8 часов назад
Compliance Program Manager - Dora (DORA)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Compliance Program Manager - Dora (DORA): Building and operating audit-ready security controls and evidence pipelines for regulated cross-border payment infrastructure with an accent on DORA, GDPR, SOC 2, ISO 27001, and cloud security. Focus on translating regulatory requirements into AWS, Kubernetes, and application-layer controls, automating compliance validation, and leading audit walkthroughs and remediation.
Location: Based in Amsterdam, Netherlands (EU/EEA); London is also listed as a location
Company
builds infrastructure for cross-border payment systems serving institutional customers.
What you will do
- Design, implement, and maintain technical and operational controls for DORA, GDPR, SOC 2, ISO 27001, and regional regulations.
- Enforce security controls across AWS, Kubernetes, and application layers.
- Translate regulatory requirements into practical security mechanisms with Legal, Compliance, Risk, and Engineering.
- Lead audit preparation, evidence collection, auditor walkthroughs, and remediation tracking.
- Build automated evidence pipelines and tooling for access reviews, logging coverage, and configuration drift.
- Embed secure-by-default logging, access control, encryption, monitoring, and change management into the platform.
Requirements
- 6+ years of experience in security engineering, cloud security, or compliance-focused security roles.
- Hands-on production experience implementing DORA, including ICT risk management, incident classification and reporting, third-party oversight, and operational resilience testing.
- Experience supporting SOC 2 and/or ISO 27001 audits and accountability for audit outcomes.
- Strong AWS security knowledge, including IAM, logging, encryption, and networking.
- Ability to translate regulatory requirements into technical controls and explain systems clearly to auditors.
- Experience automating security and compliance processes with Python, Bash, Go, or similar tools.
Nice to have
- Experience securing Kubernetes environments and using AppSec tooling such as SAST, DAST, and manual testing.
- Experience with GuardDuty, AWS Config, and Security Hub.
- Background in fintech, payments, or regulated infrastructure.
- CISSP, CISA, ISO 27001 Lead Implementer, or AWS Security certification.
- Familiarity with EU financial regulators and competent authorities, including DNB, AFM, EBA, and ESMA.
Culture & Benefits
- Competitive salary and benefits package.
- Equity in a rapidly growing fintech startup.
- Opportunity to influence global financial infrastructure.
- Collaborative environment focused on personal and professional growth.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →