Director, Security & Compliance

MHC•Burnsville, MN
•Remote

About The Position

MHC is a global provider of AI-powered SaaS solutions for document, communication, and payment automation, purpose-built for highly regulated industries. Our platform helps enterprise and mid-market organizations improve efficiency, ensure compliance, and modernize customer communications at scale. We are seeking a hands-on Director, Security and Compliance to build and own our security, data governance, and AI governance program as we scale. This is a rare "own it end to end" role where you will be the single point of accountability for keeping customer trust, data, and AI systems secure and audit-ready. This role sits at the intersection of security compliance (SOC 2 and beyond), data governance, and AI governance/risk. You'll set the strategy and also do the work writing policies, running access reviews, managing auditors, and answering enterprise security questionnaires. Maintaining our SOC 2 Type II report is a top priority.

Requirements

  • Direct, hands-on experience operating and renewing an existing SOC 2 Type II program including managing annual/ongoing audit cycles.
  • Working knowledge of data governance practices; classification, retention, access review, and privacy regulations (CCPA/GDPR).
  • Familiarity with AI governance concepts and frameworks (NIST AI RMF, OWASP LLM Top 10, ISO 42001).
  • Comfort operating without a large team or established playbook; equally comfortable writing a policy and configuring a compliance automation tool yourself.
  • Strong written and verbal communication skills as you'll translate technical risk into plain language for executives, auditors, and enterprise customers.
  • Experience with compliance automation platforms (Vanta, Drata, Secureframe, or similar).
  • Vendor/third-party risk assessment and management skills.
  • Ability to build credibility directly with enterprise customers and prospects on security and trust topics.
  • Bachelor’s degree in Computer Science, Information Security, or a related field.
  • 6+ years of experience across security, compliance, IT/GRC, or risk management.
  • At least 2+ years running a SOC 2 program day-to-day (evidence collection, control monitoring, auditor management).

Nice To Haves

  • CISSP, CISM, CIPP, or CISA
  • Experience achieving or maintaining ISO 27001 or ISO 42001

Responsibilities

  • Own the renewal and continuous operation of our SOC 2 Type II report and serve as primary liaison to our audit firm.
  • Mature the existing control environment: reduce manual evidence collection, tighten scope as new products/systems come online, and keep controls audit-ready year-round.
  • Develop, document, and operate controls that maximize risk mitigation and remain compliant with our target regulatory frameworks (SOC 2 Type II, HIPAA, PCI, GDPR/CCPA), and work directly with auditors to ensure ongoing compliance.
  • Expand our attestation footprint as needed based on customer and market demand (ISO 27001, HIPAA, GDPR/CCPA, or SOC 2 + additional Trust Services Criteria like Privacy).
  • Serve as the primary point of contact for customer security reviews, questionnaires, and due-diligence requests during the sales cycle.
  • Maintain the company's security policy suite, risk register, and incident response plan; run tabletop exercises.
  • Establish data classification, retention, and access-control standards across production systems, data warehouses, and SaaS tools.
  • Partner with engineering to implement least-privilege access, encryption standards, and data lifecycle management.
  • Develop and implement secure software development lifecycle (SDLC) policies in partnership with engineering, along with environmental and physical security standards.
  • Own vendor/third-party risk management, including security review of new SaaS and AI tools before adoption.
  • Assist Legal with customer and vendor contractual negotiations related to security and data privacy obligations.
  • Build the company's AI governance framework: acceptable use policies, model/vendor risk assessment, and oversight of how AI features and internal AI tools handle customer and employee data.
  • Track emerging AI-specific standards (NIST AI RMF, ISO 42001) and translate them into practical, lightweight controls appropriate for our stage.
  • Partner with product/engineering on responsible AI practices for customer-facing AI features (data usage disclosures, model risk review, opt-out mechanisms).
  • Provide security and compliance input on shadow AI risk — discovery and governance of AI tools used across the company.
  • Act as a trusted advisor to the executive team and board on security and compliance posture.
  • Partner with Sales and Customer Success as a credible technical voice in enterprise deals.
  • Build out the security/compliance function.

Benefits

  • Workplace Flexibility
  • 401(k) Plan: Deferred and Roth options available to help you save for retirement, with a generous employer match of 50% up to maximum of 4.5% of gross pay.
  • Medical Plans: Comprehensive co-pay or HSA coverage options to keep you and your family healthy.
  • Dental and Vision Plans: Access to a large network of providers for dental and vision health.
  • Daycare and Medical FSA/HSA: Save on eligible daycare and healthcare expenses with our flexible spending and health savings account plans.
  • Group Term Life Insurance: Coverage of $50,000 to provide peace of mind.
  • Generous Paid Time Off (PTO) Policies: Ample time to relax and recharge.
  • Employee Assistance Program (EAP): Support for personal and professional challenges.
  • Voluntary Benefits Available: Additional Life Insurance, Critical Illness Insurance, Accident, Cancer & Hospital Indemnity Insurance, Legal/ID Shield, Pet Insurance.
  • Parental Leave: Four weeks of paid paternity leave, available after one year of employment, with partial eligibility beginning at six months. Twelve weeks of paid leave for the birth parent, eligibility rules apply.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service