Company
Founded by CPAs, tax attorneys, and engineers, Taxbit is the leading innovator automating global tax reporting for the digital economy. Taxbit's AI-enabled platform streamlines compliance related to digital assets, payments, and other financial transactions. Its unique combination of deep subject matter expertise and AI-forward technology have made it a fast-growing disruptor trusted by the world's leading fintechs, marketplaces, digital asset players, Big 4 accounting firms, traditional enterprises, and government agencies. Backed by top-tier Silicon Valley VCs, Taxbit's team is located across offices in San Francisco, New York, Seattle, Salt Lake City, London, Madrid, and Singapore.
Opportunity for Impact
Taxbit is seeking a Senior Compliance Analyst to be a critical partner in maturing our global compliance and certification programs, with a particular focus on European and international regulatory requirements. This role combines hands-on control ownership with close collaboration across legal, engineering, and customer-facing teams—ideal for someone who thrives at the intersection of compliance, regulation, and real-world impact. You will lead ISO 27001 and ISO 42001 program execution — ISO 42001 being the international standard for AI management systems, governing how organizations responsibly develop, deploy, and manage AI throughout its lifecycle — monitor and translate evolving European regulatory obligations — including GDPR, DORA, NIS 2.0, and the EU AI Act — into actionable controls, and act as a trusted advisor to stakeholders navigating audits, vendor risk, AI governance, and customer due diligence.
We welcome individuals who are humble, hungry, and excited to tackle some of the industry’s biggest challenges at the intersection of compliance and regulation!
This role is based in Madrid. Candidates must be legally authorized to work in Spain or another European Union country without company-sponsored visa support (e.g., holders of a valid Residency and Work Visa or Permanent Resident status).
Role and Responsibilities
Compliance Program Management
- Own day-to-day execution of Taxbit’s ISO 27001 and ISO 42001 compliance programs, including evidence collection, control testing, and audit coordination.
- Serve as a primary point of contact for third-party auditors and European regulators, managing audit timelines, requests, and remediation tracking.
- Build and maintain policies, procedures, and control documentation that align to applicable European and global frameworks and regulatory requirements.
- Identify gaps in the current compliance and control environment and collaborate with stakeholders to drive remediation.
- Support continuous monitoring and automation of compliance evidence collection across GRC and security tooling.
- Conduct third-party risk assessments (TPRAs) for new and existing vendors, evaluating security, privacy, cross-border data transfer, and AI governance posture.
- Draft and maintain responses to customer security questionnaires and due diligence requests, including those focused on EU/international regulatory obligations.
European Regulatory Strategy & Enablement
- Lead Taxbit’s compliance efforts against European and international regulatory frameworks, including GDPR, DORA, NIS 2.0, and the EU AI Act, translating requirements into actionable controls and program requirements.
- Monitor the evolving European and international regulatory landscape and advise stakeholders on the impact of new or amended requirements to Taxbit’s products and operations.
- Serve as the voice of European compliance across engineering, legal, and sales, translating regulatory risk into actionable work.
- Educate and mentor colleagues on GDPR, DORA, NIS 2.0, EU AI Act, and other European regulatory requirements.
- Help shape the compliance roadmap as Taxbit expands its footprint in European and other international markets.
Professional Qualifications
- Fluent in English; native fluency in a main European language; preferred business-level proficiency in 1-2 additional languages.
- Proven track record of identifying opportunities to build, test, and scale AI-powered solutions.
- Sees AI as a force multiplier and actively looks for ways to enhance team performance through innovation & curiosity.
- 5+ years of experience in compliance, information security, audit, or risk management.
- 3+ years of hands-on experience supporting ISO 27001 and ISO 42001 audits and certification maintenance.
- Working knowledge of European and international regulatory requirements, including GDPR, DORA, and/or NIS 2.0.
- Working knowledge of the EU AI Act, including its risk-tiering approach and obligations for providers and deployers of AI systems.
- Understanding of AI agentic workflows (e.g., multi-step autonomous or semi-autonomous AI agents) and their associated risk, control, and governance considerations.
- Experience conducting or supporting third-party/vendor risk assessments.
- Strong analytical and problem-solving skills.
- Ability to work autonomously in a fast-paced, distributed environment with minimal supervision.
- Comfortable working independently across time zones, with the majority of the team based in the United States.
- Bachelor’s degree in a technical, business, or related field (Information Systems, Cybersecurity, Accounting, or other related field).
Technical Qualifications
- Experience with GRC or compliance automation platforms.
- Knowledge of common compliance and security frameworks: ISO 27001, ISO 42001, NIST CSF, and/or SOC 2.
- Strong written communication skills, with experience drafting policies, procedures, and questionnaire responses.
- Experience with AI governance frameworks, such as the NIST AI Risk Management Framework (AI RMF).
Nice to Have
- Working knowledge of a scripting language (e.g., Python) for compliance automation.
- Experience in a fintech, digital assets, or highly regulated industry operating across EU/international markets.
Personal Characteristics
- Passionate about building strong compliance programs and solving complex regulatory problems.
- Strong sense of ownership and accountability.
- Comfortable collaborating across teams.
- Thrives in an agile, fast-paced environment.
- Enjoys mentoring others.
Taxbit in the News
- Bybit Collaborates with Taxbit to Ensure Seamless Financial Compliance for Global and EU Users
- Taxbit Expands Global Platform to Power CARF/DAC8 Compliance at Scale
- Taxbit Unveils Industry-First Global Reporting Platform, Bridging Digital and Traditional Finance
- Taxbit Wins the Digital Banker’s 2025 Digital Assets Award for Best Technology Solution Provider for Digital Assets - Tax & Compliance Automation
- Taxbit Named to 2024 Deloitte Technology Fast 500™ List of Fastest-Growing Companies in North America
- Taxbit Appoints Former OECD Advisor Colby Mangels as Global Head of Government Solutions
- Unlocking Compliance at Scale: CARF/DAC8 Reporting for Digital Asset Platforms
Disclaimers
- By submitting an application for this role, you certify that the information contained in the application is correct to the best of your knowledge. You understand that to falsify information is grounds for refusing to hire you, or for discharge should you be hired.
- For US roles, employment with the Company is at will unless otherwise stated in a written agreement signed by the CEO of the Company. This means that either the Company or the employee can terminate the employment at any time and for any reason, with or without notice.