Compliance Engineer
Listed on 2026-07-21
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Compliance Engineer
Youtrust is a European Digital Trust provider, fully compliant with eIDAS and the highest European standards. Our four modules – electronic signatures, identity and document verification, and e-seals – can be used independently or combined within sector-specific workflows, ensuring simple, secure and legally compliant processes for SMEs and mid-sized companies. Hosted and processed entirely in Europe, we guarantee sovereignty, transparency and reliability.
As a certified B-Corp, we combine innovation with responsibility – building trust at the heart of every digital exchange. We are entering a key moment as we expand from eSignature to the full Digital Trust chain.
As Compliance Engineer at Youtrust, you lead the company's compliance programs end-to-end. You own gap analyses, remediation roadmaps, and certification processes for eIDAS v2, NIS2, and ISO 27001 — and serve as the primary interface with external auditors and certification bodies, including ANSSI and LSTI.
This is not a consultant role. On selected topics arising from audits and gap analyses, you will implement the remediation directly — from design through to delivery. You bring the structure and rigour needed to keep Youtrust ahead of its regulatory obligations while remaining pragmatic about business constraints.
You also step into the topics that make Youtrust a Digital Trust provider: the security of our Trusted Zone, our fraud detection and prevention efforts, and our broader security posture. You won't own every one of these, but you contribute wherever the team needs you — your specialization defines where you spend most of your time, not a silo you stay inside.
YourResponsibilities
- Own the full compliance lifecycle for eIDAS v2: gap analysis, remediation roadmap, implementation tracking, and certification preparation.
- Map NIS2 obligations to Youtrust's perimeter, define the compliance scope, and drive the remediation and reporting cycle.
- Maintain and evolve Youtrust's ISO 27001 program: continuous improvement cycle, internal audit coordination, and ISMS documentation.
- Serve as the primary point of contact with external auditors, ANSSI, and LSTI: prepare audit packages, manage interactions, and own the certification timeline.
- Monitor the European regulatory landscape (ETSI, eIDAS, NIS, PCI DSS, and related standards), assess impact on Youtrust, and translate new requirements into actionable compliance initiatives.
- Contribute to the security of the Trusted Zone, and to fraud detection and prevention, alongside the Security & Compliance team.
- Take part in the team's weekly on-call ("doctor") rotation, and build automation (n8n, AI tooling, alerting) to reduce manual toil.
- You have deep, hands-on experience with at least one technically demanding compliance standard — eIDAS v2, ETSI EN 319 series, PCI DSS, or equivalent. You have run gap analyses independently, built remediation plans, and implemented them directly on selected items. You know the difference between advising on compliance and actually delivering it.
- You are experienced running internal audits and gap analyses end-to-end. You produce structured remediation backlogs, track progress rigorously, and prepare audit packages that hold up to external scrutiny.
- You have managed or actively participated in a live ISO 27001 program. Experience in ANSSI-qualified or LSTI-accredited environments is a strong plus.
- You are familiar with the NIS2 directive and able to anticipate its implications for a SaaS company. You can scope the obligations, map them to the business, and build a readiness roadmap.
- You can represent Youtrust confidently in front of external auditors, ANSSI, and LSTI. You are equally at ease translating complex regulatory requirements into clear, actionable language for engineering and product teams.
- You are comfortable working across domains. Your core is compliance, but you are happy to contribute to security operations, fraud detection, and the security of a Trusted Zone. Prior exposure to a regulated or Digital Trust environment is a strong plus.
- You are self-sufficient and manage multiple long-cycle compliance programs in parallel…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).