Head of Risk, Compliance and Information Security at Compass Education | AU | Rezi

Head of Risk, Compliance and Information Security at Compass Education

Head of Risk, Compliance and Information Security

Compass Education · AU

Today

Head of Risk, Compliance and Information Security

Compass Education · AU

19 hours ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now
Resume preview

Tailor your resume to this Head of Risk, Compliance and Information Security role.

Rezi rewrites your resume against Compass Education's job description. Free.

Resume score gauge reading 58 out of 100

Don't guess if your resume is good enough.

See how it scores against the Head of Risk, Compliance and Information Security posting at Compass Education — free, in seconds.

About the Role

Lead how Compass manages risk, compliance, and information security as the business evolves. This role involves owning certification and audit programs (ISO 27001, PCI DSS), managing multi-jurisdictional regulatory compliance, information governance, and the security and information policy framework. You will be the point of accountability for reporting information security and compliance posture to the ELT and Board, translating complexity into clear priorities and practical frameworks.

Responsibilities

  • Maintain the ISMS and manage certification audits and corrective actions for ISO 27001 and equivalent standards.
  • Scope and maintain PCI DSS compliance for payment processing.
  • Manage privacy and data protection obligations under Australian Privacy Principles and equivalent UK and Irish regimes.
  • Conduct privacy impact assessments and privacy by design sign-offs.
  • Handle privacy complaints.
  • Oversee data classification, retention and disposal, and records management.
  • Own the overarching security and information policy suite.
  • Manage regulatory breach notification.
  • Ensure compliance with compliance clauses in customer and government contracts.
  • Respond to customer and government due diligence questionnaires.
  • Maintain the compliance risk register.
  • Aggregate information security posture and risk into a quarterly report to the ELT and Board.
  • Ensure vendor contracts carry appropriate data protection and security clauses.
  • Line manage Legal Counsel.
  • Oversee legal risk and contract review.

Requirements

  • 6+ years in compliance, risk, or information security leadership, ideally in a SaaS, fintech, or regulated technology environment.
  • Experience owning PCI DSS compliance end to end.
  • Hands-on ISO 27001 experience, having led a certification or maintained an ISMS end to end.
  • Multi-jurisdictional compliance experience, including practical application of the AU Privacy Act and GDPR.
  • Practical knowledge of a recognised security framework and how to translate it into requirements for a technical team.
  • Experience presenting risk and compliance posture to a Board or Audit & Risk Committee.
  • A builder's mindset, comfortable designing frameworks and policies from scratch.
  • Strong stakeholder communication skills, able to translate regulatory and technical complexity into clear, commercial language.
  • A valid Employee Working With Children Check.
  • A satisfactory National Police Check.
  • Verification of unrestricted work rights in Australia.

Skills

  • ISO 27001
  • PCI DSS
  • Australian Privacy Principles
  • GDPR
  • Security frameworks
  • Risk management
  • Compliance
  • Information security
  • Stakeholder communication
  • Payments
  • Acquiring
  • Merchant services
  • PayTo
  • NPP
  • Open Banking
  • SaaS
  • EdTech
  • Fintech
  • GCP
  • Cloud first infrastructure compliance

Location

  • Australia

Work Type

  • Hybrid
  • Full-time

Experience Level

  • 6+ years

Education Level

  • ICA, CIPP, CISSP, CISM or equivalent qualifications are highly regarded.

Benefits

  • Learning and development opportunities with a dedicated PD budget.
  • 24/7 access to Employee Assistance Program (EAP).
  • Parental leave program.
  • Regular team events and social budgets.
  • Employee Referral Program.

About the Company

  • Compass is on a mission to transform the school day for everyone by building smart, seamless technology. The company supports 5,000+ schools across three countries with a team of 300+ people. Their all-in-one school management platform redefines how education communities connect, communicate and operate.

Equal Opportunity

  • Compass is proud to be an equal opportunity employer. We embrace and celebrate diversity and are committed to creating an inclusive environment for all employees.