Head of Compliance

mpathic
Hybrid

About The Position

mpathic is seeking a mid-level attorney to serve as Head of Compliance, owning day-to-day compliance across the company. This work supports high-velocity AI safety, human data, and evaluation projects with leading AI companies. Reporting to our Chief Operations Officer/Chief Legal Officer, you will help build and operate a world-class compliance program spanning legal and regulatory compliance, SOC 2 and information security compliance, company-wide policy compliance, and AI safety and customer contractual compliance during active campaigns. You will be the connective tissue between legal requirements and operational execution. When campaigns launch, you will translate customer contractual requirements, industry best practices, and legal obligations into clear, auditable processes for cross-functional teams (operations, HR, clinical experts, red teamers, annotators, TPMs, and reviewers). You will support confidential initiatives involving AI safety protocols, red teaming, model behavior evaluation, policy testing, and human data workflows, which may include exposure to sensitive information and content. You will also own and mature our SOC 2 program: maintaining controls, coordinating evidence collection, managing audit cycles, and driving remediation. Beyond SOC 2, you will monitor the evolving legal landscape around AI, data privacy, and human data work, identify gaps, and build a best-in-class compliance function that keeps us true to our strong commitment to safety, ethics, confidentiality, and execution quality. You will also own legal compliance in general, alongside the General Counsel and Chief Legal officer, to research, implement, and draft policies, review changing legal landscapes, handle employment law matters, immigration questions, international legal questions, intellectual property, and more. This role is ideal for an attorney who enjoys operationalizing legal requirements in a fast-moving AI safety environment. Strong candidates are proactive, reliable, highly organized, and comfortable balancing autonomy with timely escalation. You do not need to be a clinician or machine learning expert, but you should be comfortable working closely with clinical, research, operations, product, and technical teams. This job requires flexible hours to manage client project velocity. It also may require the willingness and ability to travel to brick and mortar office spaces, as necessary, when campaigns launch. We highly value work/life balance and encourage all team members to work reasonable hours, but want to be up-front that working hours can ebb and flow depending on active campaigns. This role sits on the G&A team and partners closely with Legal, Human Data leadership, clinical experts, red team leadership, HR, and operations. It will require the ability to travel to brick and mortar offices when campaigns launch.

Requirements

  • Hold a JD from an accredited law school and are an active member in good standing of at least one U.S. state bar.
  • Have 3–6 years of legal experience with a substantial compliance focus, in-house, at a law firm, or in a regulatory setting.
  • Have hands-on experience with SOC 2 (or comparable frameworks such as ISO 27001), including audits, control design, or evidence management.
  • Are experienced reading and operationalizing commercial contracts — turning customer requirements into processes teams can actually follow.
  • Have familiarity with data privacy and AI-related regulatory frameworks (e.g., HIPAA, GDPR/CCPA, emerging AI governance standards) — or the demonstrated ability to get up to speed quickly.
  • Are comfortable working in fast-moving, ambiguous environments where priorities shift and clear communication matters.

Nice To Haves

  • You do not need to be a clinician or machine learning expert, but you should be comfortable working closely with clinical, research, operations, product, and technical teams.

Responsibilities

  • Build out compliance processes and systems, including a compliance calendar, risk register, and escalation paths.
  • Take ownership of the SOC 2 program: control monitoring, evidence collection, audit coordination, and remediation tracking.
  • Develop campaign launch compliance protocols that map customer contractual requirements to operational checklists, and coordinate cross-functional alignment on them.
  • Review and update company policies (confidentiality, data handling, acceptable use, vendor management).
  • Develop and conduct compliance trainings across the company.
  • Take over ownership of insurance and maintaining our certificates and renewals.
  • Establish a contractual compliance review cadence for active campaigns, verifying adherence to customer requirements and documenting compliance.
  • Build a roadmap of compliance programs, controls, and processes to help the company scale with new campaigns.
  • Develop and supervise the company's first legal externship program.
  • Own day-to-day compliance across the company.
  • Help build and operate a world-class compliance program spanning legal and regulatory compliance, SOC 2 and information security compliance, company-wide policy compliance, and AI safety and customer contractual compliance during active campaigns.
  • Translate customer contractual requirements, industry best practices, and legal obligations into clear, auditable processes for cross-functional teams.
  • Support confidential initiatives involving AI safety protocols, red teaming, model behavior evaluation, policy testing, and human data workflows.
  • Maintain SOC 2 controls, coordinate evidence collection, manage audit cycles, and drive remediation.
  • Monitor the evolving legal landscape around AI, data privacy, and human data work, identify gaps, and build a best-in-class compliance function.
  • Own legal compliance in general, research, implement, and draft policies, review changing legal landscapes, handle employment law matters, immigration questions, international legal questions, intellectual property, and more.

Benefits

  • work/life balance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service