You will lead the governance, risk, and compliance function, overseeing multi-framework compliance programs and developing a 'Compliance-as-a-Service' offering. You will also manage the security steering committee, handle third-party risk, and build a team to support the company's scaling security division.
CompassMSP delivers managed IT and managed security services to clients across regulated and enterprise markets. We are scaling our security division, and we are building the governance, risk, and compliance function that will carry it. This role leads that function and reports directly to the CISO.
The mandate is broad by design. You will lead a multi framework compliance program spanning SOC 2 Type II, HITRUST CSF, and PCI DSS, with ISO 27001 on the roadmap behind them. You will select the platform configuration, the auditors, and the operating rhythm, and you will hire the team that runs it.
You will also take that capability to market. Our clients need managed compliance programs, not one time assessments, and we intend to be the provider that delivers them. Compliance-as-a-Service is a defined offering in our growth plan, and this role owns it.
- Eight or more years in security, risk, or compliance, with at least three leading a GRC function or multi framework program.
- Compliance program experience inside an MSP, MSSP, or another multi tenant service provider. This one matters. Service provider compliance is a different discipline from single enterprise compliance, and we are looking for someone who already knows the difference.
- At least one SOC 2 Type II taken from readiness to clean opinion with you owning it.
- Real depth in two or more of: HITRUST CSF, PCI DSS, NIST CSF, NIST SP 800-171 and CMMC, ISO 27001.
- Hands on with a compliance automation platform. Vanta preferred, and you should be the person who configures the integrations, not the person who watches someone else do it.
- Fluency with formal risk methodology and a track record of running a risk register that executives actually use to make decisions.
- The ability to sit in front of a CEO or a board and explain risk as a business decision rather than a compliance demand.
- Leadership experience. You have hired and developed analysts and you want to build a team, not just a program.
Nice to have
- CISA, CRISC, CISM, or CISSP. HITRUST CCSFP. PCI ISA or QSA. CMMC RP or CCP.
- You have built a compliance service that clients paid for, not only a program that satisfied auditors.
- Private equity backed growth environment experience, including diligence support.
- The enterprise policy and ISMS framework. Control mapped, maintained in Vanta, and governed by a formal annual review and approval cycle.
- The enterprise risk register, the scoring methodology behind it, and quarterly risk reporting to the executive team and the board.
- The certification roadmap. SOC 2 Type II, then HITRUST CSF and PCI DSS, with ISO 27001 to follow. You select the auditors, run the programs, and deliver the opinions.
- The third party risk program, and a centralized response capability for inbound client security questionnaires across SIG Lite, CAIQ, and custom formats.
- Compliance-as-a-Service. A tiered, recurring compliance offering for our client base, from SOC 2 readiness at the SMB end through multi framework managed compliance at the enterprise end. You design it, launch it, and grow it.
- Compliance program support to our CMMC practice, which serves defense industrial base clients and is pursuing C3PAO authorization.
- A seat on the Security Steering Committee alongside the CEO, CFO, CTO, and VP of Operations.
- Competitive pay
- Quarterly Bonuses
- Progressive PTO
- Medical/Dental/Vision/Life/Disability available
- Tax deferred retirement plan with company match
- Career Development and Coaching
- Fun work environment!
Our Commitment to Inclusion: Step into a role that respects your individuality and supports your growth. CompassMSP is proud to be an Equal Opportunity Employer.
CompassMSP is committed to fair and equitable compensation practices. Salary range will reflect experience, location and other factors. This position is eligible for an annual bonus.