Head of Compliance & Privacy
About the Company
Every day, ePayPolicy helps over 10,000 insurance companies speed up incoming and outgoing payments. By helping them move from manual, outdated forms of payment collection to modern payment tools, we help their companies work faster and more efficiently. Our secure, online ACH and credit card payment page is the core product, complemented by an integrated suite of features including point-of-sale financing, payables network tools, and check reconciliation—all within a single dashboard. Our expert, live support team delivers exceptional care, achieving an industry-leading 97% customer retention rate. Founded in 2014 and based in Austin, TX, we serve clients in all 50 US states and have grown over 300% in the last three years.
About the Role
We are seeking a highly motivated, hands-on Head of Compliance & Privacy to lead, scale, and operationalize our payments, regulatory, technical compliance, and data privacy programs. Reporting directly to the Sr. Director of Legal & Compliance, you will own the day-to-day operations of our compliance and privacy frameworks in a fast-paced fintech/insurtech environment. The ideal candidate is deeply knowledgeable about payment processing (specifically ACH and credit card), has a proven track record managing PCI-DSS audits, understands strict data privacy mandates governing financial and consumer data, and enjoys turning complex regulatory requirements into practical, scalable business workflows.
Responsibilities
- Payments & Regulatory Compliance Oversight
- ACH & NACHA Operations: Maintain, update, and audit internal frameworks to ensure 100% alignment with NACHA Operating Rules (including Phase 2 monitoring and compliance).
- Card Network & PayFac Compliance: Monitor and enforce compliance with Visa, Mastercard, Discover, and American Express rules, with a focus on merchant surcharge regulations and state-level limits.
- Licensing & Regulatory Monitoring: Track state-by-state money transmission laws, FinCEN requirements, and coordinate required regulatory filings, reports, and disclosures.
- AML Compliance & Audit Coordination: Serve as the primary point of coordination for annual AML audits, managing timelines and cross-functional responses in partnership with the Payment Operations and Risk teams.
- Security Compliance, PCI-DSS, & Data Privacy Ownership
- PCI-DSS Level 1 Maintenance: Serve as the internal program manager for our annual PCI-DSS Level 1 certification and act as the primary liaison with our external Qualified Security Assessor (QSA).
- Privacy Program Management: Build, maintain, and scale ePayPolicy's data privacy compliance framework, ensuring strict compliance with US federal laws (GLBA, Regulation E/EFTA), state-level privacy mandates (CCPA/CPRA), and Canadian privacy legislation (PIPEDA).
- Data Mapping & Impact Assessments: Conduct regular data inventory mapping, lead Privacy Impact Assessments (PIAs) for new system integrations, and manage consumer privacy rights response workflows (DSARs).
- Audit Readiness & GRC: Work with internal IT, Security (InfoSec), and Engineering teams to manage ongoing compliance control testing, penetration testing schedules, and vulnerability scans.
- Third-Party Risk Management (TPRM): Collaborate on the annual assessment calendar for vendors, reviewing vendor SOC reports, security profiles, and privacy practices to evaluate third-party data sharing risks.
- Policy Drafting, Procurement & Business Enablement
- Contractual & Procurement Reviews: Review inbound procurement requests from a compliance and contractual perspective, and update client-facing compliance terms, including Data Processing Agreements (DPAs) and Proprietary Information Agreements (PIAs).
- Internal Policies: Draft, update, and manage company-wide compliance manuals, Incident Response Plans, Business Continuity policies, and external-facing Privacy Policies.
- Cross-Functional Advisory: Provide practical, high-judgment compliance and privacy guidance to Product, Engineering, and Sales teams during new product development, regional expansions (e.g., Canadian setup), and third-party integrations (Salesforce, DocuSign, etc.).
Requirements
- 5 years of dedicated compliance experience within the payments, FinTech, InsurTech, or Payment Facilitator (PayFac) space.
- 3+ years of legal experience with a JD is an added bonus.
- Direct, hands-on experience leading a company through a PCI-DSS compliance audit (ideally Level 1 or Level 2) and managing relationships with external QSAs.
- Practical experience implementing and managing data privacy programs under GLBA, CCPA/CPRA, and/or PIPEDA within a financial services or cloud software context.
- Deep understanding of NACHA Operating Rules, card network operating regulations, FinCEN compliance, and BSA/AML protocols.
- Strong execution skills; comfortable rolling up your sleeves to draft policies, map data flows, audit logs, and test controls.
- Excellent written and verbal communication skills, with the ability to translate dense regulatory and privacy concepts for non-legal stakeholders.
- Adaptable mindset with an "Optimistic Grit" and "No Ego, Amigo" attitude, thriving in a high-growth, fast-paced environment where priorities dynamically evolve.
Preferred Qualifications
- Professional privacy or compliance certifications (e.g., CIPP/US, CIPP/C, CAMS, CISA, or equivalent).
- Experience with cross-border payment compliance and international privacy rules (specifically US-Canada payment operations).
- Experience integrating compliance tooling into GRC platforms, Salesforce, or client-onboarding workflows.
Benefits
- Competitive salary
- Comprehensive benefits package with employer-paid basic life and disability premiums
- 401K
- Flexible Paid Time Off Policy (FTO)
- Company-sponsored quarterly “ePayItForward” initiatives
- Supportive and inclusive company culture with a focus on work/life balance
- Fully-stocked kitchen
- Lunch stipend when working onsite
- Open communication and encouragement of ideas for product improvements or customer experience enhancements
- Huge opportunity for growth
Schedule
Hybrid schedule for in-office employees, with a standard of three days per week in the office. Cadence and days are determined by each team and manager.