SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
OpenFX is building cross-border payment infrastructure for institutions, backed by top-tier investors (Accel, Faction, NfX) with a team from JP Morgan, Goldman Sachs, FalconX, PayPal, and other leading fintech firms. The company is scaling globally in a heavily regulated financial environment and needs a Compliance Program Manager to own security controls and regulatory evidence end-to-end.
In this role, you will design, implement, and maintain technical and operational controls for SOC 2, ISO 27001, GDPR, DORA, and future regional requirements. You'll translate regulatory language into concrete security mechanisms across AWS, Kubernetes, and application layers, working closely with Legal, Compliance, and Engineering teams. Key responsibilities include ensuring controls are enforced (not just documented), owning audit preparation and evidence collection, building automated evidence pipelines, and reducing manual compliance work by pushing checks into code and infrastructure.
You will also design systems that are secure by default and defensible to regulators, ensure logging, access controls, encryption, monitoring, and change management meet regulatory expectations, and build tooling to continuously validate controls. You'll monitor new regulations and assess their technical impact across the platform.
Required qualifications: 6+ years in security engineering, cloud security, or compliance-focused security roles; hands-on experience supporting SOC 2, ISO 27001, GDPR, DORA, or similar frameworks; ability to translate regulatory requirements into technical controls; strong AWS security knowledge (IAM, logging, encryption, networking); comfort owning auditor interactions; and experience building or automating security/compliance processes (Python, Bash, Go, etc.).
Preferred: Kubernetes security experience, AppSec tooling familiarity (SAST/DAST), AWS security services (GuardDuty, Config, Security Hub), fintech/payments/regulated infrastructure background, and relevant certifications (CISSP, CISA, ISO 27001 Lead Implementer, AWS Security).