| Title | Compliance Manager |
|---|---|
| Department | Compliance / Legal & Regulatory Affairs |
| Reports to | [Director of Compliance / Chief Compliance Officer / General Counsel] |
| Location | [Remote / Hybrid / On-site] |
| Employment type | Full-time |
| Salary | [Salary range. Postings with a range perform significantly better, and several states require one.] |
Position overview
The Compliance Manager leads the operating compliance program at [Company], translating regulatory obligations into practical policies, controls, monitoring, and training. The role owns program execution and manages the analysts and specialists who carry it out.
The Compliance Manager partners with legal, risk, operations, and business leaders to set the compliance agenda, resolve issues, and prepare for examinations and audits. As regulators address AI and automated decision systems, this role builds those obligations into the program rather than treating them as an exception.
This is a people-leading role for a seasoned compliance professional who can balance regulatory rigor with practical business judgment.
Key responsibilities
Program ownership
- Own the design and operation of the compliance program.
- Set the compliance calendar, priorities, and risk-based plan.
- Maintain the compliance risk assessment and program metrics.
- Report program status to senior leadership and committees.
Regulatory strategy
Turn regulatory obligations into an actionable program:
- Track regulatory change and assess business impact.
- Translate requirements into policies, controls, and procedures.
- Advise business leaders on regulatory implications of new initiatives.
- Build AI and automated-decision obligations into the program.
Monitoring and testing
- Oversee compliance monitoring and testing programs.
- Review findings, root causes, and remediation plans.
- Escalate significant issues and track them to closure.
- Strengthen controls based on testing results and trends.
Team leadership
Lead, coach, and develop compliance analysts and specialists, set clear priorities and standards, and manage workload across monitoring, policy, and investigation work.
Policy and training
- Own the policy framework and review cycle.
- Direct the compliance training and awareness program.
- Maintain approvals, exceptions, and attestations.
- Keep policies current with new laws and AI-related obligations.
Investigations and issue management
Oversee intake, investigation, and resolution of compliance issues, ensure corrective actions are effective, and manage regulatory reporting obligations.
Exams and audits
Serve as a primary point of contact for internal audits, external examinations, and regulatory requests, and coordinate evidence, responses, and remediation.
Required qualifications
- Bachelor's degree in Business, Finance, Law, Accounting, or a related field. Advanced degree or JD a plus.
- 6 to 9+ years of compliance, audit, or regulatory experience, including program or people leadership.
- Deep knowledge of the regulations governing the organization's industry.
- Experience owning compliance monitoring, testing, and policy programs.
- Track record managing examinations, audits, and regulatory relationships.
- Strong leadership, communication, and stakeholder-management skills.
Preferred certifications
One or more of: CCEP, CRCM, CAMS, CISA, CRISC, CGRC, depending on industry and program focus.
Technical knowledge
Compliance program management, regulatory strategy, compliance risk assessment, monitoring and testing oversight, policy governance, investigations, examination management, controls remediation, and AI and automated-decision compliance.
Essential competencies
People leadership, regulatory interpretation, risk-based decision making, stakeholder influence, executive communication, program management, and sound business judgment.
Success measures: first 12 months
- Establish or refresh the compliance risk assessment and program plan.
- Implement a risk-based monitoring and testing schedule.
- Strengthen the policy framework and review cycle.
- Stand up or improve compliance metrics and leadership reporting.
- Close priority remediation items and reduce open findings.
- Build AI and automated-decision obligations into the program.
- Develop the compliance team's skills and coverage.
- Improve readiness for examinations and audits.
About [Company]
[Two or three sentences about your organization, the maturity of your program, and what the first year looks like. Candidates in this field respond to honesty about whether they are joining a build or an established function.]
Post this role on GRC Careers
Reach professionals who specialize in compliance program management rather than hoping they find you in a general feed. Hand reviewed, live within one business day.
See how others are hiring
Review live GRC jobs postings to benchmark scope, level, and posted salary before you publish yours.
Stay close to the market
Job alerts
Get new GRC jobs roles sent to you as they post.
Newsletter
Hiring trends, salary signals, and new templates from GRC Careers.
Frequently asked questions
What does a Compliance Manager do?
A Compliance Manager owns the operating compliance program. They set regulatory strategy, run monitoring and testing, maintain policies and training, manage investigations and examinations, and lead the compliance analysts who carry out the work.
What qualifications and certifications does a Compliance Manager need?
Most Compliance Managers have a bachelor's degree, sometimes a JD or advanced degree, and 6 to 9 or more years in compliance, including program or people leadership. Common certifications include CCEP, CRCM, CAMS, and CISA.
Who does a Compliance Manager report to?
A Compliance Manager typically reports to a Director of Compliance, the Chief Compliance Officer, or the General Counsel, depending on the size and structure of the organization.
How is AI changing the Compliance Manager role?
Regulators are extending existing obligations to AI and automated decision systems. Compliance Managers increasingly build AI-related requirements, such as those in the EU AI Act and state AI laws, into monitoring, policy, and testing rather than treating them separately.