Назад
Company hidden
8 часов назад

Compliance Program Manager - Dora (DORA)

Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UK/Netherlands
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Compliance Program Manager - Dora (DORA): Building and operating audit-ready security controls and evidence pipelines for regulated cross-border payment infrastructure with an accent on DORA, GDPR, SOC 2, ISO 27001, and cloud security. Focus on translating regulatory requirements into AWS, Kubernetes, and application-layer controls, automating compliance validation, and leading audit walkthroughs and remediation.

Location: Based in Amsterdam, Netherlands (EU/EEA); London is also listed as a location

Company

hirify.global builds infrastructure for cross-border payment systems serving institutional customers.

What you will do

  • Design, implement, and maintain technical and operational controls for DORA, GDPR, SOC 2, ISO 27001, and regional regulations.
  • Enforce security controls across AWS, Kubernetes, and application layers.
  • Translate regulatory requirements into practical security mechanisms with Legal, Compliance, Risk, and Engineering.
  • Lead audit preparation, evidence collection, auditor walkthroughs, and remediation tracking.
  • Build automated evidence pipelines and tooling for access reviews, logging coverage, and configuration drift.
  • Embed secure-by-default logging, access control, encryption, monitoring, and change management into the platform.

Requirements

  • 6+ years of experience in security engineering, cloud security, or compliance-focused security roles.
  • Hands-on production experience implementing DORA, including ICT risk management, incident classification and reporting, third-party oversight, and operational resilience testing.
  • Experience supporting SOC 2 and/or ISO 27001 audits and accountability for audit outcomes.
  • Strong AWS security knowledge, including IAM, logging, encryption, and networking.
  • Ability to translate regulatory requirements into technical controls and explain systems clearly to auditors.
  • Experience automating security and compliance processes with Python, Bash, Go, or similar tools.

Nice to have

  • Experience securing Kubernetes environments and using AppSec tooling such as SAST, DAST, and manual testing.
  • Experience with GuardDuty, AWS Config, and Security Hub.
  • Background in fintech, payments, or regulated infrastructure.
  • CISSP, CISA, ISO 27001 Lead Implementer, or AWS Security certification.
  • Familiarity with EU financial regulators and competent authorities, including DNB, AFM, EBA, and ESMA.

Culture & Benefits

  • Competitive salary and benefits package.
  • Equity in a rapidly growing fintech startup.
  • Opportunity to influence global financial infrastructure.
  • Collaborative environment focused on personal and professional growth.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →