FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
C
Head of Risk, Compliance and Information Security
Compass Education. Lead Compass's risk, compliance and information security functions .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates extensive experience in compliance, risk management, and information security leadership, with a strong focus on PCI DSS and ISO 27001 compliance. Capable of translating complex regulatory requirements into actionable policies and frameworks while effectively communicating with stakeholders at all levels.
Highest-signal resume keywords
PCI DSS Compliance ManagementISO 27001 Certification LeadershipMulti-Jurisdictional Compliance ExperienceStakeholder Communication SkillsRegulatory Framework Design
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Risk ManagementCompliance AuditingInformation Security Management System (ISMS)Privacy Impact AssessmentsData ClassificationRegulatory Breach NotificationsContract ReviewTechnical Requirements TranslationGovernance Framework DesignData Protection Compliance
Soft Skills
Strong Communication SkillsStakeholder EngagementProblem-SolvingCollaboration
Tools & Technologies
SaaSFintechCloud Infrastructure ComplianceOpen Banking CompliancePayments Compliance
Certifications & Qualifications
ISO 27001PCI DSSICACIPPCISSPCISM
Industry Keywords
Australian Privacy PrinciplesGDPRLegal Risk ManagementData GovernanceRecords Management
Tech Stack
Tools & technologiesCloudGoogle Cloud Platform
About the role
Key responsibilities & impact- Lead Compass's risk, compliance and information security functions
- Own certification and audit programmes, including ISO 27001 and PCI DSS
- Maintain the ISMS and manage certification audits and corrective actions
- Scope and maintain PCI DSS compliance for payment processing
- Manage obligations under the Australian Privacy Principles and equivalent UK and Irish regimes
- Conduct privacy impact assessments and privacy-by-design sign-off
- Handle privacy complaints
- Manage information governance, including data classification, retention, disposal and records management
- Own the security and information policy suite with technical input from technology leaders
- Manage regulatory breach notifications and compliance clauses in customer and government contracts
- Respond to customer and government due diligence questionnaires
- Maintain the compliance risk register
- Aggregate information security posture and risk into quarterly reports for the ELT and Board
- Ensure vendor contracts include appropriate data protection and security clauses
- Line manage Legal Counsel
- Oversee legal risk and contract review as part of the broader governance remit
Requirements
What you’ll need- 6+ years in compliance, risk or information security leadership
- Experience in a SaaS, fintech or regulated technology environment
- Experience owning PCI DSS compliance end to end
- Hands-on ISO 27001 experience, having led a certification or maintained an ISMS end to end
- Multi-jurisdictional compliance experience, including practical application of the AU Privacy Act and GDPR
- Practical knowledge of a recognised security framework and translating it into implementable technical requirements
- Experience presenting risk and compliance posture to a Board or Audit & Risk Committee
- Experience designing frameworks and policies from scratch
- Strong stakeholder communication skills
- Ability to translate regulatory and technical complexity into clear, commercial language
- Ability to work as a peer with technical leaders rather than as their manager
- Valid Employee Working With Children Check required before commencing employment
- Satisfactory National Police Check required before commencing employment
- Unrestricted work rights in Australia required before commencing employment
- Highly regarded: experience in payments, acquiring or merchant services environments
- Highly regarded: familiarity with PayTo, NPP or Open Banking compliance
- Highly regarded: experience in a scaling SaaS, EdTech or fintech business
- Highly regarded: ICA, CIPP, CISSP, CISM or equivalent qualifications
- Highly regarded: exposure to GCP or cloud-first infrastructure compliance
Benefits
Comp & perks- Hybrid working environment at office hubs
- Learning and development opportunities
- Dedicated professional development budget
- 24/7 Employee Assistance Program (EAP), including face-to-face, phone and live chat support
- Parental leave program for primary and secondary carers
- Regular team events
- Social budgets
- In-office perks, including team lunches and end-of-week socials
- Employee Referral Program
- Supportive, inclusive culture
- Equal opportunity employer committed to diversity and inclusion