Senior Risk Management / GRC Manager

Zero Hash

Amsterdam

On-site

EUR 90,000 - 130,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Equity
Maternity & Paternity leave
WeWork Membership
WFH Yearly Stipend
L&D Stipend

Job summary

zerohash is seeking a Governance, Risk and Compliance (GRC) Manager to lead security, governance, risk management, and compliance programs in Europe, with a focus on DORA. The role requires deep IT security expertise and strong regulatory navigation, based in the Netherlands.

You will own DORA compliance, manage programs, coordinate with stakeholders, and drive governance across ISO 27001, SOC 1/2, and related standards. Strong leadership and cross-functional collaboration are essential.

Qualifications

  • Prior experience in a Risk Management / GRC leadership role.
  • Prior experience with the Digital Operational Resilience Act (DORA) is required.
  • Professional certifications such as CISSP, CISM, CRISC or CISA is a plus.
  • Proven experience in technical IT security, governance, risk management, and compliance roles.
  • Experience with SOC 1, SOC 2, and ISO 27001 is strongly preferred.
  • Excellent communication and interpersonal skills, with the ability to collaborate effectively with cross-functional teams.

Responsibilities

  • Provide day-to-day ownership of the company’s DORA compliance.
  • Stay current with laws and standards related to IT security and compliance.
  • Manage technical compliance programs and initiatives.
  • Conduct assessments to evaluate regulatory adherence and internal policies.
  • Prepare compliance reports and documentation for audits.
  • Develop and maintain governance policies, procedures, and standards.
  • Coordinate with stakeholders to establish governance committees.
  • Oversee incident management and root-cause analysis.
  • Deliver security, governance, risk, and compliance training.
  • Report to senior management and the board on risk and compliance.

Skills

GRC leadership
DORA knowledge
IT security
Regulatory compliance

Tools

GRC tools

Job description

About the Job

The Governance, Risk and Compliance (GRC) Manager will be responsible for developing, implementing, and maintaining the organization’s security and governance, risk management, and compliance programs within the Risk Function of zerohash in Europe, with a particular focus on DORA compliance. This role requires a deep technical understanding of IT security measures and risk management practices to ensure the security and integrity of the company's systems and data, align operations with regulatory requirements, and mitigate IT risks.
Please note we are only considering candidates based in the Netherlands at this time.

Key Responsibilities

Compliance:

  • Provide day to day ownership and management of the company’s compliance with DORA.
  • Stay current on and compliant with relevant laws, regulations, and industry standards related to IT security and compliance such as DORA, GDPR, NY DFS Part 500, and others.
  • Manage technical compliance programs and initiatives.
  • Conduct compliance assessments to evaluate adherence to regulatory requirements and internal policies.
  • Prepare compliance reports and documentation for regulatory audits and review.

Governance:

  • Develop and maintain governance policies, procedures, and standards in alignment with industry best practices and regulatory requirements.
  • Develop and maintain governance frameworks, technical policies, and procedures.
  • Manage governance frameworks such as ISO 27001, SOC 1, SOC 2, etc., in coordination with global zerohash security and audit staff, to ensure effective IT governance across the organization.
  • Coordinate with key stakeholders to establish governance committees and facilitate regular meetings to review and update policies and procedures.
  • Facilitate governance structures and technical committees.

Technical IT Security Management:

  • Develop and implement advanced IT security strategies and solutions.
  • Manage and monitor security systems, including firewalls, intrusion detection systems, and endpoint protection.
  • Conduct detailed security assessments, vulnerability scans, and penetration tests.
  • Respond to and resolve complex security incidents, including conducting forensic investigations and root cause analysis.
  • Ensure the implementation of security controls and best practices across IT systems and networks.

Risk Management:

  • Identify, assess, and prioritize technical risks, in coordination with the global Risk function.
  • Develop and implement risk management strategies and technical mitigation plans.
  • Conduct regular technical risk assessments and identify potential threats and vulnerabilities within zerohash infrastructure.
  • Develop risk mitigation strategies and action plans to address identified risks.
  • Monitor and track risk mitigation activities to ensure timely resolution and compliance with established policies and procedures.
  • Monitor and report on the status of technical risks and control effectiveness.

Policy and Procedure Development:

  • Develop, implement, and maintain technical security policies and procedures.
  • Ensure technical policies and procedures are communicated and enforced across the organization.

Incident Management:

  • Oversee the technical incident management process, in coordination with global zerohash response teams.
  • Ensure timely identification, reporting, and resolution of technical security incidents.
  • Conduct root cause analysis and implement corrective technical actions.

Security Awareness:

  • Develop and deliver technical security, governance, risk, and compliance training programs.
  • Collaborate with the security team to develop and deliver training programs on governance, risk management, and compliance.
  • Promote a culture of security awareness and compliance throughout the organization.

Stakeholder Engagement:

  • Collaborate with internal and external stakeholders, including auditors, regulators, and technical teams.
  • Provide technical guidance and support to management and staff on security and GRC-related matters.

