OpenFX - Compliance Program Manager - Dora
Requirements
• Must-haves: • 6+ years in security engineering, cloud security, or compliance-focused security roles. • Hands-on, operational experience implementing DORA in a production/regulated environment (not advisory only) — e.g. ICT risk management, incident classification and reporting, third-party/ICT vendor oversight, and digital operational resilience testing. GDPR implementation experience is a strong bonus. • Experience supporting SOC 2 and/or ISO 27001 audits (strong plus). • Ability to translate regulatory requirements into technical controls. • Strong working knowledge of AWS security fundamentals (IAM, logging, encryption, networking). • Comfortable owning auditor interactions and explaining systems clearly. • Experience building or automating security/compliance processes (Python, Bash, Go, etc.). • Accountability for an audit outcome — if you've never owned one, this role is not a fit. • What helps you stand out: • Experience securing Kubernetes environments. • Familiarity with AppSec tooling (SAST/DAST, manual testing). • Experience with AWS security services (GuardDuty, Config, Security Hub). • Prior work in fintech, payments, or regulated infrastructure. • Security or compliance certifications (CISSP, CISA, ISO 27001 Lead Implementer, AWS Security). • Familiarity with EU financial regulators and national competent authorities (e.g. DNB/AFM in the Netherlands, EBA/ESMA).
Responsibilities
• Own audit-ready security controls • Design, implement, and maintain technical and operational controls for DORA, GDPR, SOC 2, ISO 27001, and future regional requirements. • Ensure controls are not just documented, but actually enforced in AWS, Kubernetes, and application layers. • Be the technical counterpart to Legal, Compliance & Risk • Translate regulatory language into concrete security mechanisms. • Partner with Legal and Compliance to monitor new regulations and assess technical impact. • Decide what is "good enough" vs. over-engineered for compliance. • Run audits instead of reacting to them • Own audit preparation, evidence collection, walkthroughs, and remediation tracking. • Build repeatable, automated evidence pipelines instead of last-minute scrambles. • Be the person auditors trust when they ask, "Show me how this actually works." • Embed compliance into the platform • Work with engineering to design systems that are secure by default and defensible to regulators. • Ensure logging, access controls, encryption, monitoring, and change management meet regulatory expectations. • Automate compliance wherever possible • Build tooling and scripts to continuously validate controls (access reviews, logging coverage, config drift). • Reduce manual compliance work over time by pushing checks into code and infrastructure.
Benefits
• Competitive salary and benefits package. • Equity in a rapidly growing company. • Opportunity to work in a fast-paced startup at the forefront of fintech innovation. • Opportunity to make a significant impact on global financial infrastructure • Collaborative work culture with emphasis on personal and professional growth.
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT