OpenFX jobs
OpenFX logoOpenFX

Compliance Program Manager

📍 Bangalore/RemoteRemote📂 Risk, Compliance & Legal📅 Posted Feb 23, 2026
Apply at OpenFX

Job Description

The Problem

OpenFX is expanding globally in a heavily regulated financial environment. As we scale into new regions, regulators, auditors, and enterprise partners expect provable, continuously operating security controls - not slide decks or one-off audits.

Right now, compliance requirements (DORA, GDPR, SOC 2, ISO 27001, and region-specific regulations) are increasing faster than our ability to operationalize them in production systems. If we don’t solve this, we risk:

We need someone who can turn regulatory requirements into real, running controls - and then prove to auditors that they work.

This role has been created to support OpenFX as we continue expanding our institution-grade, regulator-facing infrastructure.

What You’ll Actually Do & Own (First 6–12 Months)

You will own the security controls and evidence that regulators and auditors care about, end to end.

Specifically, you will:

  1. Own audit-ready security controls
    • Design, implement, and maintain technical and operational controls for SOC 2, ISO 27001, GDPR, DORA, and future regional requirements
    • Ensure controls are not just documented, but actually enforced in AWS, Kubernetes, and application layers
  2. Be the technical counterpart to Legal, Compliance & Risk
    • Translate regulatory language into concrete security mechanisms
    • Partner with Legal/Compliance to monitor new regulations and assess technical impact
    • Decide what is “good enough” vs. over-engineered for compliance
  3. Run audits instead of reacting to them
    • Own audit preparation, evidence collection, walkthroughs, and remediation tracking
    • Build repeatable, automated evidence pipelines instead of last-minute scrambles
    • Be the person auditors trust when they ask, “Show me how this actually works”
  4. Embed compliance into the platform
    • Work with engineering to design systems that are secure by default and defensible to regulators
    • Ensure logging, access controls, encryption, monitoring, and change management meet regulatory expectations
  5. Automate compliance wherever possible
    • Build tooling/scripts to continuously validate controls (access reviews, logging coverage, config drift, etc.)
    • Reduce manual compliance work over time by pushing checks into code and infrastructure

What Success Looks Like

You’ll know you’re succeeding if:

If audits feel boring and predictable, you’re doing the job well.

Requirements

Required (Non-Negotiable)

If you’ve never been accountable for an audit outcome, this role is not a fit.

Preferred (Nice to Have)

Why This Role

This is not a checkbox compliance role.

In this role, you will:

You’ll learn how to build compliance that scales, not compliance that slows teams down - a skillset that’s rare and extremely valuable in fintech.

This Role Is Not For You If:


Apply at OpenFX