Jobs / product
Senior Security Program Manager
Adyen · Amsterdam
What you will do
- Program Management: Manage programs across multiple domains - for example responsible for program managing the PCI-DSS and PCI 3DS certifications in addition to supporting security on regulatory requirements surrounding a broad set of security risk domains for example security detection and monitoring, data loss prevention, vulnerability management and three core operational risk domains as your team’s core anchor: Incident Management, Change Management, and Business Continuity Management
- Defining standards and ensuring frameworks withstand internal and external scrutiny
- Operational Design: Translate complex regulatory requirements into actionable operational program designs that engineering teams can implement.
- Documentation: Plan, write, and implement process documents and enablement materials that work for diverse audiences including operational teams, leadership, auditors, and regulators.
- Cross-functional Coordination: Align and provide input to roadmaps and programs across enterprise risk, security, and the broader technology organization.
- Regulatory Alignment: Oversee regulatory frameworks such as DORA and other DNB mandates, and maintaining awareness of obligations across our other global regions (e.g., OCC, MAS TRM, RBI, BNM).
What they look for
- Demonstrated background and 5+ years experience in implementing security compliance, tech operations management, security and technology risk, or a closely adjacent discipline within a fast-growing company, ideally in financial services or payments.
- Experience in security engineering/GRC roles with prior PCI-DSS and 3DS domain experience.
- Proven experience as a first-line owner who is embedded in operational reality.
- Ability to manage complex operational risk domains simultaneously, specifically Incident Management, Change Management, and Business Continuity Management.
- Strong written communication skills, capable of explaining concepts and producing artifacts that satisfy both technical and non-technical stakeholders.