Compliance Program Manager - Dora in London

Compliance Program Manager - Dora in London

London Full-Time 63000 - 77000 £ / year (est.) No working from home possible
OpenFX

At a Glance

  • Tasks: Own security controls and ensure compliance with regulations like DORA and GDPR.
  • Company: Join a fast-growing fintech startup revolutionising cross-border payments.
  • Benefits: Competitive salary, equity, and a collaborative work culture focused on growth.
  • Other info: Diverse and inclusive workplace committed to personal and professional development.
  • Why this job: Make a real impact on global financial infrastructure in a dynamic environment.
  • Qualifications: 6+ years in security engineering with hands-on compliance experience.

The predicted salary is between 63000 - 77000 £ per year.

Open FX is on a mission to move money as freely as data, unrestricted by time zones, banking hours, or legacy systems.

We are building the infrastructure that will power the next generation of cross-border payment systems for institutions.

The team's execution has been exceptional, and we're scaling at a remarkable pace.

Our stellar early team comes with experience in companies like J.

Morgan, Goldman Sachs, Falcon X, Pay Pal, Affir, Polygon, Kraken, Nium & others.

We're backed by Accel, Lightspeed, Nf X and other top‑tier investors.

Role Overview

We are looking for a

Security & Compliance Engineer to turn regulatory requirements into real, running controls — and then prove to auditors that they work.

This is a senior, hands‑on role for someone who thrives in fast‑paced, heavily regulated environments and knows how to make compliance provable in production rather than on paper.

Open FX is expanding across Europe in a heavily regulated financial environment.

As we scale into EU markets, regulators, auditors, and enterprise partners expect provable, continuously operating security controls — not slide decks or one‑off audits.

Compliance requirements (DORA, GDPR, SOC 2, ISO 27001, and region‑specific regulations) are increasing faster than our ability to operationalize them, and this role exists to close that gap.

You will own the security controls and evidence that regulators and auditors care about, end to end — from translating regulatory language into concrete mechanisms through to audit walkthroughs and remediation.

You will partner closely with Legal, Compliance, Risk, and engineering to ensure compliance is built into the platform rather than bolted on after the fact.

This role is based in Amsterdam, Netherlands (EU/EEA).

Key Responsibilities

  • Own audit-ready security controls
  • Design, implement, and maintain technical and operational controls for DORA, GDPR, SOC 2, ISO 27001, and future regional requirements.
  • Ensure controls are not just documented, but actually enforced in AWS, Kubernetes, and application layers.
  • Be the technical counterpart to Legal, Compliance & Risk
  • Translate regulatory language into concrete security mechanisms.
  • Partner with Legal and Compliance to monitor new regulations and assess technical impact.
  • Decide what is “good enough” vs. over-engineered for compliance.
  • Run audits instead of reacting to them
  • Own audit preparation, evidence collection, walkthroughs, and remediation tracking.
  • Build repeatable, automated evidence pipelines instead of last-minute scrambles.
  • Be the person auditors trust when they ask, “Show me how this actually works.”
  • Embed compliance into the platform
  • Work with engineering to design systems that are secure by default and defensible to regulators.
  • Ensure logging, access controls, encryption, monitoring, and change management meet regulatory expectations.
  • Automate compliance wherever possible
  • Build tooling and scripts to continuously validate controls (access reviews, logging coverage, config drift).
  • Reduce manual compliance work over time by pushing checks into code and infrastructure.
  • What we are looking for
  • Must-haves
  • 6+ years in security engineering, cloud security, or compliance-focused security roles.
  • Hands‑on, operational experience implementing DORA in a production/regulated environment (not advisory only) — e. g.

ICT risk management, incident classification and reporting, third‑party/ICT vendor oversight, and digital operational resilience testing.

GDPR implementation experience is a strong bonus.

  • Experience supporting SOC 2 and/or ISO 27001 audits (strong plus).
  • Ability to translate regulatory requirements into technical controls.
  • Strong working knowledge of AWS security fundamentals (IAM, logging, encryption, networking).
  • Comfortable owning auditor interactions and explaining systems clearly.
  • Experience building or automating security/compliance processes (Python, Bash, Go, etc.).
  • Accountability for an audit outcome — if you've never owned one, this role is not a fit.
  • What helps you stand out
  • Experience securing Kubernetes environments.
  • Familiarity with App Sec tooling (SAST/DAST, manual testing).
  • Experience with AWS security services (Guard Duty, Config, Security Hub).
  • Prior work in fintech, payments, or regulated infrastructure.
  • Security or compliance certifications (CISSP, CISA, ISO 27001 Lead Implementer, AWS Security).
  • Familiarity with EU financial regulators and national competent authorities (e. g. DNB/AFM in the Netherlands, EBA/ESMA).