Reporting:

  • Prepare and present regular technical reports on security, governance, risk, and compliance to senior management and the board of directors.
  • Maintain accurate technical records and documentation.
Requirements
  • Prior experience in a Risk Management / GRC leadership role is required.
  • Prior experience with the Digital Operational Resilience Act (DORA) is required.
  • Professional certifications such as CISSP, CISM, CRISC or CISA is a plus.
  • Proven experience in technical IT security, governance, risk management, and compliance roles.
  • Strong technical knowledge of IT governance frameworks, regulatory requirements, and best practices.
  • Experience with SOC 1, SOC 2, and ISO 27001 is strongly preferred.
  • Strong analytical and problem-solving skills with attention to detail.
  • Ability to manage multiple technical projects and priorities in a fast-paced environment.
  • Experience with technical security and GRC tools and software.
  • Excellent communication and interpersonal skills, with the ability to collaborate effectively with cross-functional teams.
  • Proficiency in risk assessment methodologies and tools.
  • Experience with IT audit processes and procedures.
  • Knowledge of other relevant laws and regulations such as GDPR, NYDFS Part 500, etc. is a plus.
Benefits

We believe a happy, motivated, and healthy team is the best way to succeed. We offer the following benefits:

  • Chance to earn equity
  • Maternity & Paternity leave
  • WeWork Membership
  • WFH Yearly Stipend
  • L&D Stipend (after 6 months)
About zerohash

zerohash's full stack financial infrastructure seamlessly connects fiat, crypto and stablecoins, enabling a better way to move and transfer money and value globally.

zerohash provides the complete technical infrastructure (delivered through API and SDK) as well as the global regulatory stack to easily and compliantly send, receive, store, and convert fiat, crypto, and stablecoins, in one platform.

Start-ups, enterprises and Fortune 500 companies, including Stripe, Interactive Brokers, Shift4, Franklin Templeton, and MoonPay embed our infrastructure to power a diverse range of use cases: cross-border payments, commerce, trading, remittance, payroll, tokenization, wallets and on and off-ramps.

Backed by Interactive Brokers, Point72 Ventures, NYCA, Bain Capital, and tastytrade.

The zerohash Culture

All zerohash employees are guided by the following characteristics and core principles:

  • Independence/Ownership - An ability to work autonomously. Join zerohash, pitch ideas, and shape the work you do.
  • Passion - We are innovating quickly and challenging the status quo. We want you to think big, be creative and make a difference every day.
  • Collaborative - A good attitude and respect for others. We’re teammates, not co-workers. Everything we do is a shared success and equally a shared failure - we talk in terms of “we” not “me”.
  • Initiative - An ability and passion for learning and asking questions. We will champion you, challenge you and push you to achieve your best - and we expect you to do the same.
  • Empathy - An ability to listen, respect, and understand your co-workers, customers, and everyone you interact with no matter how different they are to you.
  • Adaptability - An ability to respond quickly. We are in a fast-paced industry and so we expect you to be creative when solving a new problem and comfortable under pressure.
  • Transparency - We believe that transparency is critical to empowering everyone to make the best decisions, both the company to its people and vice versa.
  • Integrity - Integrity creates trust. As both an organization collectively and as individuals, it is our most valuable asset.

Follow us

Twitter

LinkedIn

Youtube

For candidates based in Colorado or California , please contact colorado-wages @zerohash.com to request compensation and benefits information regarding a particular role(s). Please include with you email the city you reside (or intend to reside in Colorado or California) and the title/link to the roles you're interested in.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Technical Program Manager
Staff Technical Program Manager

Zscaler • Amsterdam

On-site
EUR 120,000 - 160,000
Health plans
Parental leave options
Retirement options
+2
Senior Technical Support Engineer, EMEA
Senior Technical Support Engineer, EMEA

Linuxconfig • Amsterdam

Hybrid
EUR 60,000 - 90,000
Equity package
Health, vision & dental insurance
Hybrid work options
Principal Specialist Sales Engineer, Zero Trust Branch - Healthcare/SLED
Principal Specialist Sales Engineer, Zero Trust Branch - Healthcare/SLED

Socket.dev • Amsterdam

On-site
EUR 153,000 - 218,000
Senior Technical Support Engineer, EMEA
Senior Technical Support Engineer, EMEA

NightDragon Acquisition Corp. • Amsterdam

Hybrid
EUR 70,000 - 90,000
Equity package
Health, vision & dental insurance
Flexible vacation policy
+1
IT Risk Officer
IT Risk Officer

Coinmerce • Schiphol-Rijk

On-site
EUR 65,000 - 85,000
Free lunch
25 vacation days
Monthly chair massages
+2
Compliance Program Manager - Dora
Compliance Program Manager - Dora

Castle Island • Amsterdam

Hybrid
EUR 110,000 - 150,000
Competitive salary
Equity
Startup atmosphere
+2
Sr. Customer Engineer, Central & Eastern Europe - Hebrew Speaking
Sr. Customer Engineer, Central & Eastern Europe - Hebrew Speaking

Cloudflare • Amsterdam

On-site
EUR 112,000 - 154,000
Equity
Senior Technical Support Engineer, EMEA
Senior Technical Support Engineer, EMEA

Horizon3.ai • Amsterdam

Hybrid
EUR 70,000 - 110,000
Inclusive Team
Growth Opportunities
Innovative Culture
+1
Netherlands-Based DORA GRC & IT Security Lead
Netherlands-Based DORA GRC & IT Security Lead

Zero Hash • Amsterdam

On-site
EUR 90,000 - 130,000
Equity
Maternity & Paternity leave
WeWork Membership
+2
Commercial Counsel
Commercial Counsel

Horizon3 • Amsterdam

Hybrid
EUR 93,000 - 110,000
Inclusive Team
Growth Opportunities
Innovative Culture
+4