Skip to main content
Back to jobs

Head of Compliance & Privacy

External
epay-policy logoEpay-policy · Austin, TX
Full-timeRemote2d ago
ComplianceIncident ResponseMovePenetration TestingRisk ManagementSalesforce
Cover LetterConnect

Prepare for this interview

Elite

AI-generated questions, company research, and talking points tailored to this role


About the role

We are seeking a highly motivated, hands-on Head of Compliance & Privacy to lead, scale, and operationalize our payments, regulatory, technical compliance, and data privacy programs. Reporting directly to the Sr. Director of Legal & Compliance , you will own the day-to-day operations of our compliance and privacy frameworks in a fast-paced fintech/insurtech environment. You are the ideal candidate if you are deeply knowledgeable about the nuances of payment processing (specifically ACH and credit card), possess a proven track record managing PCI-DSS audits, understand the strict data privacy mandates governing financial and consumer data, and enjoy turning complex regulatory requirements into practical, scalable business workflows.

Responsibilities

  • Payments & Regulatory Compliance Oversight
  • ACH & NACHA Operations: Maintain, update, and audit internal frameworks to ensure 100% alignment with NACHA Operating Rules (including Phase 2 monitoring and compliance).
  • Card Network & PayFac Compliance: Monitor and enforce compliance with Visa, Mastercard, Discover, and American Express rules, with a particular focus on merchant surcharge regulations and state-level limits.
  • Licensing & Regulatory Monitoring: Track state-by-state money transmission laws, FinCEN requirements, and coordinate required regulatory filings, reports, and disclosures.
  • AML Compliance & Audit Coordination: Serve as the primary point of coordination for annual AML audits, managing timelines and cross-functional responses in close partnership with the Payment Operations and Risk teams.
  • Security Compliance, PCI-DSS, & Data Privacy Ownership
  • PCI-DSS Level 1 Maintenance: Serve as the internal program manager for our annual PCI-DSS Level 1 certification. Act as the primary liaison with our external Qualified Security Assessor (QSA).
  • Data Mapping & Impact Assessments: Conduct regular data inventory mapping, lead Privacy Impact Assessments (PIAs) for new system integrations, and manage consumer privacy rights response workflows (DSARs).
  • Audit Readiness & GRC: Work closely with our internal IT, Security (InfoSec), and Engineering teams to manage ongoing compliance control testing, penetration testing schedules, and vulnerability scans.
  • Third-Party Risk Management (TPRM): Collaborate on the annual assessment calendar for vendors, reviewing vendor SOC reports, vendor security profiles, and privacy practices to evaluate third-party data sharing risks.
  • Policy Drafting, Procurement & Business Enablement
  • Contractual & Procurement Reviews: Review inbound procurement requests from a compliance and contractual perspective, and update client-facing compliance terms, including Data Processing Agreements (DPAs) and Proprietary Information Agreements (PIAs).
  • Internal Policies: Draft, update, and manage company-wide compliance manuals, Incident Response Plans, Business Continuity policies, and external-facing Privacy Policies.
  • Cross-Functional Advisory: Provide practical, high-judgment compliance and privacy guidance to Product, Engineering, and Sales teams during the development of new products, regional expansions (such as Canadian setup), and third-party integrations (Salesforce, DocuSign, etc.).
  • REQUIRED QUALIFICATIONS
  • Education: Juris Doctor (J.D.) degree from an accredited law school, active membership in a State Bar, and license to practice law in good standing.
  • Experience: 5-7 years of professional legal experience plus 2-3 years of dedicated compliance experience within the payments, FinTech, InsurTech, or Payment Facilitator (PayFac) space.
  • Technical Compliance & PCI-DSS: Direct, hands-on experience leading a company through a

Additional Information

Every day, ePayPolicy helps over 10,000 insurance companies speed up incoming and outgoing payments. By helping them move from manual, outdated forms of payment collection to modern payment tools, we help their companies work faster and more efficiently. (Check out our almost 5-star customer reviews .) How do we do it? With powerful payment tools that just work. Our secure, online ACH and credit card payment page is the core product for many of our companies. But we also provide an integrated suite of helpful features for insurance companies of all sizes, including point-of-sale financing, payables network tools, and check reconciliation, all within a single dashboard. Our expert, live support team helps deliver exceptional care every day, with an industry-leading 97% customer retention rate. Our customers love us. We love them. Founded in 2014, our growing team is based in Austin, TX, and has clients in all 50 US states. We've grown over 300% in the last three years - with big plans for the future.


Your Match

How well this role fits your profile.

Company Intel

What employees say

Worked at epay-policy? Share your experience

Interested in this role?

Apply on the company's website.

Cover LetterConnect