About InvoiceCloud:
InvoiceCloud is a fast-growing fintech leader recognized with 20 major awards in 2025, including USA TODAY and Boston Globe Top Workplaces, multiple SaaS Awards wins for Best Solution for Finance and FinTech, and national customer service honors from Stevie and the Business Intelligence Group. Judges also highlighted our mission to reduce digital exclusion and restore simplicity and dignity to how people pay for essential services, as well as our leadership in AI maturity and responsible innovation. It’s an award-winning, purpose-driven environment where top talent thrives. To learn more, visit InvoiceCloud.com.
- Serves as the authoritative individual contributor for privacy and data protection, making independent decisions within established regulatory, contractual, and risk guardrails.
- Owns the design, execution, and ongoing operation of InvoiceCloud’s enterprise privacy and data protection program.
- Leads enterprise data governance practices, including data mapping, classification, retention, and lifecycle management.
- Acts as the primary point of contact for regulators, data subjects, and internal stakeholders, maintaining trust, accountability, and consistency in privacy decision-making.
- Designs and maintains scalable, auditable privacy controls that embed privacy-by-design into products, systems, data flows, and operational processes.
- Standardizes workflows for RoPA, DPIAs, DSARs, vendor privacy reviews, and incident response to reduce friction and improve execution consistency.
- Establishes clear metrics, dashboards, and reporting to provide leadership with visibility into data risk posture and program maturity.
- Continuously refines processes to reduce manual effort, eliminate rework, and support responsible business velocity as the company scales.
- Establishes and executes a measurable enterprise privacy and data protection program that reduces regulatory, contractual, and operational risk.
- Prioritizes high-impact data risks across business units, translating regulatory requirements into actionable plans with defined milestones.
- Delivers timely, high-quality outcomes across DPIAs, DSARs, incident reporting, audits, and ongoing compliance obligations.
- Strengthens InvoiceCloud’s compliance posture by ensuring consistent, repeatable execution of privacy controls across the organization.
- Leverages GRC platforms, data governance tooling, and collaboration systems to modernize privacy operations and improve scalability and execution quality.
- Applies automation and GenAI to support activities such as data discovery, classification, policy enforcement, and risk analysis, reducing manual effort while increasing consistency and speed.
- Evaluates emerging technologies, regulatory trends, and best practices to continuously strengthen data protection capabilities as the business evolves.
- 10+ years of experience in privacy, data protection, governance, GRC, or security engineering, with demonstrated ownership of enterprise programs
- Strong working knowledge of GDPR, CCPA/CPRA, and U.S. state privacy laws; familiarity with PCI DSS, SOC 2, and the NIST Privacy Framework
- Hands-on experience with tools such as Drata, Microsoft Purview, DLP platforms, and data governance solutions
- Proven ability to design measurable controls and balance risk reduction with business enablement
- High integrity and sound judgment when handling sensitive and confidential information
InvoiceCloud is committed to providing equal employment opportunities to all employees and applicants. We do not tolerate discrimination or harassment of any kind based on race, color, religion, age, sex, nationality, disability, genetic information, veteran or military status, sexual orientation, gender identity or expression, or any other characteristic protected under applicable laws.
This commitment applies to all aspects of employment, including recruitment, hiring, placement, promotion, termination, layoff, recall, transfer, leave, compensation, and training.
If you require a disability-related or religious accommodation during the application or recruitment process, and wish to discuss possible adjustments, please contact jobs@invoicecloud.com.
Click here to review InvoiceCloud’s Job Applicant Privacy Policy.
For recruitment agencies: InvoiceCloud does not accept unsolicited resumes from agencies. Please do not forward resumes to our job aliases, employees, or any other company location. InvoiceCloud is not responsible for any fees associated with unsolicited submissions.
Sponsored