Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
CompassMSP

Director, Governance, Risk & Compliance

CompassMSP

Director of Governance, Risk & Compliance at CompassMSP leading compliance programs like SOC 2 and HITRUST. Overseeing risk management and team development in a managed services context.

Posted 8/1/2026full-timeRemote • 🇺🇸 United StatesLeadWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates extensive experience in security, risk, and compliance, with a strong focus on leading GRC functions and multi-framework programs. Proven ability to design and implement compliance services, manage risk registers, and communicate risk as a business decision to executive leadership.

Highest-signal resume keywords
GRC Function LeadershipSOC 2 Type II OwnershipCompliance Automation Platform ConfigurationHITRUST CSF ExpertiseRisk Methodology Fluency

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Security Risk ManagementCompliance Program DevelopmentRisk Register ManagementMulti-Framework ComplianceCompliance-as-a-Service Design
Soft Skills
LeadershipCommunicationTeam Building
Tools & Technologies
VantaCompliance Automation Platforms
Certifications & Qualifications
CISACRISCCISMCISSPHITRUST CCSFPPCI ISACMMC RP
Industry Keywords
SOC 2HITRUST CSFPCI DSSNIST CSFNIST SP 800-171CMMCISO 27001MSPMSSPPrivate Equity

About the role

Key responsibilities & impact
  • The enterprise policy and ISMS framework. Control mapped, maintained in Vanta, and governed by a formal annual review and approval cycle.
  • The enterprise risk register, the scoring methodology behind it, and quarterly risk reporting to the executive team and the board.
  • The certification roadmap. SOC 2 Type II, then HITRUST CSF and PCI DSS, with ISO 27001 to follow. You select the auditors, run the programs, and deliver the opinions.
  • The third party risk program, and a centralized response capability for inbound client security questionnaires across SIG Lite, CAIQ, and custom formats.
  • Compliance-as-a-Service. A tiered, recurring compliance offering for our client base, from SOC 2 readiness at the SMB end through multi framework managed compliance at the enterprise end. You design it, launch it, and grow it.
  • Compliance program support to our CMMC practice, which serves defense industrial base clients and is pursuing C3PAO authorization.
  • A seat on the Security Steering Committee alongside the CEO, CFO, CTO, and VP of Operations.

Requirements

What you’ll need
  • Eight or more years in security, risk, or compliance, with at least three leading a GRC function or multi framework program.
  • Compliance program experience inside an MSP, MSSP, or another multi tenant service provider. This one matters. Service provider compliance is a different discipline from single enterprise compliance, and we are looking for someone who already knows the difference.
  • At least one SOC 2 Type II taken from readiness to clean opinion with you owning it.
  • Real depth in two or more of: HITRUST CSF, PCI DSS, NIST CSF, NIST SP 800-171 and CMMC, ISO 27001.
  • Hands on with a compliance automation platform. Vanta preferred, and you should be the person who configures the integrations, not the person who watches someone else do it.
  • Fluency with formal risk methodology and a track record of running a risk register that executives actually use to make decisions.
  • The ability to sit in front of a CEO or a board and explain risk as a business decision rather than a compliance demand.
  • Leadership experience. You have hired and developed analysts and you want to build a team, not just a program.
  • Nice to have****
  • CISA, CRISC, CISM, or CISSP. HITRUST CCSFP. PCI ISA or QSA. CMMC RP or CCP.
  • You have built a compliance service that clients paid for, not only a program that satisfied auditors.
  • Private equity backed growth environment experience, including diligence support.

Benefits

Comp & perks
  • Competitive pay
  • Quarterly Bonuses
  • Progressive PTO
  • Medical/Dental/Vision/Life/Disability available
  • Tax deferred retirement plan with company match
  • Career Development and Coaching
  • Fun work environment!