Title: Manager, Governance Risk and Compliance (Paisly)
Dania Beach, FL, US, 33004
Position Summary:
The Governance Risk and Compliance (GRC) Manager will establish, execute, and maintain Paisly’s global governance, enterprise risk management and operational compliance frameworks as the platform expands its digital travel product offerings across domestic and international markets. Reporting directly to the Head of Legal, this role translates regulatory requirements, privacy mandates and business goals into clear operational controls, risk management programs and policy frameworks.
Working in close partnership with the Cloud Engineering Compliance team, this role acts as a primary bridge between Legal, external auditors and business operations. The ideal candidate provides regulatory and policy guidance to cross-functional teams, while taking ownership of enterprise risk, vendor risk, privacy alignment and corporate compliance operations.
Essential Responsibilities:
- Oversee enterprise risk management by maintaining the master Compliance Obligations Register and proactively identifying, assessing, and monitoring travel e-commerce risks related to fee transparency, consumer protection, and multi-tenant partner integrations.
- Translate regulatory requirements, such as Federal Trade Commission/Department of Transportation (FTC/DOT) travel rules and data privacy mandates, into actionable guidance for cross-functional teams while partnering with Cloud Engineering Compliance to align corporate risk policies.
- Facilitate third-party due diligence and serve as the escalation point for risk concerns, ensuring all vendors complete required vetting and execute necessary agreements, data processing agreements, data structures and algorithms, non-disclosure agreements (DPAs, DSAs, NDAs) to minimize operational risk.
- Evaluate privacy and regulatory compliance across Paisly's international footprint (U.S., EU, UK, Canada) and collaborate with Legal to ensure workflows, customer data handling, and monitoring practices adhere to California consumer privacy act, general data protection regulation, (CCPA, GDPR), and global data protection standards.
- Establish and govern company-wide operational policies and standard operating procedures (SOPs), while coordinating evidence collection and supporting internal and external audits alongside legal and Cloud Engineering Compliance teams.
- Manage state-by-state Seller of Travel (SOT) registrations, renewals, and corporate regulatory filings in partnership with Legal Counsel, while proactively evaluating international licensing requirements to support Paisly's ongoing expansion.
- Develop, implement, and track the completion of mandatory company-wide training programs focused on governance, risk and compliance (GRC), data privacy and ethical compliance.
- Take a significant role in the development of crewmembers to support their engagement, growth, and goal achievement.
- Other duties as assigned.
Minimum Experience and Qualifications:
- Bachelor’s degree in Business, Risk Management, Paralegal Studies, Information Security, Legal Studies, or a related field; OR demonstrated capability to perform job responsibilities with a High School Diploma/GED and at least four (4) years of previous relevant work experience
- Five (5) years of professional experience in Governance, Risk, and Compliance (GRC), Enterprise Risk Management (ERM), or Regulatory/Privacy Compliance operations.
- Proven experience evaluating multi-jurisdiction regulatory compliance, privacy frameworks (CCPA/GDPR), and e-commerce/consumer protection rules.
- Proven ability to conduct regulatory analysis and translate statutory requirements into actionable control guidance for business and technical stakeholders.
- Strong collaborative skills with a track record of working effectively alongside technical compliance, engineering, and product teams.
- Excellent project management skills with high attention to detail for tracking regulatory deadlines, vendor reviews, and licensing requirements.
- Must be able to pass a ten (10) year background check
- Must be legally eligible to work in the country in which the position is located.
Preferred Experience and Qualifications:
- Professional Governance, Risk, and Compliance, privacy, or risk certification (e.g., Certified Information Privacy Professional/United States/Europe, Certified in Risk and Information Systems Control, Certified Information Systems Auditor, Certified Compliance & Ethics Professional, or Certified Governance, Risk, and Compliance Professional).
- Three (3) years of experience in the online travel agency (OTA), e-commerce, fintech, or technology sectors.
- Direct experience with Seller of Travel (SOT) registrations, licensing governance and travel industry regulatory frameworks.
Crewmember Expectations:
- Regular attendance and punctuality.
- Potential need to work flexible hours and be available to respond on short-notice.
- Able to maintain a professional appearance.
- When working or traveling on JetBlue flights, and if time permits, all capable crewmembers are asked to assist with light cleaning of the aircraft.
- The use of ChatGPT or any other automated tool during the interview process will disqualify a candidate from being considered for the position.
Equipment:
- Computer and other office equipment.
Work Environment:
- Traditional office environment.
Physical Effort:
- Generally not required, or up to 10 pounds occasionally, 0 pounds frequently. (Sedentary).
Nearest Major Market: Fort Lauderdale
Nearest Secondary Market: Miami