Rodeo
ResourcesPartnersSign in

OpenFX

Compliance Program Manager - Dora

London
Posted about 14 hours ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

About Us

OpenFX is on a mission to move money as freely as data, unrestricted by time zones, banking hours, or legacy systems. We are building the infrastructure that will power the next generation of cross-border payment systems for institutions. The team's execution has been exceptional, and we're scaling at a remarkable pace. Our stellar early team comes with experience in companies like J.P. Morgan, Goldman Sachs, FalconX, Paypal, Affirm, Polygon, Kraken, Nium & others. We're backed by Accel, Lightspeed, NfX and other top-tier investors.

Role Overview

We are looking for a Security & Compliance Engineer to turn regulatory requirements into real, running controls — and then prove to auditors that they work. This is a senior, hands-on role for someone who thrives in fast-paced, heavily regulated environments and knows how to make compliance provable in production rather than on paper.

OpenFX is expanding across Europe in a heavily regulated financial environment. As we scale into EU markets, regulators, auditors, and enterprise partners expect provable, continuously operating security controls — not slide decks or one-off audits. Compliance requirements (DORA, GDPR, SOC 2, ISO 27001, and region-specific regulations) are increasing faster than our ability to operationalize them, and this role exists to close that gap.

You will own the security controls and evidence that regulators and auditors care about, end to end — from translating regulatory language into concrete mechanisms through to audit walkthroughs and remediation. You will partner closely with Legal, Compliance, Risk, and engineering to ensure compliance is built into the platform rather than bolted on after the fact.

This role is based in Amsterdam, Netherlands (EU/EEA).

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Key Responsibilities

  • Own audit-ready security controls

    • Design, implement, and maintain technical and operational controls for DORA, GDPR, SOC 2, ISO 27001, and future regional requirements.
    • Ensure controls are not just documented, but actually enforced in AWS, Kubernetes, and application layers.
  • Be the technical counterpart to Legal, Compliance & Risk

    • Translate regulatory language into concrete security mechanisms.
    • Partner with Legal and Compliance to monitor new regulations and assess technical impact.
    • Decide what is "good enough" vs. over-engineered for compliance.
  • Run audits instead of reacting to them

    • Own audit preparation, evidence collection, walkthroughs, and remediation tracking.
    • Build repeatable, automated evidence pipelines instead of last-minute scrambles.
    • Be the person auditors trust when they ask, "Show me how this actually works."
  • Embed compliance into the platform

    • Work with engineering to design systems that are secure by default and defensible to regulators.
    • Ensure logging, access controls, encryption, monitoring, and change management meet regulatory expectations.
  • Automate compliance wherever possible

    • Build tooling and scripts to continuously validate controls (access reviews, logging coverage, config drift).
    • Reduce manual compliance work over time by pushing checks into code and infrastructure.

What we are looking for

Must-haves:

  • 6+ years in security engineering, cloud security, or compliance-focused security roles.
  • Hands-on, operational experience implementing DORA in a production/regulated environment (not advisory only) — e.g. ICT risk management, incident classification and reporting, third-party/ICT vendor oversight, and digital operational resilience testing. GDPR implementation experience is a strong bonus.
  • Experience supporting SOC 2 and/or ISO 27001 audits (strong plus).
  • Ability to translate regulatory requirements into technical controls.
  • Strong working knowledge of AWS security fundamentals (IAM, logging, encryption, networking).
  • Comfortable owning auditor interactions and explaining systems clearly.
  • Experience building or automating security/compliance processes (Python, Bash, Go, etc.).
  • Accountability for an audit outcome — if you've never owned one, this role is not a fit.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

What helps you stand out:

  • Experience securing Kubernetes environments.
  • Familiarity with AppSec tooling (SAST/DAST, manual testing).
  • Experience with AWS security services (GuardDuty, Config, Security Hub).
  • Prior work in fintech, payments, or regulated infrastructure.
  • Security or compliance certifications (CISSP, CISA, ISO 27001 Lead Implementer, AWS Security).
  • Familiarity with EU financial regulators and national competent authorities (e.g. DNB/AFM in the Netherlands, EBA/ESMA).

What We Offer

  • Competitive salary and benefits package.
  • Equity in a rapidly growing company.
  • Opportunity to work in a fast-paced startup at the forefront of fintech innovation.
  • Opportunity to make a significant impact on global financial infrastructure.
  • Collaborative work culture with emphasis on personal and professional growth.

We are committed to building a diverse and inclusive workplace. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

DORA Compliance
Security Engineering
Cloud Security
GDPR
SOC 2
ISO 27001
AWS Security
Kubernetes Security
Python
Bash
Go
Audit Management
ICT Risk Management
Technical Control Design
Evidence Automation
Regulatory Translation

Location

London, England, United Kingdom

Sign up to applySee more jobs like this