Compliance & Certifications Associate (m/f/d) - Remote within Germany - Full-time or part-time

 Posted a day ago
     
⭐ 2-5 years experience
Apply Now

Please mention DailyRemote when applying

AI Summary

You will lead the company's certification efforts, including ISO 27001 and SOC 2, while managing internal policies and regulatory compliance. Additionally, you will oversee vendor risk, support legal contract reviews, and ensure accurate reporting to bank partners.

Credibur builds the operational backbone for non-bank lending and structured credit in Europe. As we grow, so does what our customers, bank partners, and regulators expect of us. We are looking for someone to take responsibility for compliance and certifications at Credibur and build the function as the company scales.

This role comes with real ownership from day one. You will lead our certification work, keep our policies and regulatory obligations in order, and become the person the company relies on to stay compliant without slowing down. Done well, this means folding legal and certification requirements into how the company actually works, not bolting them on from the side, and keeping people informed and involved as that happens. That is what makes Credibur more professional, efficient, and future-proof as we grow. You will work closely with our founder, who has held compliance and risk roles before, and with our external advisors.

Tasks

  • Certifications. Take responsibility for the internal side of our ISO 27001 certification and, from there, SOC 2. Coordinate with our external advisors, lead the plan inside the company, collect and organise evidence, and track deliverables to completion.
  • Policies and governance. Draft, maintain, and improve our internal policies so they are clear, current, and actually used. Keep our governance framework up to date as we grow.
  • Regulatory and outsourcing compliance. Manage our outsourcing compliance and make sure regular reporting to our bank partners is accurate and on time. Familiarity with MaRisk or DORA helps here.
  • Vendor and third-party risk. Run due diligence on our vendors and maintain the ongoing third-party risk checks.
  • Contracts and legal support. Organise and maintain our contracts, carry out first-pass reviews, and support our legal counsel on day-to-day matters.

Requirements

  • Around two to five years in compliance, governance, risk, or audit, whether from an advisory or audit firm or in-house at a fintech or regulated business.
  • Hands-on experience with at least one certification, ISO 27001, SOC 2, or comparable. You understand what auditors expect and what good evidence looks like.
  • A pragmatic, risk-based approach. You know when a control is sufficient and you keep compliance proportionate to the business.
  • The ability to coordinate across teams and keep deadlines on track.
  • Structured and detail-oriented, with clear written German and English. Our regulatory and bank-partner work runs in German.
  • Nice to have: a degree in risk, compliance, or security management; familiarity with MaRisk, DORA, or outsourcing regulation; exposure to lending, payments, or financial services.

If you have done most of this before, or you have done the diligent version of it in an audit seat and want to move beyond audits into building the function, we want to hear from you. You do not need to tick every box.

What We Offer

πŸ› οΈ Real influence over how we do compliance - our ISO 27001 certification is already underway, you'll have a real say in whether our current compliance tooling is the right setup going forward, not just execute someone else's system.

⏱️ No billable hours, no audit-season crunch - the pace is set by what the business actually needs, not a utilization target or a client-billing calendar.

πŸ’¬ A direct line to a management team that gets compliance - take ownership but benefit from working with a management team that has worked in compliance, not against it.

πŸ• Flexible schedule and location - full-time or part-time, remote within Germany is fine, Berlin is not required.

πŸ’° Competitive compensation - based on experience and responsibility, with VESOP participation.

Similar Jobs

See all Remote Legal jobs β†’

Personalize your Remote Job Search in 3 Easy Steps!

Discover remote opportunities in Legal

Answer easy questions

Answer easy questions

200,000+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified