ePayPolicy Logo

ePayPolicy

Head of Compliance & Privacy

Posted 6 Hours Ago
Be an Early Applicant
Hybrid
Austin, TX
Senior level
Hybrid
Austin, TX
Senior level
Lead and operationalize payments, regulatory, security compliance, and data privacy programs. Manage PCI-DSS Level 1 certification, NACHA and card network compliance, AML/FinCEN coordination, privacy frameworks (GLBA, CCPA/CPRA, PIPEDA), vendor risk, audits, policy drafting, and cross-functional advisory for Product, Engineering, and Sales.
The summary above was generated by AI

Every day, ePayPolicy helps over 10,000 insurance companies speed up incoming and outgoing payments. By helping them move from manual, outdated forms of payment collection to modern payment tools, we help their companies work faster and more efficiently. (Check out our almost 5-star customer reviews.)

How do we do it? With powerful payment tools that just work. Our secure, online ACH and credit card payment page is the core product for many of our companies. But we also provide an integrated suite of helpful features for insurance companies of all sizes, including point-of-sale financing, payables network tools, and check reconciliation, all within a single dashboard.

Our expert, live support team helps deliver exceptional care every day, with an industry-leading 97% customer retention rate. Our customers love us. We love them.

Founded in 2014, our growing team is based in Austin, TX, and has clients in all 50 US states. We’ve grown over 300% in the last three years - with big plans for the future.

Overview

We are seeking a highly motivated, hands-on Head of Compliance & Privacy to lead, scale, and operationalize our payments, regulatory, technical compliance, and data privacy programs. Reporting directly to the Sr. Director of Legal & Compliance, you will own the day-to-day operations of our compliance and privacy frameworks in a fast-paced fintech/insurtech environment.

You are the ideal candidate if you are deeply knowledgeable about the nuances of payment processing (specifically ACH and credit card), possess a proven track record managing PCI-DSS audits, understand the strict data privacy mandates governing financial and consumer data, and enjoy turning complex regulatory requirements into practical, scalable business workflows.

KEY RESPONSIBILITIES

1. Payments & Regulatory Compliance Oversight

  • ACH & NACHA Operations: Maintain, update, and audit internal frameworks to ensure 100% alignment with NACHA Operating Rules (including Phase 2 monitoring and compliance).

  • Card Network & PayFac Compliance: Monitor and enforce compliance with Visa, Mastercard, Discover, and American Express rules, with a particular focus on merchant surcharge regulations and state-level limits.

  • Licensing & Regulatory Monitoring: Track state-by-state money transmission laws, FinCEN requirements, and coordinate required regulatory filings, reports, and disclosures.

  • AML Compliance & Audit Coordination: Serve as the primary point of coordination for annual AML audits, managing timelines and cross-functional responses in close partnership with the Payment Operations and Risk teams.

2. Security Compliance, PCI-DSS, & Data Privacy Ownership

  • PCI-DSS Level 1 Maintenance: Serve as the internal program manager for our annual PCI-DSS Level 1 certification. Act as the primary liaison with our external Qualified Security Assessor (QSA).

  • Privacy Program Management: Build, maintain, and scale ePayPolicy's data privacy compliance framework. Ensure strict compliance with applicable US federal laws (GLBA, Regulation E/EFTA), state-level privacy mandates (such as CCPA/CPRA and state insurance laws), and Canadian privacy legislation (PIPEDA).

  • Data Mapping & Impact Assessments: Conduct regular data inventory mapping, lead Privacy Impact Assessments (PIAs) for new system integrations, and manage consumer privacy rights response workflows (DSARs).

  • Audit Readiness & GRC: Work closely with our internal IT, Security (InfoSec), and Engineering teams to manage ongoing compliance control testing, penetration testing schedules, and vulnerability scans.

  • Third-Party Risk Management (TPRM): Collaborate on the annual assessment calendar for vendors, reviewing vendor SOC reports, vendor security profiles, and privacy practices to evaluate third-party data sharing risks.

3. Policy Drafting, Procurement & Business Enablement

  • Contractual & Procurement Reviews: Review inbound procurement requests from a compliance and contractual perspective, and update client-facing compliance terms, including Data Processing Agreements (DPAs) and Proprietary Information Agreements (PIAs).

  • Internal Policies: Draft, update, and manage company-wide compliance manuals, Incident Response Plans, Business Continuity policies, and external-facing Privacy Policies.

  • Cross-Functional Advisory: Provide practical, high-judgment compliance and privacy guidance to Product, Engineering, and Sales teams during the development of new products, regional expansions (such as Canadian setup), and third-party integrations (Salesforce, DocuSign, etc.).

REQUIRED QUALIFICATIONS

  • Experience: 5-7 years of professional legal experience plus 2-3 years of dedicated compliance experience within the payments, FinTech, InsurTech, or Payment Facilitator (PayFac) space.

  • Technical Compliance & PCI-DSS: Direct, hands-on experience leading a company through a PCI-DSS compliance audit (ideally Level 1 or Level 2) and managing relationships with external QSAs.

  • Data Privacy Expertise: Practical experience implementing and managing data privacy programs under GLBA, CCPA/CPRA, and/or PIPEDA within a financial services or cloud software context.

  • Regulatory Knowledge: Deep understanding of NACHA Operating Rules, card network operating regulations, FinCEN compliance, and BSA/AML protocols.

  • Strategic Thinker, Practical Executor: Strong execution skills; you are comfortable rolling up your sleeves to draft policies, map data flows, audit logs, and test controls yourself.

  • Communication Skills: Excellent written and verbal communication skills. Ability to translate dense regulatory and privacy concepts into digestible insights for non-legal stakeholders.

  • Adaptable Mindset: An "Optimistic Grit" and "No Ego, Amigo" attitude, thriving in a high-growth, fast-paced environment where priorities dynamically evolve.

  • Education: Juris Doctor (J.D.) degree from an accredited law school, active membership in a State Bar, and license to practice law in good standing.

PREFERRED QUALIFICATIONS

  • Professional privacy or compliance certifications (e.g., CIPP/US, CIPP/C, CAMS, CISA, or equivalent) preferred.

  • Experience with cross-border payment compliance and international privacy rules (specifically US-Canada payment operations) is a major asset.

  • Experience integrating compliance tooling into GRC platforms, Salesforce, or client-onboarding workflows.


Why ePayPolicy

  • Competitive salary

  • Comprehensive benefits package with employer-paid basic life and disability premiums

  • 401K

  • Flexible Paid Time Off Policy (FTO)

  • Company-sponsored quarterly “ePayItForward” initiatives 

  • Supportive and inclusive company culture with a focus on work/life balance

  • Fully-stocked kitchen

  • Lunch stipend when working onsite

  • Open communication (We won’t box you in! If you have a cool idea for a product improvement or a suggestion on how to improve the customer experience, let’s talk about it. We value everyone’s ideas and opinions.)

  • Huge opportunity for growth


We operate on a hybrid schedule for in-office employees. Standard schedules are three days per week in the office, however, the cadence and days are determined by each team and manager. 

We value diversity here at ePayPolicy and understand the importance of creating a safe and comfortable work environment, encouraging individualism and authenticity in every member of our team. We strive to create an accessible and inclusive experience for all candidates. If you need an accommodation during the application or recruiting process, please submit a request to our team via this Interview Accommodation form: https://forms.gle/xKppyKTSqfTUi7hz5

Similar Jobs at ePayPolicy

Yesterday
Hybrid
Junior
Junior
Fintech • Insurance • Payments • Software
Manage and grow an assigned book of middle-market insurance clients. Serve as primary contact, drive adoption, retention, and upsell through account plans, cross-functional coordination, client engagement, and CRM-driven tracking.
Top Skills: CRMReporting ToolsSaaS
11 Days Ago
Hybrid
70-80 Hourly
Senior level
70-80 Hourly
Senior level
Fintech • Insurance • Payments • Software
The Production Support Manager will ensure the stability and performance of a SaaS platform, lead a support team, perform root cause analysis, and collaborate with development and operations teams.
Top Skills: .Net Framework And .Net CoreApp ConfigurationAzure Cognitive ServicesAzure Functions/App ServicesAzure Service BusAzure Sql ServerCloudflareGoogle BigqueryLog Analytics/Azure SentinelLogic AppsPowershellPython
17 Days Ago
Hybrid
Mid level
Mid level
Fintech • Insurance • Payments • Software
Lead and develop a team of Enterprise Account Executives, manage sales pipeline and quotas, collaborate with cross-functional teams, and drive strategic sales initiatives for ePayPolicy's product offerings.
Top Skills: Crm SystemsForecasting SoftwareSales Analytics ToolsSalesforce

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account