ePayPolicy

ePayPolicy

Head of Compliance & Privacy

Austin, TX

Sponsorship not specifiedDetected 27 days ago
ExpressCybersecurityPenetration TestingIncident ResponseComplianceSalesforceProcurementCadenceCommunicationAdaptability

About the role

  • We are seeking a highly motivated, hands-on Head of Compliance & Privacy to lead, scale, and operationalize our payments, regulatory, technical compliance, and data privacy programs. Reporting directly to the Sr. Director of Legal & Compliance, you will own the day-to-day operations of our compliance and privacy frameworks in a fast-paced fintech/insurtech environment.
  • You are the ideal candidate if you are deeply knowledgeable about the nuances of payment processing (specifically ACH and credit card), possess a proven track record managing PCI-DSS audits, understand the strict data privacy mandates governing financial and consumer data, and enjoy turning complex regulatory requirements into practical, scalable business workflows.
  • We are seeking a highly motivated, hands-on Head of Compliance & Privacy to lead, scale, and operationalize our payments, regulatory, technical compliance, and data privacy programs.

Responsibilities

  • ACH & NACHA Operations: Maintain, update, and audit internal frameworks to ensure 100% alignment with NACHA Operating Rules (including Phase 2 monitoring and compliance).
  • Privacy Program Management: Build, maintain, and scale ePayPolicy's data privacy compliance framework.
  • Data Mapping & Impact Assessments: Conduct regular data inventory mapping, lead Privacy Impact Assessments (PIAs) for new system integrations, and manage consumer privacy rights response workflows (DSARs).
  • Audit Readiness & GRC: Work closely with our internal IT, Security (InfoSec), and Engineering teams to manage ongoing compliance control testing, penetration testing schedules, and vulnerability scans.
  • Internal Policies: Draft, update, and manage company-wide compliance manuals, Incident Response Plans, Business Continuity policies, and external-facing Privacy Policies.
  • Conduct regular data inventory mapping, lead Privacy Impact Assessments (PIAs) for new system integrations, and manage consumer privacy rights response workflows (DSARs).
  • Work closely with our internal IT, Security (InfoSec), and Engineering teams to manage ongoing compliance control testing, penetration testing schedules, and vulnerability scans.
  • Draft, update, and manage company-wide compliance manuals, Incident Response Plans, Business Continuity policies, and external-facing Privacy Policies.

Requirements

  • Data Privacy Expertise: Practical experience implementing and managing data privacy programs under GLBA, CCPA/CPRA, and/or PIPEDA within a financial services or cloud software context.
  • you are comfortable rolling up your sleeves to draft policies, map data flows, audit logs, and test controls yourself.
  • Track state-by-state money transmission laws, FinCEN requirements, and coordinate required regulatory filings, reports, and disclosures.
  • Juris Doctor (J.D.) degree from an accredited law school, active membership in a State Bar, and license to practice law in good standing.
  • Licensing & Regulatory Monitoring: Track state-by-state money transmission laws, FinCEN requirements, and coordinate required regulatory filings, reports, and disclosures.

Nice to have

  • Experience with cross-border payment compliance and international privacy rules (specifically US-Canada payment operations) is a major asset.
  • Fully-stocked kitchen
  • Open communication (We won't box you in!
  • If you have a cool idea for a product improvement or a suggestion on how to improve the customer experience, let's talk about it.
  • We value everyone's ideas and opinions.)
  • Huge opportunity for growth

Skills

  • Excellent written and verbal communication skills.
  • Ability to translate dense regulatory and privacy concepts into digestible insights for non-legal stakeholders.
  • Professional privacy or compliance certifications (e.g., CIPP/US, CIPP/C, CAMS, CISA, or equivalent) preferred.
  • Experience integrating compliance tooling into GRC platforms, Salesforce, or client-onboarding workflows.
  • Why ePayPolicy
  • Competitive salary
  • Comprehensive benefits package with employer-paid basic life and disability premiums
  • 401K
  • Flexible Paid Time Off Policy (FTO)
  • Company-sponsored quarterly "ePayItForward" initiatives
  • Supportive and inclusive company culture with a focus on work/life balance

Compensation

  • AML Compliance & Audit Coordination: Serve as the primary point of coordination for annual AML audits, managing timelines and cross-functional responses in close partnership with the Payment Operations and Risk teams.
  • PCI-DSS Level 1 Maintenance: Serve as the internal program manager for our annual PCI-DSS Level 1 certification. Act as the primary liaison with our external Qualified Security Assessor (QSA).
  • Third-Party Risk Management (TPRM): Collaborate on the annual assessment calendar for vendors, reviewing vendor SOC reports, vendor security profiles, and privacy practices to evaluate third-party data sharing risks.

Equal opportunity

  • https://forms.gle/xKppyKTSqfTUi7hz5

Visa & Work Authorization

  • Monitor and enforce compliance with Visa, Mastercard, Discover, and American Express rules, with a particular focus on merchant surcharge regulations and state-level limits.

This listing is sourced directly from ePayPolicy's careers page and normalized into a canonical job model.