Compliance Program Manager - Dora

Castle Island

Amsterdam

Hybrid

EUR 110,000 - 150,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Competitive salary
Equity
Startup atmosphere
Impactful work
Professional growth

Job summary

OpenFX, based in Amsterdam, is seeking a Security & Compliance Engineer to turn regulatory requirements into running controls and prove them to auditors. This senior role operates in a heavily regulated EU environment and requires hands-on experience implementing DORA, GDPR, SOC 2, and ISO 27001.

You will own end-to-end security controls, partner with Legal, Compliance, and Risk, and ensure controls are enforced across AWS, Kubernetes, and application layers.

Qualifications

  • 6+ years in security engineering, cloud security, or compliance-oriented roles.
  • Hands-on experience implementing DORA in a production/regulatory environment.
  • Experience supporting SOC 2 and/or ISO 27001 audits.
  • Ability to translate regulatory requirements into technical controls.
  • Strong knowledge of AWS security fundamentals (IAM, logging, encryption, networking).
  • Comfortable leading auditor interactions and explaining systems clearly.
  • Experience building or automating security/compliance processes (Python, Bash, Go).
  • Accountability for audit outcomes.

Responsibilities

  • Own audit-ready security controls for regulatory frameworks (DORA, GDPR, SOC 2, ISO 27001).
  • Translate regulatory language into concrete security mechanisms and collaborate with Legal/Compliance.
  • Run audits: prepare evidence, walkthroughs, remediation tracking, automate pipelines.
  • Embed security/compliance into the platform, ensuring logs, access controls, encryption, monitoring meet expectations.
  • Automate compliance checks and push controls into code and infrastructure.

Skills

Security Engineering
Cloud Security
DORA compliance
GDPR
SOC 2
ISO 27001
AWS security
Kubernetes
Python
Audit leadership

Tools

AWS GuardDuty
AWS Config
CloudWatch

Job description

About Us

OpenFX is on a mission to move money as freely as data, unrestricted by time zones, banking hours, or legacy systems. We are building the infrastructure that will power the next generation of cross-border payment systems for institutions. The team's execution has been exceptional, and we're scaling at a remarkable pace. Our stellar early team comes with experience in companies like J.P. Morgan, Goldman Sachs, FalconX, Paypal, Affi­…

Role Overview

We are looking for a Security & Compliance Engineer to turn regulatory requirements into real, running controls — and then prove to auditors that they work. This is a senior, hands-on role for someone who thrives in fast-paced, heavily regulated environments and knows how to make compliance provable in production rather than on paper.

OpenFX is expanding across Europe in a heavily regulated financial environment. As we scale into EU markets, regulators, auditors, and enterprise partners expect provable, continuously operating security controls — not slide decks or one-off audits. Compliance requirements (DORA, GDPR, SOC 2, ISO 27001, and region-specific regulations) are increasing faster than our ability to operationalize them, and this role exists to close that gap.

You will own the security controls and evidence that regulators and auditors care about, end to end — from translating regulatory language into concrete mechanisms through to audit walkthroughs and remediation. You will partner closely with Legal, Compliance, Risk, and engineering to ensure compliance is built into the platform rather than bolted on after the fact.

This role is based in Amsterdam, Netherlands (EU/EEA).

