Apply Edge Start your job search

Medior/Senior Compliance Lead

Bluem payment & identity services · Amersfoort, Utrecht, Netherlands

Apply & track with Apply Edge

Location: Amersfoort, the NetherlandsEmployment: Full-timeLevel: Medior / SeniorAbout BluemBluem B.V. is a Dutch fintech and SaaS company based in Amersfoort.

We develop digital services that help organisations securely identify, onboard and interact with their customers.Our solutions include identity verification, digital onboarding, banking and identity-related services, and compliance-focused integrations. Security, privacy and regulatory compliance are therefore an important part of both our products and our daily operations.As a relatively small and technical organisation, we work with short communication lines and a high degree of individual responsibility. Compliance at Bluem is not limited to writing policies or maintaining documentation: it requires translating requirements into working processes, coordinating implementation across multiple teams, and ensuring that controls are operational, evidenced and audit-ready.The roleWe are looking for a Medior/Senior Compliance Lead who can independently lead and further develop Bluem's information security, privacy and compliance framework.This is a hands-on role with significant ownership. You will be responsible not only for maintaining existing compliance activities, but also for taking new regulatory, certification and assurance requirements from initial interpretation through gap assessment, design, implementation, stakeholder coordination, evidence collection, audit and remediation.The role combines GRC, information security governance, audit management, privacy, operational compliance and cross-functional programme coordination.What you will doLead the Compliance Department of four people and coordinate its priorities and initiatives.Coordinate and further develop Bluem's Information Security Management System (ISMS).Lead end-to-end implementation of new compliance, security and assurance requirements across the organisation.Lead and support certification and assurance activities, including ISO/IEC 27001, ISAE 3402, NIS2-related requirements, DIATF and other applicable frameworks.Perform gap assessments and translate findings into concrete implementation plans, actions, owners and evidence requirements.Coordinate complex compliance initiatives involving Management, Legal, IT, Development, Infrastructure and other stakeholders.Drive implementation to completion, including stakeholder follow-up, remediation tracking, evidence collection and audit preparation.Maintain and improve information security policies, procedures, standards and supporting documentation.Alongside the Legal Counsel, translate regulatory, contractual and certification requirements into practical controls for technical and non-technical teams.Maintain risk assessments and support information security and supplier risk management.Collaborate with the Technical Compliance Specialist on the technical implementation of policies and controls requiring system or configuration changes.Own relevant Jira spaces, workflows and configurations used for compliance processes.Work with IT, Infrastructure and Development teams on areas including access management, vulnerability management, backups, change management, incident management and business continuity.Maintain compliance evidence and control monitoring within tools such as Vanta and Jira Service Management.Support privacy and data protection activities, including DPIAs, vendor assessments, DPAs and wider GDPR compliance.Monitor progress across multiple parallel compliance projects and ensure agreed actions are followed through to completion.What we are looking forYou have at least 3 years of relevant professional experience in information security governance, GRC, compliance, IT risk or a comparable role.You are comfortable taking independent ownership of complex compliance projects and coordinating stakeholders across different disciplines and seniority levels.You should be able to take a regulatory, certification or contractual requirement, determine what it means for the organisation, identify the gaps, design an appropriate solution, coordinate its implementation and demonstrate through evidence that the requirement has been met.We are looking for someone who:Has experience with ISO/IEC 27001 and information security management systems.Understands risk management, controls, audits, corrective actions and evidence management.Has experience preparing for or coordinating external audits or certifications.Has experience implementing compliance requirements rather than only maintaining existing controls.Can manage projects involving multiple technical and non-technical stakeholders.Can write clear policies, procedures and other governance documentation.Can communicate effectively with technical specialists, management and external auditors.Is comfortable challenging existing practices when they do not meet security or compliance requirements.Can manage multiple compliance projects, dependencies and deadlines simultaneously.Is able to drive actions to completion and follow up with stakeholders where necessary.Works independently and proactively rather than waiting for detailed instructions.Has strong organisational, analytical and documentation skills.Is professionally proficient in English.Experience with ISAE 3402, NIS2, DIATF, GDPR, business continuity, SaaS, fintech or digital identity is considered an advantage.Working at BluemBecause Bluem is a relatively small organisation, you will have significant visibility and ownership. You will work directly with senior management, developers, infrastructure specialists, IT, Legal and other teams rather than operating in an isolated compliance department.The role offers the opportunity to work across information security, privacy, risk, audit and governance while playing a central role in the continued development and implementation of Bluem's compliance programme.This position is particularly suited to someone who enjoys taking complex requirements and turning them into practical, organisation-wide solutions from start to finish.