I'd suggest you look I to the technical compliance route - PCI and HiTrust have many technical. requirements.
There are also many companies that develop technical compliance tools - ServiceNow, Archer, Vulcan, etc.
Becoming a technical auditor, QSR, pen tester, etc. might be an option.