SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Security Program Manager

Adyen - Amsterdam, North Holland, Netherlands - In-office - posted 2026-08-05

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Adyen is seeking a Senior Security Program Manager to join the Tech Regulatory team within the first line of defense. This role is responsible for ensuring that Adyen's products and services comply with security regulations and laws globally, managing multiple security compliance programs such as PCI-DSS and PCI 3DS. Key responsibilities include: **Program Management**: Manage security compliance programs across multiple domains, including PCI-DSS and PCI 3DS certifications, plus broader security risk domains such as security detection and monitoring, data loss prevention, and vulnerability management. Additionally, anchor three core operational risk domains: Incident Management, Change Management, and Business Continuity Management. **Standards & Frameworks**: Define security standards and ensure frameworks withstand internal and external scrutiny from auditors and regulators. **Operational Design**: Translate complex regulatory requirements into actionable operational program designs that engineering teams can implement effectively. **Documentation & Enablement**: Plan, write, and implement process documents and enablement materials for diverse audiences including operational teams, leadership, auditors, and regulators. **Cross-functional Coordination**: Align and provide input to roadmaps and programs across enterprise risk, security, and the broader technology organization. **Regulatory Alignment**: Oversee regulatory frameworks such as DORA and other DNB mandates, maintaining awareness of obligations across global regions (OCC, MAS TRM, RBI, BNM). Required qualifications: 5+ years of experience in security compliance, tech operations management, security and technology risk, or adjacent disciplines within fast-growing companies, ideally in financial services or payments. Experience with security engineering/GRC roles, PCI-DSS and 3DS domain expertise, and proven track record as a first-line owner embedded in operational reality. Strong ability to manage complex operational risk domains simultaneously and excellent written communication skills for both technical and non-technical stakeholders. Preferred: Working knowledge of regulatory standards (DORA, PCI-DSS, PCI 3DS, ISO 27001, SOC 1/2), ability to write scripts or queries for reporting and data analysis, detail-oriented and analytical mindset, collaborative team player.

Similar roles