Head of Compliance at Compass managing enterprise risk, information security, and multi-jurisdictional regulatory compliance. Building compliance frameworks in an exciting high-growth SaaS environment.
Responsibilities
Oversee compliance across payment operations, third-party providers and key commercial partners.
Establish and standardise onboarding, compliance requirements and documentation processes.
Lead external compliance audits and act as the primary liaison with partners and assessors.
Identify and implement process improvements and automation to improve efficiency and reduce manual effort.
Lead ISO 27001 certification and ongoing ISMS maintenance across Australian and international entities.
Own audit preparation, evidence gathering and control documentation, driving a shift to continuous audit readiness.
Manage risk assessments and maintain the risk register, escalating material findings where required.
Support expansion into the UK and Ireland, ensuring alignment with GDPR, UK GDPR and NIS2.
Partner with Product and Engineering to embed security and compliance-by-design principles.
Oversee alignment with PCI-DSS and other relevant data security standards.
Provide compliance input into new products, commercial initiatives and customer contracts.
Develop, maintain and embed compliance policies and procedures across the organisation.
Deliver training and awareness programs across privacy, information security and payments.
Monitor regulatory developments (ASIC, APRA, OAIC, ICO, CBI) and advise on required actions.
Establish and maintain a compliance monitoring and assurance program.
Drive a culture of proactive risk identification and accountability.
Maintain and report on the compliance risk register to the General Counsel, CFO and Board.
Build relationships with regulators and key external partners.
Support Legal on complex or high-risk compliance matters, escalating clearly and early.
Requirements
3–6 years’ experience in compliance, risk or information security within a regulated or technology environment.
Proven experience operating as the primary or sole compliance owner in a previous role.
Hands-on experience with ISO 27001, including certification or ISMS management.
Exposure to multi-jurisdictional compliance, including UK and/or Irish regulatory environments.
Strong process mindset, with the ability to design practical, scalable compliance frameworks.
Clear and confident communication skills, translating regulatory complexity into actionable guidance.
Highly regarded:
Experience in payments, acquiring or merchant services environments.
Exposure to Australian Privacy Act, GDPR or UK GDPR.
Experience in a scaling SaaS, fintech or EdTech business.
Relevant compliance qualifications (e.g. ICA).
Familiarity with PayTo, NPP or Open Banking compliance.
Benefits
A hybrid working environment, with teams working a hybrid structure in our office hubs.
Learning and development opportunities, including a dedicated PD budget.
24/7 access to our Employee Assistance Program (EAP), including face-to-face, phone and live chat support.
A parental leave program for both primary and secondary carers.
Regular team events, social budgets and in-office perks help you stay connected, from team lunches to end-of-week socials.
Employee Referral Program
A supportive, inclusive culture where your voice is valued and heard.
Regional Regulatory Lead overseeing EUCAN regulatory strategy for pharmaceutical projects and products. Planning submissions, coordinating meetings, and collaborating with regulatory authorities.
Manager Regulatory Affair at Capgemini Engineering coordinating activities for the US market. Preparing submissions to the FDA and collaborating with internal teams for regulatory compliance.
Engineer IT Compliance responsible for compliance activities in regulated IT systems. Building partnerships with IT functions and ensuring regulatory alignment in pharmaceutical industry.
Regulatory Affairs Associate for managing new drug registrations and preparing documentation in the India Market. Collaborating with stakeholders and supporting compliance in bulk drug registration.
Senior Tech Compliance Analyst at Syneos Health responsible for global Technology Disaster Recovery efforts, collaborating with various teams and service providers.
Chief Nuclear Officer serving as the nuclear safety authority for BaRupOn's SMR/MMR programs. Establishing safety frameworks and ensuring regulatory compliance within the organization.
International Trade Compliance Manager overseeing compliance with international trade regulations at Northrop Grumman. Leading a team and managing compliance initiatives across multiple locations in the US.
Compliance Manager leading Autodesk's Enterprise Compliance program. Ensuring compliance with SOX, PCI regulations and overseeing security controls across teams.
Compliance Student supporting compliance and risk management activities for individual insurance at iA Financial Group. Involves monitoring processes, collaborating with teams, and assisting with compliance tasks.
Nurse Licensure & Compliance Coordinator managing multi - state nurse licensure and compliance inquiries while ensuring a positive nurse experience. Advocating for nurses and maintaining regulatory adherence at the organization.