Key Responsibilities:
  • Own audit-ready security controls
    • Design, implement, and maintain technical and operational controls for DORA, GDPR, SOC 2, ISO 27001, and future regional requirements.
    • Ensure controls are not just documented, but actually enforced in AWS, Kubernetes, and application layers.
  • Be the technical counterpart to Legal, Compliance & Risk
    • Translate regulatory language into concrete security mechanisms.
    • Partner with Legal and Compliance to monitor new regulations and assess technical impact.
    • Decide what is "good enough" vs. over-engineered for compliance.
  • Run audits instead of reacting to them
    • Own audit preparation, evidence collection, walkthroughs, and remediation tracking.
    • Build repeatable, automated evidence pipelines instead of last-minute scrambles.
    • Be the person auditors trust when they ask, "Show me how this actually works."
  • Embed compliance into the platform
    • Work with engineering to design systems that are secure by default and defensible to regulators.
    • Ensure logging, access controls, encryption, monitoring, and change management meet regulatory expectations.
  • Automate compliance wherever possible
    • Build tooling and scripts to continuously validate controls (access reviews, logging coverage, config drift).
    • Reduce manual compliance work over time by pushing checks into code and infrastructure.
What we are looking for
Must-haves:
  • 6+ years in security engineering, cloud security, or compliance-focused security roles.
  • Hands‑on, operational experience implementing DORA in a production/regulated environment (not advisory only) — e.g. ICT risk management, incident classification and reporting, third‑party/ICT vendor oversight, and digital operational resilience testing. GDPR implementation experience is a strong bonus.
  • Experience supporting SOC 2 and/or ISO 27001 audits (strong plus).
  • Ability to translate regulatory requirements into technical controls.
  • Strong working knowledge of AWS security fundamentals (IAM, logging, encryption, networking).
  • Comfortable owning auditor interactions and explaining systems clearly.
  • Experience building or automating security/compliance processes (Python, Bash, Go, etc.).
  • Accountability for an audit outcome — if you've never owned one, this role is not a fit.
What helps you stand out:
  • Experience securing Kubernetes environments.
  • Familiarity with AppSec tooling (SAST/DAST, manual testing).
  • Experience with AWS security services (GuardDuty, Config, Security Hub).
  • Prior work in fintech, payments, or regulated infrastructure.
  • Security or compliance certifications (CISSP, CISA, ISO 27001 Lead Implementer, AWS Security).
  • Familiarity with EU financial regulators and national competent authorities (e.g. DNB/AFM in the Netherlands, EBA/ESMA).
What We Offer
  • Competitive salary and benefits package.
  • Equity in a rapidly growing company.
  • Opportunity to work in a fast-paced startup at the forefront of fintech innovation.
  • Opportunity to make a significant impact on global financial infrastructure
  • Collaborative work culture with emphasis on personal and professional growth.

We are committed to building a diverse and inclusive workplace. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Compliance Security Engineer — FinTech (EU, DORA/GDPR)
Senior Compliance Security Engineer — FinTech (EU, DORA/GDPR)

Castle Island • Amsterdam

Hybrid
EUR 110,000 - 150,000
Competitive salary
Equity
Startup atmosphere
+2
Security Engineer - Security & Cloud Operations - FinTech Scale up (Global impact) - Cloud Native - Solid comp/equity - Amsterdam, the Netherlands
Security Engineer - Security & Cloud Operations - FinTech Scale up (Global impact) - Cloud Native - Solid comp/equity - Amsterdam, the Netherlands

Sprint and Partners • Amsterdam

Hybrid
EUR 78,000 - 96,000
Stock options
Pension
Office lunch
+2
Information Security Officer
Information Security Officer

Startup Atlas • Amsterdam

Hybrid
EUR 90,000 - 130,000
Bonus scheme
Shares incentive plan
Office in Amsterdam (cool office)
Finance Manager
Finance Manager

Compliance Wise • Amsterdam

Hybrid
EUR 70,000 - 100,000
25 vacation days
Hybrid working
D&I day off
+5
Compliance Analyst (Amsterdam)
Compliance Analyst (Amsterdam)

Privalgo Limited • Amsterdam

Hybrid
EUR 70,000 - 100,000
Compliance Officer
Compliance Officer

alloptions • Amsterdam

On-site
EUR 60,000 - 80,000
Competitive salary
Bonus opportunities
Profit sharing
+6
Staff Engineer (Amsterdam)
Staff Engineer (Amsterdam)

Provable Markets LLC • Amsterdam

Hybrid
EUR 90,000 - 140,000
Competitive salary
25 vacation days per year
Hybrid work schedule
Compliance officer
Compliance officer

Blockrise • Rotterdam

Hybrid
EUR 70,000 - 90,000
Remote work option
Office in Rotterdam
Travel reimbursement
+5
Compliance Director - Europe
Compliance Director - Europe

Verifone • Amsterdam

Hybrid
EUR 120,000 - 180,000
Compliance officer
Compliance officer

Rotterdam Innovation City • Netherlands

Hybrid
EUR 70,000 - 90,000
Travel reimbursement or NS Business-卡
Share certificate programme
NS Business Card
+3