Group Compliance Manager

Il y a 2 jours

Brussel Hoofdstad, Brussel Hoofdstad, Belgique Dstny Temps plein 70 000 € - 90 000 € Contrat

For our Group Legal & Compliance department, we are looking for a Group Compliance Manager to support the business in navigating complex regulatory frameworks with a focus on Artificial Intelligence and a broader remit across key EU digital, information security, privacy, data and sustainability regulations.

You will play a critical role in strengthening Dstny’s global compliance maturity, supporting its transition towards more complex customers and services, and ensuring readiness across a growing set of regulatory obligations identified in our Group Risk & Compliance (GRC) roadmap.

1. AI product compliance & governance

  • Lead the implementation of the EU AI Act, identified as a top-priority regulatory topic for Dstny
  • Translate AI regulatory requirements into practical governance frameworks, risk assessments and product requirements
  • Develop and manage:
  • AI product compliance documentation and audit readiness
  • Vendor and subcontractor product compliance frameworks
  • Support contractual negotiations involving AI-specific terms and annexes
  • Ensure alignment between AI product compliance, product development and vendor ecosystem constraints

2. Information security & resilience regulatory framework

  • Coordinate compliance efforts across key information security regulations and standards, including:
  • EU NIS2 Directive
  • EU DORA Regulation
  • EU Cyber Resilience Act
  • EU Cybersecurity Act
  • National laws & regulations such as Germany’s BSIG / BSI-KritisV, UK’s Telecommunications Security Act and California’s CCPA where applicable
  • Support certification and assurance programmes such as:
  • ISO 9001 / ISO 27001 / ISO 27701 / ISAE3000 / SOC2 / BSI C5 / HDS / NEN7510
  • Lead or support compliance initiatives related to:
  • EU Data Act & Data Governance Act
  • EU Digital Services Act
  • EU e-Evidence Regulation (cross-border data access obligations)
  • Support the definition of:
  • Data-sharing frameworks
  • Platform governance and transparency obligations

4. Accessibility, sustainability & ESG regulatory framework

  • Support compliance and reporting initiatives for:
  • EU Accessibility Act
  • EU CSRD
  • EU CSDDD
  • Broader ESG and sustainability frameworks (including SBTi)
  • Work with finance, legal and business teams to:
  • Implement ESG data collection and reporting processes
  • Support due diligence on supply chains and human rights impacts
  • Build and scale a group-wide compliance operating model, aligned with Dstny’s GRC priorities
  • Transition from a reactive (product) compliance approach to a structured, scalable framework, where compliance is embedded in the product lifecycle
  • Improve, develop and implement policies:
  • Create risk registers and prioritisation frameworks based on regulatory weight and maturity gaps
  • Develop internal training & awareness programmes
  • Set up and maintain a central compliance knowledge base

7. Business partnership & strategic enablement

Act as a trusted advisor to product, engineering and business teams

Support:

  • Customer negotiations and tenders (particularly enterprise and service provider clients)
  • Product roadmap decisions where compliance impacts go‑to‑market strategy
  • Contribute to strategic discussions on AI and digital product offerings, ensuring regulatory readiness
  • Coordinate compliance obligations across subcontractors and vendors, including:
  • Cascading regulatory requirements (AI, security, data, ESG)
  • Contractual protections and audit rights
  • Support procurement in managing third‑party compliance risks across all relevant frameworks

Work closely with:

  • Group Compliance Officer
  • Group Information Security Officer
  • Data Protection Officer
  • Local Compliance Ambassadors
  • Product, engineering, and procurement teams
  • External advisors
  • Represent Dstny in discussions with customers, regulators, authorities and partners on compliance matters

Qualifications

  • 5+ years of experience in regulatory, compliance, technology law, information security or risk management;
  • Working knowledge of the following regulations is a plus:
  • AI Act, NIS2, DORA and related frameworks
  • Broader EU digital and ESG regulatory landscape
  • Experience in SaaS or technology environments is strongly preferred;
  • Ability to operate in a multi‑jurisdictional and fast‑evolving regulatory environment;
  • Strong stakeholder management and communication skills;
  • Pragmatic, structured and hands‑on approach;
  • Fluent in En