Compliance & Certifications Associate (mfd)
Job Summary
Credibur builds the operational backbone for non-bank lending and structured credit in Europe. As we grow so does what our customers bank partners and regulators expect of us. We are looking for someone to take responsibility for compliance and certifications at Credibur and build the function as the company scales.
This role comes with real ownership from day one. You will lead our certification work keep our policies and regulatory obligations in order and become the person the company relies on to stay compliant without slowing down. Done well this means folding legal and certification requirements into how the company actually works not bolting them on from the side and keeping people informed and involved as that happens. That is what makes Credibur more professional efficient and future-proof as we grow. You will work closely with our founder who has held compliance and risk roles before and with our external advisors.
- Certifications. Take responsibility for the internal side of our ISO 27001 certification and from there SOC 2. Coordinate with our external advisors lead the plan inside the company collect and organise evidence and track deliverables to completion.
- Policies and governance. Draft maintain and improve our internal policies so they are clear current and actually used. Keep our governance framework up to date as we grow.
- Regulatory and outsourcing compliance. Manage our outsourcing compliance and make sure regular reporting to our bank partners is accurate and on time. Familiarity with MaRisk or DORA helps here.
- Vendor and third-party risk. Run due diligence on our vendors and maintain the ongoing third-party risk checks.
- Contracts and legal support. Organise and maintain our contracts carry out first-pass reviews and support our legal counsel on day-to-day matters.
- Around two to five years in compliance governance risk or audit whether from an advisory or audit firm or in-house at a fintech or regulated business.
- Hands-on experience with at least one certification ISO 27001 SOC 2 or comparable. You understand what auditors expect and what good evidence looks like.
- A pragmatic risk-based approach. You know when a control is sufficient and you keep compliance proportionate to the business.
- The ability to coordinate across teams and keep deadlines on track.
- Structured and detail-oriented with clear written German and English. Our regulatory and bank-partner work runs in German.
- Nice to have: a degree in risk compliance or security management; familiarity with MaRisk DORA or outsourcing regulation; exposure to lending payments or financial services.
If you have done most of this before or you have done the diligent version of it in an audit seat and want to move beyond audits into building the function we want to hear from you. You do not need to tick every box.
What We Offer
Real influence over how we do compliance - our ISO 27001 certification is already underway youll have a real say in whether our current compliance tooling is the right setup going forward not just execute someone elses system.
No billable hours no audit-season crunch - the pace is set by what the business actually needs not a utilization target or a client-billing calendar.
A direct line to a management team that gets compliance - take ownership but benefit from working with a management team that has worked in compliance not against it.
Flexible schedule and location - full-time or part-time remote within Germany is fine Berlin is not required.
Competitive compensation - based on experience and responsibility with VESOP participation.
About Company
Credibur is building the operating platform for non-bank lending, automating the entire debt facility lifecycle from facility structuring and SPV setup to portfolio reporting, covenant monitoring, drawdowns, and backup servicing. We partner with BNPL providers, factoring companies, SM ... View more