Skip to main content
AfterDuty

Head of Compliance

Compass Education · Sydney, New South Wales

Type
Full-time
Posted
8 days ago

Overview

Your regulatory compliance experience and risk management skills transfer directly to this governance role.

About this role

Come shape the future of education with us.

At Compass, we’re on a mission to transform the school day for everyone - from staff and students to families and administrators. We build smart, seamless technology that empowers schools to focus on what really matters: learning, growing and thriving.

As Australia’s leading K–12 school management platform, we support thousands of schools and are continuing to expand across Australia, the UK and Ireland. With that growth comes increasing complexity - across data privacy, payments regulation, information security, and multi-jurisdictional compliance obligations. Compass is at an exciting inflection point - scaling its product, its team and its compliance obligations in parallel.

We’re now looking for a Head of Compliance to own this space.

Reporting to the Chief Financial Officer, this is a newly created, hands-on, standalone role - it is an opportunity to build a structured compliance function from the ground up, working alongside a pragmatic in-house legal function in a high-growth SaaS environment.

The role spans three core domains: enterprise risk and governance, information security (ISO 27001), and multi-jurisdictional regulatory compliance across Australia, the UK, and Ireland, with oversight of operational and third-party compliance (including payment ecosystems).

What you'll own

Information Security & Data Compliance

  • Lead ISO 27001 certification and ongoing ISMS maintenance across Australian and international entities.
  • Own audit preparation, evidence gathering and control documentation - driving continuous audit readiness.
  • Manage risk assessments and maintain the risk register, escalating material findings as required.
  • Partner with Product and Engineering to embed compliance-by-design across the platform.
  • Support our UK and Ireland expansion with practical GDPR, UK GDPR and NIS2 compliance frameworks.

Regulatory Compliance & Policy Frameworks

  • Develop and embed compliance policies and procedures across the organisation.
  • Monitor regulatory developments across ASIC, APRA, OAIC, ICO, CBI and translate them into action.
  • Deliver training and awareness programs across privacy, information security and payments.
  • Provide compliance input into new products, commercial initiatives and customer contracts.

Operational & Third-Party Compliance

  • Oversee compliance across payment operations, third-party providers and key commercial partners.
  • Lead external compliance audits and act as the primary liaison with partners and assessors.
  • Build scalable onboarding and compliance documentation processes.
  • Identify and implement automation workflows to reduce manual compliance effort.

Risk & Governance

  • Establish and maintain a compliance monitoring and assurance program.
  • Maintain and report on the compliance risk register to the Legal Counsel, CFO and Board.
  • Build relationships with regulators and key external partners.
  • Drive a culture of proactive risk identification across the business.

Requirements

About You

You're energised by building, not just maintaining, and you know how to translate complex regulatory requirements into practical frameworks that a fast-moving business can actually follow.

You'll bring

  • 4+ years’ experience in compliance, risk or information security, ideally within a SaaS, fintech or regulated technology environment.
  • Proven experience as the primary or sole compliance owner.
  • Hands-on ISO 27001 experience - you've led a certification or maintained an ISMS end to end, not just assessed against the framework.
  • Multi-jurisdictional compliance experience, including practical application of the AU Privacy Act and GDPR.
  • A builder's mindset - you design frameworks that are practical and scalable.
  • Strong stakeholder communication skills - you can translate regulatory complexity into clear, commercial language.

Highly regarded

  • Experience in payments, acquiring or merchant services environments.
  • Familiarity with PayTo, NPP or Open Banking compliance.
  • Experience in a scaling SaaS, EdTech or fintech business.
  • Relevant qualifications (e.g. ICA, CIPP, CISSP or equivalent).
  • Exposure to GCP or cloud-first infrastructure compliance.

Benefits

Why Compass

You'll join a purpose-driven company at a genuinely exciting stage scaling product, team, and markets simultaneously. This is a rare opportunity to build something from scratch and leave a real mark on how a high-growth EdTech business operates safely and responsibly.

What we offer

  • A hybrid working environment, with teams working a hybrid structure at our office hubs.
  • Learning and development opportunities, including a dedicated PD budget.
  • 24/7 access to our Employee Assistance Program (EAP), including face-to-face, phone and live chat support.
  • A parental leave program for both primary and secondary carers.
  • Regular team events, social budgets and in-office perks help you stay connected, from team lunches to end-of-week socials.
  • Employee Referral Program
  • A supportive, inclusive culture where your voice is valued and heard.

Compass is proud to be an equal opportunity employer. We embrace and celebrate diversity and are committed to creating an inclusive environment for all employees.

Prior to commencing employment, you’ll need

  • A valid Employee Working With Children Check
  • A satisfactory National Police Check
  • Verification of unrestricted work rights in Australia (e.g. citizenship, passport or birth certificate)

Ready to build something that matters?

We'd love to hear from you. Find out more at www.compass.education.

About compliance & regulatory roles for ex-police

Compliance, AML/CTF and regulatory roles. Working to AUSTRAC, ASIC and APRA obligations is a stronger regulatory grounding than most civilian applicants can offer — firms increasingly recognise this.

See all compliance & regulatory jobs in Sydney

Why this fits a police background

  • Police experience explicitly valued
  • Evidence & case files
  • Intelligence & OSINT
  • Risk & threat assessment
  • Working to legislation & regulation

More compliance & regulatory jobs for ex-police

  • Ranger - Compliance

    City of Ryde · Sydney

    Full-time

    A$80,474 – A$104,616Estimated

    Your evidence gathering, conflict management, and legislative interpretation skills are directly transferable to regulatory enforcement.

    Posted 2 days ago

  • Your incident investigation and report writing experience directly supports audit and compliance activities.

    Posted 3 days ago

  • Delivery & Governance Manager - Admin Platforms & Compliance (Remote/Hybrid)

    Commonwealth Superannuation Corporation (CSC) · Sydney

    Contract

    Posted: 24/08/2026 Job Type: Fixed Term Job Category: Banking and Financial Services Job title: Delivery & Governance Manager (Admin Platforms & Compliance) Position Type: Fixed Term – 12 months As the Delivery & Governance Manager, you will have the responsibility to oversee and coordinate…

    Posted 3 days ago

  • Full-time

    Your experience handling sensitive data and complying with legal frameworks like PACE directly applies to privacy compliance.

    Posted 3 days ago