ClinicMind · 1 day ago
Director, Payments Platform & Compliance
ClinicMind is expanding its platform payments capabilities across patient and practice experiences. They are seeking a senior leader to own payment processing end-to-end, including PCI compliance, certifications/audit readiness, and building the team and product workflows that power payments inside ClinicMind.
BillingHealth CareMental HealthSoftware
Responsibilities
Define and lead the end-to-end payments architecture (card + bank/ACH where applicable), from authorization through settlement, refunds, disputes, and reporting
Own relationships and technical/compliance coordination with payment processors, gateways, and acquiring partners (as applicable)
Establish and run ClinicMind’s PCI DSS compliance program (scoping, controls, evidence, audit readiness)
Lead completion of PCI artifacts (as applicable to scope), including SAQs/ROCs and AOCs and managing assessors/vendors (e.g., ASVs, QSAs) as needed. PCI SSC defines these reporting tools and attestation forms as standard PCI compliance artifacts
Drive implementation of PCI DSS v4.x requirements and the 'future-dated' requirements that became effective March 31, 2025
Build and maintain a PCI responsibility matrix (what ClinicMind owns vs. what partners/clients own) and the process to provide it upon request—aligning with PCI DSS v4.x expectations for service providers/TPSPs (e.g., responsibility allocation and evidence sharing)
Implement appropriate operational controls for monitoring, fraud/risk signals, and disputes/chargebacks
If ClinicMind operates in a payment facilitator / platform model (or partners with one), design the operational approach consistent with payment-network expectations around sub-merchant onboarding and ongoing monitoring. Mastercard rules describe Payment Facilitator obligations to ensure submerchant compliance and perform ongoing monitoring to deter fraud/wrongful activity
For onboarding/screening workflows, understand and implement network screening patterns used in PayFac contexts (e.g., screening services such as Mastercard MATCH and Visa VMSS) as described by J.P. Morgan’s PayFac guidance
Design processes that align with ACH-network fraud controls where relevant. NACHA has highlighted rules requiring organizations that send ACH payments to have risk-based processes to identify potentially fraudulent transactions
Own the payments product surface area across patient and practice workflows (e.g., how users pay, track balances, handle receipts, refunds, disputes, and reconcile)
Translate compliance/security requirements into clean, low-friction UI/UX —without pushing risk downstream to patients or practices
Build and lead the internal team responsible for payments program execution (compliance ops, partner management, payments operations, and cross-functional delivery with engineering/product)
Create repeatable processes, documentation, and internal training to sustain compliance and operational excellence
Qualification
Required
Proven ownership of a payments processing implementation in a platform/software environment (not just using a payments product)
Direct experience leading PCI DSS compliance workstreams (scoping, evidence, audits, controls), including managing standard artifacts and assessors/vendors (PCI SSC defines common compliance reporting and attestation mechanisms such as SAQ/ROC and AOC)
Experience defining and operating shared responsibility across vendors/partners/customers (PCI v4.x emphasizes clarity of responsibility allocation and supporting customer requests for compliance/responsibility information)
Ability to lead cross-functionally (Engineering, Product, Security, Legal/Compliance, Ops) and convert requirements into production systems and user workflows
Preferred
Experience with payment-platform models that require merchant/sub-merchant onboarding and monitoring expectations (e.g., PayFac contexts). Mastercard rules describe ongoing monitoring expectations and PayFac duties to ensure submerchant compliance
Experience implementing screening/onboarding workflows that incorporate network screening services (e.g., MATCH/VMSS) referenced in PayFac onboarding patterns
Experience with ACH risk controls where applicable (NACHA's risk-based requirements for ACH senders)
Healthcare payments experience (patient/payor/provider workflows), especially in systems integrated with clinical and front-office workflows
Company
ClinicMind
ClinicMind is a Mental Health Billing Software with built-in Practice Management automation tools.
Funding
Current Stage
Growth StageRecent News
Company data provided by crunchbase