For Employers

MHC

Director, Security & Compliance

Posted 2 hours ago
5-10 years experience
Apply Now

Please mention DailyRemote when applying

?
Resume Match Score

See how much of this job your resume covers, and what’s missing.

Want a recruiter to go through it line by line?

Get professional review

Create a cover letter for this job

Upload your resume and we draft a letter for this exact role, tailored to what it asks for.

  • Tailored to this role
  • Based on your resume
  • Fully editable
AI Summary

The Director of Security and Compliance will own the end-to-end security, data governance, and AI governance programs, ensuring the company remains audit-ready. This role involves managing SOC 2 Type II renewals, developing security policies, and partnering with engineering and sales to maintain a robust control environment.

Who we are:

MHC is a global provider of AI-powered SaaS solutions for document, communication, and payment automation - purpose-built for highly regulated industries. We simplify complexity and unlock intelligence so organizations can deliver exceptional experiences with confidence.


Our platform helps enterprise and mid-market organizations improve efficiency, ensure compliance, and modernize customer communications at scale. Customers use MHC solutions to generate more than 10 billion documents and process billions in AP payments annually. Recognized as a Leader in multiple G2 reports and featured in analyst reports from Gartner, IDC, Aspire, and Aragon, MHC is built for organizations that can't afford to get it wrong.


People are at the center of everything we do - for our customers and within our own walls. MHC supports a flexible, work-where-you-live model, and for five consecutive years has been named one of Minnesota's Top Workplaces by the Star Tribune, based entirely on employee feedback. We are a team driven to grow, committed to being better than yesterday, and stronger together. We earn trust every day with our customers, our partners, and each other. We experiment boldly, and when our customers win, we win.


For more information, visit mhcautomation.com.



Who we are looking for:

We are seeking a hands-on Director, Security and Compliance to build and own our security, data governance, and AI governance program as we scale. This is a rare "own it end to end" role. You won't be managing a large team or inheriting a mature GRC function. You'll be the single point of accountability for keeping customer trust, data, and AI systems secure and audit-ready, while working shoulder to shoulder with engineering, product, and sales.

 

This role sits at the intersection of three disciplines that are converging fast in AI-native companies: security compliance (SOC 2 and beyond), data governance, and AI governance/risk. You'll set the strategy and also do the work writing policies, running access reviews, managing auditors, and answering enterprise security questionnaires. This is also a certification-critical role. Maintaining our SOC 2 Type II report is a top-priority.



What you will get to do:

Security & Compliance Program

  • Own the renewal and continuous operation of our SOC 2 Type II report and serve as primary liaison to our audit firm
  • Mature the existing control environment: reduce manual evidence collection, tighten scope as new products/systems come online, and keep controls audit-ready year-round rather than sprinting before each renewal
  • Develop, document, and operate controls that maximize risk mitigation and remain compliant with our target regulatory frameworks (SOC 2 Type II, HIPAA, PCI, GDPR/CCPA), and work directly with auditors to ensure ongoing compliance
  • Expand our attestation footprint as needed based on customer and market demand (ISO 27001, HIPAA, GDPR/CCPA, or SOC 2 + additional Trust Services Criteria like Privacy)
  • Serve as the primary point of contact for customer security reviews, questionnaires, and due-diligence requests during the sales cycle
  • Maintain the company's security policy suite, risk register, and incident response plan; run tabletop exercises


Data Governance

  • Establish data classification, retention, and access-control standards across production systems, data warehouses, and SaaS tools
  • Partner with engineering to implement least-privilege access, encryption standards, and data lifecycle management
  • Develop and implement secure software development lifecycle (SDLC) policies in partnership with engineering, along with environmental and physical security standards
  • Own vendor/third-party risk management, including security review of new SaaS and AI tools before adoption
  • Assist Legal with customer and vendor contractual negotiations related to security and data privacy obligations


AI Governance & Risk

  • Build the company's AI governance framework: acceptable use policies, model/vendor risk assessment, and oversight of how AI features and internal AI tools handle customer and employee data
  • Track emerging AI-specific standards (NIST AI RMF, ISO 42001) and translate them into practical, lightweight controls appropriate for our stage
  • Partner with product/engineering on responsible AI practices for customer-facing AI features (data usage disclosures, model risk review, opt-out mechanisms)
  • Provide security and compliance input on shadow AI risk — discovery and governance of AI tools used across the company


Leadership & Cross-Functional Partnership

  • Act as a trusted advisor to the executive team and board on security and compliance posture
  • Partner with Sales and Customer Success as a credible technical voice in enterprise deals
  • Build out the security/compliance function

 

What Success Looks Like in This Role:

