The Compliance Program Manager will own and drive CentralReach's overall compliance program, working directly with the Chief Compliance Officer and Chief Information Security Officer. Beyond day-to-day maintenance and special projects, this role brings program ownership: translating regulatory and security standards into action plans, building KPIs and reporting cadences for leadership, developing metrics, monitoring, and incident response capabilities in partnership with Information Security and Infrastructure teams, and continually evolving the program's processes and tooling.
Key Accountabilities:
- Lead and Manage Third-Party and Internal Audits
- SOC 2 Type 2
- HIPAA Attestation
- Privacy Audit
- Security Audits
- Compliance Program Strategy & Implementation
- Translate requirements from regulatory and security frameworks (e.g., NIST 800-53, SOC 2, HIPAA) into concrete action items for cross-functional teams
- Track progress and communicate compliance rollout status with the teams doing the work
- Program Reporting & Communication
- Develop KPIs and dashboards to measure compliance program maturity, and report on them regularly to the Chief Compliance Officer and leadership
- Partner with Information Security and IT leadership to continually evolve the compliance program
- Metrics, Monitoring & Incident Response
- Partner with Security and Infrastructure teams to support automated identification, alerting, and response for compliance-relevant risks and incidents
- Maintain the compliance/security Incident Response Plan
- Support on-call and escalation planning for compliance and security incidents
- Compliance Process Development & Tooling
- Create, implement, and automate recurring compliance processes, such as account and access reviews and employee onboarding/offboarding checks
- Identify and evaluate GRC (governance, risk, and compliance) and compliance management tools to support the program
- Projects
- Build out the compliance program KPI framework and reporting cadence for leadership
- Manage Security and Compliance policy updates
- Lead and manage required internal audits
- Oversee Vendor Management
- Implement security and compliance program
- Desired Skills and Experience:
- Experience working with auditors through internal and external security and compliance audits
- Working knowledge of security and compliance frameworks (e.g., NIST 800-53, SOC 2, HIPAA, ISO 27001) and the ability to translate them into operational action plans
- Experience developing KPIs, metrics, and reporting cadences for program and executive leadership
- Familiarity with security monitoring, alerting, and incident response concepts
- Experience with Business Continuity and Disaster Recovery planning
- Process improvement and automation mindset, including experience evaluating and implementing GRC or compliance management tools
- Strong cross-functional collaboration and stakeholder management, including with Information Security, Infrastructure, and Legal teams
- Proven ability to manage multiple compliance initiatives simultaneously (e.g., audit cycles, risk assessments, policy rollouts) with competing timelines and cross-functional dependencies
- Excellent written and verbal communication skills, with demonstrated ability to translate complex regulatory or legal requirements into clear, actionable guidance for non-compliance audiences
- Detail-oriented approach to documenting audit findings, risk assessments, or corrective action plans, with follow-through on tracking items to closure
- Analytical mindset with a track record of identifying root causes of process or control gaps and recommending sustainable fixes rather than short-term patches
Base Salary Range
$100,000-$120,000 USD