Director, Compliance and Privacy
MXAbout the role
Life at MX
We are driven by our moral imperative to advance mankind - and it all starts with our people, product and purpose. We always carry a deep sense of drive and passion with us. If you thrive in a challenging work environment, surrounded by incredible team members who will help you grow, MX is the right place for you.
Come build with us and be part of an award-winning company that’s helping create meaningful and lasting change in the financial industry.
The Director, Compliance and Privacy will lead in a variety of operational, technical, corporate, and compliance matters. As a member of the MX’s Information Security team, you’ll work across a variety of teams including, security, legal, and sales. This position will report directly to the VP, CISO and manage a compliance team to support them.This position’s primary role will be to drive best in class Security, Risk & Privacy programs and policies that will safeguard the company and its partners.
Job Duties
The (GRC) Director’s primary role will be to drive best in class Compliance, Risk & Privacy programs and policies that will safeguard the company and its partners
Develop, enhance, operationalize enterprise-level security, risk and privacy policies, processes and controls to mitigate risk and comply with applicable laws and regulations
Performing activities to monitor and assess the security, risk and privacy controls on an ongoing basis as part of an Internal Controls Program.
Manage the audit programs for PCI, SOC2, and other regulatory compliance requirements.
Lead the company wide Enterprise Risk Management program, working closely with the operational departments (Legal, Engineering, Sales, Support, Operations, …) to develop, monitor policies and standards in compliance with applicable privacy policy & regulations
Collaborate with key stakeholders to review projects, business critical systems and related data to ensure compliance with data privacy laws, and if necessary, perform and advise on privacy impact assessments
Complete ownership and responsibility to answer privacy questionnaires and client required privacy information
Responsible for all internal and external audits and customer inquiries (as it relates privacy, security & compliance)
Lead the development and ongoing management of privacy programs across the company across all locations / jurisdictions
Implement measures and a governance framework to manage data use in compliance with laws and regulations, including developing templates for data collection, assisting with data mapping, and vendor management reviews
Identify, track, monitor and report on privacy controls and all applicable Data Privacy requirements
Provide recommendations to stakeholders when appropriate
Responsible for the regulatory security and privacy training of all employees and contractors
Job Requirements
An compliance-minded leader that has a strong sense of integrity and the ability to balance business interests with the need for compliance standards
Bachelor’s degree in the IT/Technology or legal field
12+ years of experience in Information Security and/or Data Privacy and Compliance positions
Experience leading teams and influencing stakeholders.
Expertise in compliance standards, eg ISO27K, SOC2, SSAE 16, NIST CSF and PCI DSS
Strong understanding of data privacy regulations eg CCPA, GDPR, HIPAA, PIPEDA, UK DPA and Privacy Shield
Strong understanding of regulations applicable to the Financial sector.
Strong understanding and experience in enabling GRC solutions and common control framework for data regulations
Excellent project management and process improvement skills
Ability to work independently in a fast-paced environment and handle multiple complex & confidential tasks
Excellent communication, interpersonal skills and attention to details & deadlines
Knowledge of standards NIST, COBIT, SABSA, is an asset
Past experience in GRC/privacy based role for a SaaS company is an asset
Knowledge of Business Continuity Planning is an advantage
Work Environment
At MX, we utilize a hybrid work model, which allows us to attract top talent and increase impact through collaboration. Our team members enjoy a balance of remote work and in-office days. Travel expectations for remote employees is about 15%, and the company covers travel expenses for remote employees. Local employees will utilize in-office time on a weekly basis Tuesday through Thursday. Both local and remote empl
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s