  • Every SOC 2 Type II audit cycle closes with zero exceptions and no gaps in control coverage between periods
  • Evidence collection and control monitoring run continuously in the background (via automation tooling)
  • Enterprise security questionnaires and customer due-diligence requests are turned around quickly and don't bottleneck sales cycles
  • A documented, living AI governance framework is in place and actually used and new AI tools and features get risk-reviewed before adoption, not after an incident
  • Data classification, retention, and access-control standards are documented, adopted by engineering, and hold up under audit scrutiny
  • Executives and the board have a clear, current view of security/compliance position and risk at all times
  • The security/compliance function scales appropriately as the company grows


Knowledge and Skills: 

  • Direct, hands-on experience operating and renewing an existing SOC 2 Type II program including managing annual/ongoing audit cycles
  • Working knowledge of data governance practices; classification, retention, access review, and privacy regulations (CCPA/GDPR)
  • Familiarity with AI governance concepts and frameworks (NIST AI RMF, OWASP LLM Top 10, ISO 42001) you don't need to be an ML engineer, but you need to speak the language credibly
  • Comfort operating without a large team or established playbook; equally comfortable writing a policy and configuring a compliance automation tool yourself
  • Strong written and verbal communication skills as you'll translate technical risk into plain language for executives, auditors, and enterprise customers
  • Experience with compliance automation platforms (Vanta, Drata, Secureframe, or similar)
  • Vendor/third-party risk assessment and management skills
  • Ability to build credibility directly with enterprise customers and prospects on security and trust topics


Education and Qualifications: 

  • Bachelor’s degree in Computer Science, Information Security, or a related field
  • 6+ years of experience across security, compliance, IT/GRC, or risk management
  • At least 2+ years running a SOC 2 program day-to-day (evidence collection, control monitoring, auditor management)

 

Preferred Certifications

  • CISSP, CISM, CIPP, or CISA
  • Experience achieving or maintaining ISO 27001 or ISO 42001



Worksite Location: This is a remote role. Candidates must be based in the United States. Regular travel is expected for partner meetings, business reviews, industry events, and company gatherings.


This role is not eligible for visa sponsorship.



MHC Comprehensive Benefits Package

We offer a robust benefits package designed to support the well-being and financial security of our employees. 

Our Benefits Include:

  • Workplace Flexibility
  • 401(k) Plan: Deferred and Roth options available to help you save for retirement, with a generous employer match of 50% up to maximum of 4.5% of gross pay.
  • Medical Plans: Comprehensive co-pay or HSA coverage options to keep you and your family healthy.
  • Dental and Vision Plans: Access to a large network of providers for dental and vision health. 
  • Daycare and Medical FSA/HSA: Save on eligible daycare and healthcare expenses with our flexible spending and health savings account plans.
  • Group Term Life Insurance: Coverage of $50,000 to provide peace of mind.
  • Generous Paid Time Off (PTO) Policies: Ample time to relax and recharge.
  • Employee Assistance Program (EAP): Support for personal and professional challenges.

 

 Voluntary Benefits Available:

  • Additional Life Insurance
  • Critical Illness Insurance
  • Accident, Cancer & Hospital Indemnity Insurance
  • Legal/ID Shield
  • Pet Insurance

 

Parental Leave:

If your state offers a paid family or medical leave program, you will have access to those benefits. For employees in states without a state program, we offer:

  • Four weeks of paid paternity leave, available after one year of employment, with partial eligibility beginning at six months.
  • Twelve weeks of paid leave for the birth parent, eligibility rules apply.



We are proud to be an equal opportunity employer and welcome our employee’s differences, regardless of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, or Veteran status. Different makes us better - Join us. 

 

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

 

While we may use AI tools to support parts of our hiring process, applicants and candidates may not use AI tools (such as chatbots, writing assistants, or real-time response generators etc.) to complete application materials, assessments, or interviews. Responses should reflect your own knowledge, skills, and communication style. If our review indicates that AI was used in a manner inconsistent with this expectation, we will not move forward with your candidacy.

Automatically Apply to the Best Remote Jobs

Stop the endless job search. Our AI finds and applies to the best jobs for you.

Try it Now
Keep looking

Similar Jobs

See all Remote Legal jobs →

Family Law Paralegal

Full Time United States Legal

Creditors Rights Paralegal

Full Time United States Legal

Transportation Claims & Subrogation Specialist

Full Time United States Legal

Senior Trial Paralegal

Other United States $48 - $58 per hour Legal

Regulatory Affairs Specialist - APAC

Full Time Japan, Singapore, South Korea +1 more Legal

Senior Regulatory Medical Writer, Client-embedded, FSP

Full Time United States Legal
Apply Now

Personalize your Remote Job Search in 3 Easy Steps!

Featuring 220,524+ Jobs in Legal

Answer easy questions

Answer easy questions

220,524+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified