Lendistry is an Equal Opportunity/Affirmative Action Employer. We consider applicants without regard to race, color, religion, age, national origin, ancestry, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, veteran status, disability, genetic information, or membership in any other group protected by federal, state, or local law.
If you need assistance or accommodation due to a disability, you may contact us at [email protected]
Lendistry does not accept unsolicited resumes from recruiters, employment agencies, or staffing firms. To conduct business with Lendistry, a Master Services Agreement (MSA) must be executed and confirmed prior to submitting any information relating to a potential candidate. Without a signed MSA, Lendistry shall not be responsible to any individual or entity for any payment relating to any form of fee or compensation.
And, in the event that a resume or candidate is submitted by a recruiter, an employment agency, or a staffing firm without a fully executed MSA, Lendistry has the unrestricted right to pursue and hire any of those candidate(s) without any legal or financial responsibility to the recruiter, agency, and/or firm.
A Day in the Life
As a member of the technology team reporting to VP, Enterprise Security, you will serve as Lendistry's technical data privacy subject matter expert. This is not an attorney position and does not involve independently interpreting laws or regulations. You will operationalize guidance from Legal and Compliance on applicable regulatory requirements, privacy standards, and related best practices into concrete technical controls and auditable processes.
You will own the governance, technical, and operational aspects of Lendistry’s privacy program, including consumer privacy rights handling, vendor privacy diligence, privacy risk assessments, data inventory and data flow management, incident response support, and embedding privacy-by-design in product development and AI/ML pipelines.
You will partner closely with the rest of the Security team, Legal, Compliance, Product, Engineering, and every business unit that collects, processes, or shares personal information. You will serve as the primary driver of the technical implementation of compliance obligations across the organization.
Lendistry: Who We Are
We’re proud to be the nation’s largest minority-led, tech-savvy lender for small businesses and commercial real estate. As a certified Community Development Financial Institution (CDFI) and Community Development Entity (CDE), our mission is all about creating economic opportunities and fueling growth for small business owners and their communities. Join us as we pave the way with innovative financing and financial education!
What You’ll Be Doing
Data Privacy & Protection
Technical data privacy subject matter expert, and administrator of the organization’s Privacy Program.
Design, implement, and manage solutions to protect personal data, embedding “privacy by design” across the software development lifecycle, product architecture, and AI/ML pipelines.
Act as a technical bridge between Compliance, Legal, and Engineering teams to facilitate the translation of privacy policy and regulatory requirements into actionable requirements such as data minimization, encryption, tokenization, data masking, anonymization, and access controls, and clearly defined auditable controls.
Maintain and continuously update enterprise data flow diagrams and data inventories to map the lifecycle of personal information from ingestion to deletion.
Lead and document annual privacy risk assessments, including Privacy Impact Assessments (PIAs) and similar assessments required under applicable U.S. state privacy laws.
Manage first-line-of-defense compliance with the technical requirements of applicable US Federal and US state privacy laws based on regulatory interpretations provided by Legal and Compliance.
Support incident response activities related to data privacy, including breach assessment, documentation, and regulatory support, in partnership with the Security, Legal and Compliance Teams.
Privacy Strategy & Program Ownership
Work cross-departmentally with Legal, Compliance, and Engineering to set enterprise privacy strategy across Lendistry and all subsidiary entities. Legal and Compliance lead on regulatory interpretation; this role operationalizes their determinations into program controls and processes and documents change management.
Serve as a technical resource to Legal and Compliance involving day-to-day privacy matters, including support for engagements with external parties on privacy-related matters, including by consumers, internal and external auditors, regulators, examiners and banking partners.
Set the privacy roadmap, including annual program priorities, investment requests, and measurable objectives tied to business and regulatory risk.
Report regularly to VP, Security, Chief Compliance Officer and other executive leadership on privacy posture, material risks, regulatory developments, incidents, and program maturity.
Privacy by Design & AI Privacy
Embed privacy by design in the product development lifecycle, reviewing new features, data flows, retention changes, and vendor integrations before they ship.
Partner with the AI team to set privacy guardrails on Lendistry’s AI systems, including data minimization, PII redaction before inference, model training data governance, and consumer disclosure for automated decisioning.
Contribute to Lendistry’s responsible AI posture alongside Legal, Compliance, Security, and the AI team, with attention to fair lending, consumer disclosures for AI-driven decisions, and alignment with the NIST AI Risk Management Framework.
Third-Party & Vendor Risk
Support third-party risk assessments with a focus on data handling, privacy, and related risks.
Review vendor security and privacy documentation (SOC reports, SIGs, DPAs).
Ensure data inventory and data flow diagrams are updated to reflect new vendor tools or changes in existing tools, accurately capturing the data lifecycle, including ingress and egress points, purpose and method of transmission, and security protocols for data at rest and in transit.
Track controls and remediation items and ensure vendors meet contractual and regulatory obligations.
Training & Culture
Work with Compliance and Training and Development teams to administer privacy training, including role-based training for engineering, credit, servicing, marketing, and customer-facing teams, plus executive-level education.
Build a privacy-aware culture where data questions prompt conversation rather than workarounds.
Serve as a credible, accessible partner to every business unit that handles personal information.
Cross-Functional Collaboration
Work closely with Security, Engineering, Product, Legal, Compliance, and Operations teams.
Provide practical guidance that balances compliance, risk reduction, and business velocity.
Assist with regulator, auditor, and customer due-diligence inquiries.
AI Governance & Responsible Use
Lendistry expects its Security and Privacy teams to be among the most thoughtful users of AI tools in the company. This role will collaborate with Legal, Compliance, AI and Engineering leadership to set AI use standards and strategy for privacy operations
Stay current on AI capabilities and limitations as they relate to privacy operations
Assist the Legal, Compliance and AI teams in shaping the policies, training, and controls that govern AI use across the organization
Your Areas of Knowledge and Expertise
Core Experience
5+ years in privacy, data protection, or a closely adjacent field, with a clear pattern of growing program ownership and cross-functional leadership.
Hands-on experience supporting regulatory and compliance programs under applicable federal privacy and consumer protection laws (GLBA, FCRA, ECOA, Reg B) and existing U.S. state privacy laws (e.g., CCPA/CPRA and comparable statutes in CO, VA, CT, UT, TX, OR, MT, NJ, TN, IA, IN, DE, NE, NH, MD, MN).
Working knowledge of applicable industry standards and compliance frameworks, including SOC 2 attestation standards, the NIST Cybersecurity Framework (CSF 2.0) and the NIST Privacy Framework.
Demonstrated ability to perform privacy and security risk assessments, including Privacy Impact Assessments (PIAs) and comparable assessments required under applicable U.S. state privacy laws, with strong documentation and evidence-management practices.
Demonstrated ability to develop and maintain data inventories, data maps, and data flow diagrams to support privacy compliance and regulatory obligations.
Deep working knowledge of consumer privacy rights under CCPA/CPRA and applicable U.S. state privacy laws, including rights to access, delete, and opt out, sensitive personal information classifications, service provider vs. third-party distinctions, opt-out preference signals, and CPPA enforcement expectations.
Technical & Program Skills
Understanding of privacy engineering and secure system design, including familiarity with privacy-enhancing technologies such as differential privacy, federated learning, and secure multi-party computation (particularly in AI/ML pipelines).
Working knowledge of data mapping and automation tools used to manage data subject rights requests and privacy operations workflows (e.g., OneTrust, Archer, ServiceNow, TrustArc, Transcend, Osano, or equivalent).
Experience embedding privacy into product development — reviewing features, data flows, and vendor integrations at the point of design rather than at launch.
Experience overseeing privacy for AI or automated decisioning systems — data minimization, training data governance, consumer disclosure, and fair lending intersections.
Strong analytical, organizational, and documentation skills, with the ability to manage multiple compliance initiatives independently and communicate effectively across technical and business stakeholders.
Preferred Qualifications
CIPT/CDPSE/CIPP/US, CIPP/E, CIPM, CIPT, or FIP privacy certifications.
Experience building privacy programs across multiple legal entities or operating subsidiaries
Experience with cross-border operations.
Experience with NIST AI RMF, FedRAMP, PCI DSS and international frameworks such as GDPR, PIPEDA, LGPD, or DPDPA
Experience in SBA lending, CDFI operations, or other federally regulated financial institutions.
Experience with state lending examinations, CFPB matters, or other consumer-protection regulator engagement.
Why You'll Love Working Here:
Comprehensive Medical, Dental, and Vision Insurance
Generous Paid Time Off
Birthday Day Off
12 Paid Company Holidays
401(k) Match
FSA and HSA
Paid Life Insurance
Paid Disability Insurance
Pet Insurance
Employee Assistance Program (EAP)
Professional Development Courses
In Office Provided Snacks and Drinks
Gym Facilities (LA & Tustin/CEC Offices)
In Office Engagement Activities
Compensation Range
The US base salary range for this full-time position is $118,400 - $152,300 annually.
Our salary ranges are determined by role, level, and location.
The range displayed on each job posting reflects the minimum and maximum base salary for new hires for the position across all US locations. Within the range, individual pay is determined by multiple factors like job-related skills, experience, and state of residence. Your recruiter can share more about the specific salary range during the interview process.
Please note that the compensation details listed in US role postings reflect the base salary only, and do not include any variable compensation elements.
Physical Requirements
This is a stationary position that requires frequent sitting (approximately 95%), repetitive wrist motions, grasping, speaking, listening, close vision, and the ability to adjust focus. It also may require occasional standing, lifting, carrying of 20lbs or less, walking, kneeling, bending/stooping, twisting, pulling/pushing, and reaching above the shoulder. Employees in this position must be physically able to efficiently perform the essential functions of the position.
ACKNOWLEDGEMENT
B.S.D. Capital, Inc. dba Lendistry is an equal employment opportunity employer committed to providing its employees, applicants and other covered persons with equal opportunities without regard to race, color, age (40 or older), religious creed (including religious belief, practice or dress and grooming practices), national origin, ancestry, physical disability, mental disability, medical condition, genetic information, marital status, sex, gender (including pregnancy, childbirth or medical condition related to pregnancy or childbirth), gender expression, gender identity, sexual orientation, military or veteran status (including past, current or prospective service), or any other characteristic protected under applicable federal, state or local law.