Compliance Program Manager - Dora
OpenFX
- Location
- Netherlands, London
- Work model
- On-Site
- Level
- Mid
- Posted
- 1h ago
Skills
About this role
About Us
OpenFX is on a mission to move money as freely as data, unrestricted by time zones, banking hours, or legacy systems. We are building the infrastructure that will power the next generation of cross-border payment systems for institutions. The team's execution has been exceptional, and we're scaling at a remarkable pace. Our stellar early team comes with experience in companies like J.P. Morgan, Goldman Sachs, FalconX, Paypal, Affirm, Polygon, Kraken, Nium & others. We're backed by Accel, Lightspeed, NfX and other top-tier investors.
Role Overview
We are looking for a Security & Compliance Engineer to turn regulatory requirements into real, running controls — and then prove to auditors that they work. This is a senior, hands-on role for someone who thrives in fast-paced, heavily regulated environments and knows how to make compliance provable in production rather than on paper.
OpenFX is expanding across Europe in a heavily regulated financial environment. As we scale into EU markets, regulators, auditors, and enterprise partners expect provable, continuously operating security controls — not slide decks or one-off audits. Compliance requirements (DORA, GDPR, SOC 2, ISO 27001, and region-specific regulations) are increasing faster than our ability to operationalize them, and this role exists to close that gap.
You will own the security controls and evidence that regulators and auditors care about, end to end — from translating regulatory language into concrete mechanisms through to audit walkthroughs and remediation. You will partner closely with Legal, Compliance, Risk, and engineering to ensure compliance is built into the platform rather than bolted on after the fact.
This role is based in Amsterdam, Netherlands (EU/EEA).
Key Responsibilities
• Own audit-ready security controls
• Design, implement, and maintain technical and operational controls for DORA, GDPR, SOC 2, ISO 27001, and future regional requirements.
• Ensure controls are not just documented, but actually enforced in AWS, Kubernetes, and application layers.
• Be the technical counterpart to Legal, Compliance & Risk <ul