ePayPolicy
Head of Compliance & Privacy
Austin, TX
Sponsorship not specifiedDetected 27 days ago
ExpressCybersecurityPenetration TestingIncident ResponseComplianceSalesforceProcurementCadenceCommunicationAdaptability
About the role
- We are seeking a highly motivated, hands-on Head of Compliance & Privacy to lead, scale, and operationalize our payments, regulatory, technical compliance, and data privacy programs. Reporting directly to the Sr. Director of Legal & Compliance, you will own the day-to-day operations of our compliance and privacy frameworks in a fast-paced fintech/insurtech environment.
- You are the ideal candidate if you are deeply knowledgeable about the nuances of payment processing (specifically ACH and credit card), possess a proven track record managing PCI-DSS audits, understand the strict data privacy mandates governing financial and consumer data, and enjoy turning complex regulatory requirements into practical, scalable business workflows.
- We are seeking a highly motivated, hands-on Head of Compliance & Privacy to lead, scale, and operationalize our payments, regulatory, technical compliance, and data privacy programs.
Responsibilities
- ACH & NACHA Operations: Maintain, update, and audit internal frameworks to ensure 100% alignment with NACHA Operating Rules (including Phase 2 monitoring and compliance).
- Privacy Program Management: Build, maintain, and scale ePayPolicy's data privacy compliance framework.
- Data Mapping & Impact Assessments: Conduct regular data inventory mapping, lead Privacy Impact Assessments (PIAs) for new system integrations, and manage consumer privacy rights response workflows (DSARs).
- Audit Readiness & GRC: Work closely with our internal IT, Security (InfoSec), and Engineering teams to manage ongoing compliance control testing, penetration testing schedules, and vulnerability scans.
- Internal Policies: Draft, update, and manage company-wide compliance manuals, Incident Response Plans, Business Continuity policies, and external-facing Privacy Policies.
- Conduct regular data inventory mapping, lead Privacy Impact Assessments (PIAs) for new system integrations, and manage consumer privacy rights response workflows (DSARs).
- Work closely with our internal IT, Security (InfoSec), and Engineering teams to manage ongoing compliance control testing, penetration testing schedules, and vulnerability scans.
- Draft, update, and manage company-wide compliance manuals, Incident Response Plans, Business Continuity policies, and external-facing Privacy Policies.
Requirements
- Data Privacy Expertise: Practical experience implementing and managing data privacy programs under GLBA, CCPA/CPRA, and/or PIPEDA within a financial services or cloud software context.
- you are comfortable rolling up your sleeves to draft policies, map data flows, audit logs, and test controls yourself.
- Track state-by-state money transmission laws, FinCEN requirements, and coordinate required regulatory filings, reports, and disclosures.
- Juris Doctor (J.D.) degree from an accredited law school, active membership in a State Bar, and license to practice law in good standing.
- Licensing & Regulatory Monitoring: Track state-by-state money transmission laws, FinCEN requirements, and coordinate required regulatory filings, reports, and disclosures.
Nice to have
- Experience with cross-border payment compliance and international privacy rules (specifically US-Canada payment operations) is a major asset.
- Fully-stocked kitchen
- Open communication (We won't box you in!
- If you have a cool idea for a product improvement or a suggestion on how to improve the customer experience, let's talk about it.
- We value everyone's ideas and opinions.)
- Huge opportunity for growth
Skills
- Excellent written and verbal communication skills.
- Ability to translate dense regulatory and privacy concepts into digestible insights for non-legal stakeholders.
- Professional privacy or compliance certifications (e.g., CIPP/US, CIPP/C, CAMS, CISA, or equivalent) preferred.
- Experience integrating compliance tooling into GRC platforms, Salesforce, or client-onboarding workflows.
- Why ePayPolicy
- Competitive salary
- Comprehensive benefits package with employer-paid basic life and disability premiums
- 401K
- Flexible Paid Time Off Policy (FTO)
- Company-sponsored quarterly "ePayItForward" initiatives
- Supportive and inclusive company culture with a focus on work/life balance
Compensation
- AML Compliance & Audit Coordination: Serve as the primary point of coordination for annual AML audits, managing timelines and cross-functional responses in close partnership with the Payment Operations and Risk teams.
- PCI-DSS Level 1 Maintenance: Serve as the internal program manager for our annual PCI-DSS Level 1 certification. Act as the primary liaison with our external Qualified Security Assessor (QSA).
- Third-Party Risk Management (TPRM): Collaborate on the annual assessment calendar for vendors, reviewing vendor SOC reports, vendor security profiles, and privacy practices to evaluate third-party data sharing risks.
Equal opportunity
- https://forms.gle/xKppyKTSqfTUi7hz5
Visa & Work Authorization
- Monitor and enforce compliance with Visa, Mastercard, Discover, and American Express rules, with a particular focus on merchant surcharge regulations and state-level limits.
Apply directly at ePayPolicy →Create a free account for alerts like thisView ePayPolicy immigration profile
This listing is sourced directly from ePayPolicy's careers page and normalized into a canonical job model.