Compliance Program Manager
Core
Design, implement, and maintain technical and operational security controls to ensure compliance with regulatory frameworks like SOC 2, ISO 27001, GDPR, and DORA for a cross-border payment infrastructure platform.
Role type
Senior IC compliance program manager (security controls)
Builds
Automated evidence pipelines and secure-by-default systems for cross-border payment infrastructure
Domain
Fintech / Cross-border payments / Cloud Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
SOC 2, ISO 27001, GDPR, DORA compliance frameworks, AWS security fundamentals (IAM, logging, encryption, networking), translating regulatory requirements into technical controls, auditor interaction, automating security/compliance processes (Python, Bash, Go)
Preferred skills
Kubernetes security, AppSec tooling (SAST/DAST), AWS security services (GuardDuty, Config, Security Hub), fintech/payments/regulated infrastructure experience, security/compliance certifications (CISSP, CISA, ISO 27001 Lead Implementer, AWS Security)
Technologies
AWS, Kubernetes, Python, Bash, Go, SAST, DAST, GuardDuty, Config, Security Hub
Responsibilities
Design and maintain technical controls for SOC 2, ISO 27001, GDPR, and DORA; Ensure controls are enforced in AWS, Kubernetes, and application layers; Translate regulatory language into concrete security mechanisms; Own audit preparation, evidence collection, and remediation tracking; Build automated evidence pipelines; Work with engineering to design secure-by-default systems; Ensure logging, access controls, encryption, and monitoring meet regulatory expectations; Build tooling to continuously validate controls; Monitor new regulations and assess technical impact
Seniority
Senior, hands-on IC