Compliance Program Manager - Dora

OpenFX

Greater London

On-site

GBP 110,000 - 170,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Competitive salary
Equity in a growing company
Fast-paced fintech environment
Impact on global financial infra
Collaborative culture and growth

Job summary

OpenFX, a fast-growing fintech in the EU, is hiring a Security & Compliance Engineer to convert regulatory requirements into verifiable production controls and to guide auditors through remediation. Based in Amsterdam, the role collaborates with Legal, Compliance, Risk and Engineering to weave compliance into the platform, with emphasis on DORA, GDPR, SOC 2, ISO 27001 and future regional rules.

You will own end-to-end controls, implement automated evidence pipelines, and ensure logging, access

Qualifications

  • Hands-on, security controls implementation in production environments.
  • Experience translating regulation into technical controls for audits.
  • Strong knowledge of AWS security fundamentals and services.
  • Ability to design automated evidence pipelines and auditing workflows.
  • Familiarity with DORA, GDPR, SOC 2 and ISO 27001 requirements.

Responsibilities

  • Own audit-ready security controls across platforms and IC layers.
  • Translate regulatory language into concrete security mechanisms.
  • Run audits with evidence collection, walkthroughs and remediation tracking.
  • Embed compliance into the platform with secure-by-default designs.
  • Automate compliance checks and pipelines to reduce manual effort.

Skills

Security engineering
Cloud security
Compliance security
DORA knowledge
AWS security
Kubernetes security

Tools

GuardDuty
Config
Security Hub
Kubernetes
Python
Go
Bash

Job description

OpenFX is on a mission to move money as freely as data, unrestricted by time zones, banking hours, or legacy systems. We are building the infrastructure that will power the next generation of cross-border payment systems for institutions. The team's execution has been exceptional, and we're scaling at a remarkable pace. Our stellar early team comes with experience in companies like J.P. Morgan, Goldman Sachs, FalconX, PayPal, Affir, Polygon, Kraken, Nium & others. We're backed by Accel, Lightspeed, NfX and other top‑tier investors.

Role Overview

We are looking for a Security & Compliance Engineer to turn regulatory requirements into real, running controls — and then prove to auditors that they work. This is a senior, hands‑on role for someone who thrives in fast‑paced, heavily regulated environments and knows how to make compliance provable in production rather than on paper.

OpenFX is expanding across Europe in a heavily regulated financial environment. As we scale into EU markets, regulators, auditors, and enterprise partners expect provable, continuously operating security controls — not slide decks or one‑off audits. Compliance requirements (DORA, GDPR, SOC 2, ISO 27001, and region‑specific regulations) are increasing faster than our ability to operationalize them, and this role exists to close that gap.

You will own the security controls and evidence that regulators and auditors care about, end to end — from translating regulatory language into concrete mechanisms through to audit walkthroughs and remediation. You will partner closely with Legal, Compliance, Risk, and engineering to ensure compliance is built into the platform rather than bolted on after the fact.

This role is based in Amsterdam, Netherlands (EU/EEA).

