> Markdown version of [/jobs/ext/735584-head-of-compliance-privacy](https://www.wearedevelopers.com/jobs/ext/735584-head-of-compliance-privacy). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Head of Compliance & Privacy - **Company:** ePay3, Inc - **Location:** Austin, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Audit Trail, Network Operating System (NOS), Cloud Computing, Cyber Security, Data Mapping, Data Sharing, PCI Data Security Standards, Salesforce.Com, Data Streaming, Data Processing, Integration Frameworks, RSA Archer Platform, DocuSign - **Published:** June 29, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=99b79a1f01b94999 ## About the Role Do you have experience in Risk management compliance audits?, Do you have a Doctor of Law (JD)?, * Experience: 5-7 years of professional legal experience plus 2-3 years of dedicated compliance experience within the payments, FinTech, InsurTech, or Payment Facilitator (PayFac) space. * Technical Compliance & PCI-DSS: Direct, hands-on experience leading a company through a PCI-DSS compliance audit (ideally Level 1 or Level 2) and managing relationships with external QSAs. * Data Privacy Expertise: Practical experience implementing and managing data privacy programs under GLBA, CCPA/CPRA, and/or PIPEDA within a financial services or cloud software context. * Regulatory Knowledge: Deep understanding of NACHA Operating Rules, card network operating regulations, FinCEN compliance, and BSA/AML protocols. * Strategic Thinker, Practical Executor: Strong execution skills; you are comfortable rolling up your sleeves to draft policies, map data flows, audit logs, and test controls yourself. * Communication Skills: Excellent written and verbal communication skills. Ability to translate dense regulatory and privacy concepts into digestible insights for non-legal stakeholders. * Adaptable Mindset: An "Optimistic Grit" and "No Ego, Amigo" attitude, thriving in a high-growth, fast-paced environment where priorities dynamically evolve. * Education: Juris Doctor (J.D.) degree from an accredited law school, active membership in a State Bar, and license to practice law in good standing., * Professional privacy or compliance certifications (e.g., CIPP/US, CIPP/C, CAMS, CISA, or equivalent) preferred. * Experience with cross-border payment compliance and international privacy rules (specifically US-Canada payment operations) is a major asset. * Experience integrating compliance tooling into GRC platforms, Salesforce, or client-onboarding workflows. ## Description We are seeking a highly motivated, hands-on Head of Compliance & Privacy to lead, scale, and operationalize our payments, regulatory, technical compliance, and data privacy programs. Reporting directly to the Sr. Director of Legal & Compliance, you will own the day-to-day operations of our compliance and privacy frameworks in a fast-paced fintech/insurtech environment. You are the ideal candidate if you are deeply knowledgeable about the nuances of payment processing (specifically ACH and credit card), possess a proven track record managing PCI-DSS audits, understand the strict data privacy mandates governing financial and consumer data, and enjoy turning complex regulatory requirements into practical, scalable business workflows., 1. Payments & Regulatory Compliance Oversight * ACH & NACHA Operations: Maintain, update, and audit internal frameworks to ensure 100% alignment with NACHA Operating Rules (including Phase 2 monitoring and compliance). * Card Network & PayFac Compliance: Monitor and enforce compliance with Visa, Mastercard, Discover, and American Express rules, with a particular focus on merchant surcharge regulations and state-level limits. * Licensing & Regulatory Monitoring: Track state-by-state money transmission laws, FinCEN requirements, and coordinate required regulatory filings, reports, and disclosures. * AML Compliance & Audit Coordination: Serve as the primary point of coordination for annual AML audits, managing timelines and cross-functional responses in close partnership with the Payment Operations and Risk teams. 2. Security Compliance, PCI-DSS, & Data Privacy Ownership * PCI-DSS Level 1 Maintenance: Serve as the internal program manager for our annual PCI-DSS Level 1 certification. Act as the primary liaison with our external Qualified Security Assessor (QSA). * Privacy Program Management: Build, maintain, and scale ePayPolicy's data privacy compliance framework. Ensure strict compliance with applicable US federal laws (GLBA, Regulation E/EFTA), state-level privacy mandates (such as CCPA/CPRA and state insurance laws), and Canadian privacy legislation (PIPEDA). * Data Mapping & Impact Assessments: Conduct regular data inventory mapping, lead Privacy Impact Assessments (PIAs) for new system integrations, and manage consumer privacy rights response workflows (DSARs). * Audit Readiness & GRC: Work closely with our internal IT, Security (InfoSec), and Engineering teams to manage ongoing compliance control testing, penetration testing schedules, and vulnerability scans. * Third-Party Risk Management (TPRM): Collaborate on the annual assessment calendar for vendors, reviewing vendor SOC reports, vendor security profiles, and privacy practices to evaluate third-party data sharing risks. 3. Policy Drafting, Procurement & Business Enablement * Contractual & Procurement Reviews: Review inbound procurement requests from a compliance and contractual perspective, and update client-facing compliance terms, including Data Processing Agreements (DPAs) and Proprietary Information Agreements (PIAs). * Internal Policies: Draft, update, and manage company-wide compliance manuals, Incident Response Plans, Business Continuity policies, and external-facing Privacy Policies. * Cross-Functional Advisory: Provide practical, high-judgment compliance and privacy guidance to Product, Engineering, and Sales teams during the development of new products, regional expansions (such as Canadian setup), and third-party integrations (Salesforce, DocuSign, etc.). ## Related Videos - [How One Developer Built the Back Office for 10 Million Companies](https://www.wearedevelopers.com/videos/100082-how-one-developer-built-the-back-office-for-10-million-companies) - [Web-based Information Visualization](https://www.wearedevelopers.com/videos/84-web-based-information-visualization) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [Great DevEx and Regulatory Compliance - Possible?](https://www.wearedevelopers.com/videos/1426-great-devex-and-regulatory-compliance-possible) - [No Keys for the Robot: GitOps as the Control Plane for Autonomous Agents](https://www.wearedevelopers.com/videos/100095-no-keys-for-the-robot-gitops-as-the-control-plane-for-autonomous-agents) - [Why Your AI Agent Keeps Hallucinating Your Data: Building Deterministic Context Layers](https://www.wearedevelopers.com/videos/2055-why-your-ai-agent-keeps-hallucinating-your-data-building-deterministic-context-layers) ## Related Articles - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The Biggest German Tech Companies](https://www.wearedevelopers.com/magazine/424-the-biggest-german-tech-companies) - [Highest Paying Tech Companies in Europe](https://www.wearedevelopers.com/magazine/162-highest-paying-tech-companies-in-europe) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)