Compliance Program Manager - Dora
On-siteLondon, England, United Kingdom
Job Summary
Design and maintain audit-ready security controls for DORA, GDPR, SOC 2, and ISO 27001 by translating regulatory language into concrete AWS, Kubernetes, and application-layer mechanisms. Own end-to-end audit preparation, evidence collection, walkthroughs, and remediation tracking while building automated pipelines to validate logging, access controls, and encryption. Partner with Legal, Compliance, and Risk to embed security by default, reduce manual work through scripting, and serve as the technical counterpart auditors trust when verifying operational resilience. Based in Amsterdam, this senior role requires 6+ years in security engineering with hands-on production experience in ICT risk management and vendor oversight.
Required Qualifications
- 6+ years in security engineering, cloud security, or compliance-focused security roles
- Hands-on, operational experience implementing DORA in a production/regulated environment
- Experience supporting SOC 2 and/or ISO 27001 audits
- Ability to translate regulatory requirements into technical controls
- Strong working knowledge of AWS security fundamentals (IAM, logging, encryption, networking)
- Comfortable owning auditor interactions and explaining systems clearly
- Experience building or automating security/compliance processes (Python, Bash, Go, etc.)
- Accountability for an audit outcome
Desired Qualifications
- GDPR implementation experience
- Experience securing Kubernetes environments
- Familiarity with AppSec tooling (SAST/DAST, manual testing)
- Experience with AWS security services (GuardDuty, Config, Security Hub)
- Prior work in fintech, payments, or regulated infrastructure
- Security or compliance certifications (CISSP, CISA, ISO 27001 Lead Implementer, AWS Security)
- Familiarity with EU financial regulators and national competent authorities (e.g. DNB/AFM in the Netherlands, EBA/ESMA)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.