DSS, NIST CSF, NIST SP 800-171 and CMMC, ISO 27001.
- Hands on with a compliance automation platform. Vanta preferred, and you should be the person who configures the integrations, not the person who watches someone else do it.
- Fluency with formal risk methodology and a track record of running a risk register that executives actually use to make decisions.
- The ability to sit in front of a CEO or a board and explain risk as a business decision rather than a compliance demand.
- Leadership experience. You have hired and developed analysts and you want to build a team, not just a program.
- Nice to have****
- CISA, CRISC, CISM, or CISSP. HITRUST CCSFP. PCI ISA or QSA. CMMC RP or CCP.
- You have built a compliance service that clients paid for, not only a program that satisfied auditors.
- Private equity backed growth environment experience, including diligence support.
Benefits:
- Competitive pay
- Quarterly Bonuses
- Progressive PTO
- Medical/Dental/Vision/Life/Disability available
- Tax deferred retirement plan with company match
- Career Development and Coaching
- Fun work environment!
















