Colombia, Peru
1 month ago

Job Overview

Job Type
Full Time
Pay
Not disclosed

Job description

Location:
Colombia, Peru
Work arrangement:
On-site

Role Summary

Bold

Our company was founded in May 2019 by a team of incredible people with a unique experience, the group of founders is made up of the creators of PayU Latam and other expert companies in financial technology. We are creating payment and banking solutions for MSMEs, independents and entrepreneurs in Colombia. We currently have more than 450,000 clients registered on our platform and we have received more than USD $120 million from national and foreign investment funds, we are one of the fastest growing startups in LatAm in the fintech sector. Bold is a fintech that provides a payment solution to microentrepreneurs to receive payments with debit cards, credit cards and wallets through dataphones and payment links. However, Bold's vision is more ambitious than being a payments company and we are working to become a financial and technological services platform for small businesses in the country, complementing payment and banking solutions with other software products related to our entire value proposition. Our mission at Bold is to unleash the potential of entrepreneurs. At Bold we firmly believe that we can help small entrepreneurs develop their businesses by offering financial and technological services tailored to them, that are friendly and approachable. At Bold we define the following values as the pillars of our organizational culture: Mastery, Critical thinking, Teamwork, Sense of urgency, We are open and the customer is the center of what we do. For more information about Bold visit our website:

As a Technical Privacy Specialist, you will lead Bold's privacy and personal data protection program in Colombia and Peru from the Information Security team. You will be responsible for translating privacy risks and requirements into controls, processes and work plans that can be executed and measured across the company.

This is not a legal role. The Legal team leads regulatory interpretation and will be your main ally on issues that require specialized analysis. We are looking for a person with technical criteria, very organized and capable of coordinating complex projects with Product, Engineering, Security, Data, Operations and the business areas. You will have the autonomy to organize priorities, unblock dependencies and carry each initiative until its closure.

It will be a plus

Experience in fintech, payments, financial services or high data volume environments.

Experience attending to audits, authority requirements and programs associated with PCI DSS, ISO 27001, ISO 27701 or SOC 2.

Experience with privacy tools, GRC platforms, flow automation, or AI responsible governance.

Advanced English.

Certifications such as CIPM, CIPP, CIPT, ISO 27701, PMP or equivalent.

Responsibilities

You must

  • Define the strategy, roadmap and operating model of the privacy program, with objectives, people responsible, metrics, risks and a delivery schedule.
  • Manage a portfolio of cross-cutting initiatives, control scope, milestones, dependencies and remediation plans, and communicate progress and decisions to technical and business leaders.
  • Maintain the inventory of personal data, flow maps, the National Registry of Databases (RNBD) in Colombia and applicable records in Peru.
  • Incorporate privacy by design and by default in products, applications, integrations, payment flows and registration processes, participating from the early stages of discovery and design.
  • Lead PIA and DPIA assessments for new products, treatments, suppliers, international transfers and AI use cases, and track risks to closure.
  • Work with Legal to convert regulatory requirements into operational criteria and, with Engineering and Security, define classification, minimization, retention, deletion, anonymization, encryption, logging and access controls.
  • Coordinate the full cycle of holder requests and claims, including ARCO rights, PQRs and deletion requests, with traceability, quality and timeliness.
  • Coordinate the privacy front on incidents and data breaches along with Incident Response and Legal, documenting decisions, corrective actions and notifications when appropriate.
  • Maintain data processing policies, notices, authorizations, standards and guidelines, and promote consistent practices in all areas.
  • Respond to audits and requirements of the SIC, the SFC and equivalent authorities; prepare evidence; follow up on findings; and support frameworks such as PCI DSS, ISO 27001, ISO 27701 and SOC 2.
  • Design training, guides and support mechanisms so that teams apply privacy in their daily work.
  • Responsibly use automation and AI to improve program inventories, assessments, evidence collection, controls monitoring, and reporting.
  • Formalize and monitor the treatment contract with each processor (data transmission), verifying scope clauses, international transfers, subcontracting and final destination of the data, in accordance with the Colombian and Peruvian legal framework.

Requirements

  • 5 or more years of experience in privacy, data protection, GRC, information security or technology compliance, including managing complex programs with scope, roadmap, risks, dependencies, milestones and executive reporting.
  • Practical knowledge of the data protection regime applicable in Colombia and Peru, including Law 1581 of 2012, Law No. 29733 and its current regulatory standards. You don't need to be a lawyer.
  • Experience with data inventories, RoPA, PIA and DPIA, rights holders, privacy by design, incident management and remediation plans.
  • Technical solvency to talk with Engineering and Security about data flows, APIs, cloud services, data architectures, identity and access, encryption, records, retention and elimination. This role does not require developing software.
  • Ability to convert legal or regulatory requirements into clear controls and tasks, explain risks to different audiences and build agreements between Legal, Product, Technology, Data, Operations and business.
  • Excellent relationships, influence without formal authority, rigorous organization, constant monitoring and autonomy in an environment of changing priorities.
  • Criterion to design controls proportional to the risk and operational load, without losing traceability or quality.
  • Professional training or equivalent experience in technology, security, risk management, privacy or related areas.

Benefits

What do we have for you?

  • 🤝 Indefinite-term contract
  • đź’» Full time remote work
  • 👨🏽⚕️ Health policy/aid

🚀 Annual bonus for meeting business objectives (stocks or money).

  • đź’˛Competitive salary
  • 📚 Financial support for education
  • 🌎 World-class technologies and processes
  • 🏖️ Additional days off on vacation
  • đź‘“ Bonus for visual health
  • ❤️🩹 Emotional well-being
Role:
Technical Privacy Specialist
Job Type:
Full Time

More jobs at Bold

Similar Privacy-Compliance jobs at other companies