What We Offer

  • Competitive salary and benefits package.
  • Equity in a rapidly growing company.
  • Opportunity to work in a fast‑paced startup at the forefront of fintech innovation.
  • Opportunity to make a significant impact on global financial infrastructure.
  • Collaborative work culture with emphasis on personal and professional growth.

We are committed to building a diverse and inclusive workplace.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.

#J-18808-Ljbffr

Compliance Program Manager - Dora in London employer: OpenFX

OpenFX is an exceptional employer, offering a dynamic work culture that thrives on innovation and collaboration. As a Product Manager in London, you'll be at the forefront of cross-border payment solutions, with ample opportunities for professional growth and direct impact on revenue through currency expansion. Join a high-calibre team backed by top-tier investors, where your contributions will shape the future of financial infrastructure in Europe.

OpenFX

Contact Details:

OpenFX Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Compliance Program Manager - Dora in London

Join Compliance Communities

Get involved in compliance and risk communities — both online and offline. Look for forums, LinkedIn groups, or even local meetups where compliance pros hang out. You never know who might drop a job opportunity your way!

Attend Industry Conferences

Keep an eye out for compliance and risk management conferences and workshops in your area. These events are a goldmine for networking, and they often have job boards or recruiters on-site looking for new talent. Plus, it’s a chance to learn what's trending in the field.

Leverage Your University Career Services

If you’ve recently graduated or are still studying, head over to your university's career services. Many companies, including those in compliance, actively recruit fresh talent through these services, so make sure you tap into that resource.

Showcase Your Knowledge Online

Start writing articles or blog posts about compliance topics that interest you. Share them on platforms like LinkedIn to demonstrate your knowledge and passion. This not only builds your presence in the field but can also catch the attention of companies like OpenFX looking for candidates who are engaged and informed.

We think you need these skills to ace Compliance Program Manager - Dora in London

Security Engineering
Cloud Security
Compliance-focused Security
DORA Implementation
GDPR Implementation
SOC 2 Audit Support
ISO 27001 Audit Support

Some tips for your application 🫡

Show Your Understanding of Compliance:In the compliance-risk field, it's super important to showcase your understanding of regulations and risk management frameworks. Highlight any relevant coursework, certifications (like ICA or AML), or even projects that demonstrate your knowledge and commitment to this area. We want to see how you can navigate this complex landscape!

Quantify Your Achievements:When detailing your experience, try to quantify your achievements. For example, if you've previously worked on a project that improved compliance metrics or reduced risk exposure, give us the numbers! This data-driven approach really stands out to hiring managers in compliance-risk roles.

Tailor Your CV to Reflect Relevant Skills:Make sure your CV highlights skills that are particularly relevant to compliance, like attention to detail, analytical thinking, and report writing. Ensure these are easy to spot – consider using bullet points to break down your responsibilities and achievements for maximum impact!

Craft a Motivating Cover Letter:In your cover letter, let us know why you’re excited about the compliance-risk role at OpenFX. Share what motivates you about compliance, and how you believe you can contribute to our mission. This is your chance to showcase not only your skills but also your passion for this important field!

How to prepare for a job interview at OpenFX

Master the Regulations

Brush up on key compliance regulations relevant to the industry you're applying to. Familiarising yourself with specific laws and frameworks used in your field will give you an edge during technical questions. Show that you’re not just aware of them but can also apply them—think real-life scenarios!

Show Your Analytical Skills

Compliance roles really focus on analytical skills, so be prepared for case studies or situational questions during the interview. We've got to demonstrate how we approach risk assessments or compliance audits, possibly drawing on examples from past experiences or university projects. Bring some thoughtful case scenarios to discuss!

Know Your Tools

Get comfortable with commonly used compliance software and tools. Familiarity with platforms like RSA or MetricStream can really impress during your interview, as it shows you're ready to hit the ground running. If you’ve had any experience with them, make sure to highlight that!

Align with Company Culture

Since it's a full-time position, show your long-term commitment and interest in the company’s mission and values. Dive into how your ethics and professional philosophy align with OpenFX’s stance on compliance. A shared vision can really resonate with interviewers looking for fit as much as skill!