Key Responsibilities
  • Own audit-ready security controls
    • Design, implement, and maintain technical and operational controls for DORA, GDPR, SOC 2, ISO 27001, and future regional requirements.
    • Ensure controls are not just documented, but actually enforced in AWS, Kubernetes, and application layers.
  • Be the technical counterpart to Legal, Compliance & Risk
    • Translate regulatory language into concrete security mechanisms.
    • Partner with Legal and Compliance to monitor new regulations and assess technical impact.
    • Decide what is “good enough” vs. over-engineered for compliance.
  • Run audits instead of reacting to them
    • Own audit preparation, evidence collection, walkthroughs, and remediation tracking.
    • Build repeatable, automated evidence pipelines instead of last-minute scrambles.
    • Be the person auditors trust when they ask, “Show me how this actually works.”
  • Embed compliance into the platform
    • Work with engineering to design systems that are secure by default and defensible to regulators.
    • Ensure logging, access controls, encryption, monitoring, and change management meet regulatory expectations.
  • Automate compliance wherever possible
    • Build tooling and scripts to continuously validate controls (access reviews, logging coverage, config drift).
    • Reduce manual compliance work over time by pushing checks into code and infrastructure.
What we are looking for
Must-haves
  • 6+ years in security engineering, cloud security, or compliance-focused security roles.
  • Hands‑on, operational experience implementing DORA in a production/regulated environment (not advisory only) — e.g. ICT risk management, incident classification and reporting, third‑party/ICT vendor oversight, and digital operational resilience testing. GDPR implementation experience is a strong bonus.
  • Experience supporting SOC 2 and/or ISO 27001 audits (strong plus).
  • Ability to translate regulatory requirements into technical controls.
  • Strong working knowledge of AWS security fundamentals (IAM, logging, encryption, networking).
  • Comfortable owning auditor interactions and explaining systems clearly.
  • Experience building or automating security/compliance processes (Python, Bash, Go, etc.).
  • Accountability for an audit outcome — if you've never owned one, this role is not a fit.
What helps you stand out
  • Experience securing Kubernetes environments.
  • Familiarity with AppSec tooling (SAST/DAST, manual testing).
  • Experience with AWS security services (GuardDuty, Config, Security Hub).
  • Prior work in fintech, payments, or regulated infrastructure.
  • Security or compliance certifications (CISSP, CISA, ISO 27001 Lead Implementer, AWS Security).
  • Familiarity with EU financial regulators and national competent authorities (e.g. DNB/AFM in the Netherlands, EBA/ESMA).
What We Offer
  • Competitive salary and benefits package.
  • Equity in a rapidly growing company.
  • Opportunity to work in a fast‑paced startup at the forefront of fintech innovation.
  • Opportunity to make a significant impact on global financial infrastructure.
  • Collaborative work culture with emphasis on personal and professional growth.

We are committed to building a diverse and inclusive workplace. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Audit-Ready Security & Compliance Engineer (Fintech)
Audit-Ready Security & Compliance Engineer (Fintech)

OpenFX • Greater London

On-site
GBP 110,000 - 170,000
Competitive salary
Equity in a growing company
Fast-paced fintech environment
+2
Sr. Security Engineer - GRC EU/UK Regulation & Data Protection
Sr. Security Engineer - GRC EU/UK Regulation & Data Protection

AI Chopping Block • Greater London

Hybrid
GBP 80,000 - 110,000
Sr. Security Engineer - GRC Fintech & Financial Services EU/UK
Sr. Security Engineer - GRC Fintech & Financial Services EU/UK

Euspert - Appcast - CPC • Greater London

On-site
GBP 90,000 - 130,000
Service Automation and Continual Compliance Lead
Service Automation and Continual Compliance Lead

Moneycorp Bank Limited • Greater London

Hybrid
GBP 90,000 - 130,000
Private medical health insurance
Hybrid work in London
Sr. Security Engineer - GRC Fintech & Financial Services EU/UK
Sr. Security Engineer - GRC Fintech & Financial Services EU/UK

xAI • Greater London

On-site
GBP 100,000 - 135,000
Compliance Director
Compliance Director

Apto • Greater London

On-site
GBP 120,000 - 180,000
Long-Term Incentive Plan
Competitive salary and bonus package
Career growth opportunities
Security Governance, Risk, Compliance Lead
Security Governance, Risk, Compliance Lead

Sokin • Greater London

Hybrid
GBP 90,000 - 150,000
Security Governance, Risk, Compliance Lead
Security Governance, Risk, Compliance Lead

Sokin • Harrow

On-site
GBP 70,000 - 120,000
Global Compliance Manager
Global Compliance Manager

Light • Greater London

On-site
GBP 60,000 - 90,000
Competitive salary + potential stock options
25 days of annual leave + public holidays
Regular socials and off-sites
+1
Security Governance, Risk, Compliance Lead Technology · London, Dubai · Hybrid
Security Governance, Risk, Compliance Lead Technology · London, Dubai · Hybrid

Sokin • Greater London

Hybrid
GBP 90,000 - 130,000