About The Position

CompassMSP delivers managed IT and managed security services to clients across regulated and enterprise markets. We are scaling our security division, and we are building the governance, risk, and compliance function that will carry it. This role leads that function and reports directly to the CISO. The mandate is broad by design. You will lead a multi framework compliance program spanning SOC 2 Type II, HITRUST CSF, and PCI DSS, with ISO 27001 on the roadmap behind them. You will select the platform configuration, the auditors, and the operating rhythm, and you will hire the team that runs it. You will also take that capability to market. Our clients need managed compliance programs, not one time assessments, and we intend to be the provider that delivers them. Compliance-as-a-Service is a defined offering in our growth plan, and this role owns it.

Requirements

  • Eight or more years in security, risk, or compliance.
  • At least three years leading a GRC function or multi framework program.
  • Compliance program experience inside an MSP, MSSP, or another multi tenant service provider.
  • Experience with at least one SOC 2 Type II audit from readiness to clean opinion.
  • Deep knowledge in two or more of: HITRUST CSF, PCI DSS, NIST CSF, NIST SP 800-171 and CMMC, ISO 27001.
  • Hands-on experience with a compliance automation platform (Vanta preferred).
  • Fluency with formal risk methodology.
  • Track record of running a risk register that executives use for decision-making.
  • Ability to explain risk as a business decision to executives and boards.
  • Leadership experience, including hiring and developing analysts.

Nice To Haves

  • CISA, CRISC, CISM, or CISSP certification.
  • HITRUST CCSFP certification.
  • PCI ISA or QSA certification.
  • CMMC RP or CCP certification.
  • Experience building a compliance service that clients paid for.
  • Experience in a private equity backed growth environment, including diligence support.

Responsibilities

  • Lead a multi framework compliance program spanning SOC 2 Type II, HITRUST CSF, and PCI DSS, with ISO 27001 on the roadmap.
  • Select the platform configuration, auditors, and operating rhythm for the compliance program.
  • Hire the team that will run the compliance function.
  • Take the compliance capability to market as a Compliance-as-a-Service offering.
  • Design, launch, and grow a tiered, recurring compliance offering for clients.
  • Develop and maintain the enterprise policy and ISMS framework.
  • Manage the enterprise risk register and its scoring methodology.
  • Provide quarterly risk reporting to the executive team and the board.
  • Manage the certification roadmap (SOC 2 Type II, HITRUST CSF, PCI DSS, ISO 27001).
  • Oversee the third party risk program.
  • Centralize the response capability for inbound client security questionnaires.
  • Provide compliance program support to the CMMC practice.
  • Participate in the Security Steering Committee.

Benefits

  • Competitive pay
  • Quarterly Bonuses
  • Progressive PTO
  • Medical/Dental/Vision/Life/Disability available
  • Tax deferred retirement plan with company match
  • Career Development and Coaching
  • Fun work environment!
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service