About the Role
Reporting to the Chief Financial Officer, this is a newly created, hands-on, standalone role. It is an opportunity to build a structured compliance function from the ground up, working alongside a pragmatic in-house legal function in a high-growth SaaS environment. The role spans three core domains: enterprise risk and governance, information security (ISO 27001), and multi-jurisdictional regulatory compliance across Australia, the UK, and Ireland, with oversight of operational and third-party compliance (including payment ecosystems).
Responsibilities
- Lead ISO 27001 certification and ongoing ISMS maintenance across Australian and international entities.
- Own audit preparation, evidence gathering and control documentation - driving continuous audit readiness.
- Manage risk assessments and maintain the risk register, escalating material findings as required.
- Partner with Product and Engineering to embed compliance-by-design across the platform.
- Support UK and Ireland expansion with practical GDPR, UK GDPR and NIS2 compliance frameworks.
- Develop and embed compliance policies and procedures across the organisation.
- Monitor regulatory developments across ASIC, APRA, OAIC, ICO, CBI and translate them into action.
- Deliver training and awareness programs across privacy, information security and payments.
- Provide compliance input into new products, commercial initiatives and customer contracts.
- Oversee compliance across payment operations, third-party providers and key commercial partners.
- Lead external compliance audits and act as the primary liaison with partners and assessors.
- Build scalable onboarding and compliance documentation processes.
- Identify and implement automation workflows to reduce manual compliance effort.
- Establish and maintain a compliance monitoring and assurance program.
- Maintain and report on the compliance risk register to the Legal Counsel, CFO and Board.
- Build relationships with regulators and key external partners.
- Drive a culture of proactive risk identification across the business.
Requirements
- 4+ years’ experience in compliance, risk or information security, ideally within a SaaS, fintech or regulated technology environment.
- Proven experience as the primary or sole compliance owner.
- Hands-on ISO 27001 experience - led a certification or maintained an ISMS end to end.
- Multi-jurisdictional compliance experience, including practical application of the AU Privacy Act and GDPR.
- A builder's mindset - design frameworks that are practical and scalable.
- Strong stakeholder communication skills - translate regulatory complexity into clear, commercial language.
- Experience in payments, acquiring or merchant services environments.
- Familiarity with PayTo, NPP or Open Banking compliance.
- Experience in a scaling SaaS, EdTech or fintech business.
- Exposure to GCP or cloud-first infrastructure compliance.
- A valid Employee Working With Children Check.
- A satisfactory National Police Check.
- Verification of unrestricted work rights in Australia.
Skills
- Compliance
- Risk Management
- Information Security
- SaaS
- Fintech
- Regulated Technology
- ISO 27001
- ISMS
- GDPR
- UK GDPR
- NIS2
- ASIC
- APRA
- OAIC
- ICO
- CBI
- Payments
- NPP
- Open Banking
- GCP
- Cloud-first infrastructure
Location
- Australia
- UK
- Ireland
Work Type
- Hybrid
Experience Level
- 4+ years experience
- Primary or sole compliance owner experience
Education Level
- Relevant qualifications (e.g. ICA, CIPP, CISSP or equivalent)
Benefits
- Learning and development opportunities
- Dedicated PD budget
- 24/7 access to Employee Assistance Program (EAP)
- Parental leave program
- Regular team events
- Social budgets
- In-office perks
- Employee Referral Program
About the Company
- Compass is Australia’s leading K–12 school management platform, supporting thousands of schools and expanding across Australia, the UK and Ireland.
- We build smart, seamless technology that empowers schools to focus on learning, growing and thriving.
- Compass is at an exciting inflection point - scaling its product, its team and its compliance obligations in parallel.
Equal Opportunity
- Compass is proud to be an equal opportunity employer. We embrace and celebrate diversity and are committed to creating an inclusive environment for all employees.
