Full Time
6-8 Euros per hour
40
Oct 2, 2026
About MSTR
MSTR (
We are 20+ people, with a customer-facing team in the Netherlands and a remote development team in the Philippines. Our clients include municipalities, accountants, law firms and enterprise clients. They need to know their data is safe and that our products meet European rules, so we are hiring someone whose full focus is compliance.
This is a long-term career opportunity
We are looking for someone who wants to build a long-term career with us, not find their next gig. We invest in our people's growth and increase responsibility as you develop.
Location and type
- Remote
- Full-time, 40 hours per week, 14:00 to 23:00 Philippine time (overlapping with Netherlands business hours)
- Long-term contractor position
What you will do
You make sure every product we ship is compliant and properly documented. You report to our Head of Operations and work closely with our Head of Technology and Head of Product.
- Compliance documentation: keep it current for every product and client project, including data flows, processing records, security measures and risk assessments
- Client agreements: prepare data processing agreements and answer client security questionnaires
- Regulation checks: check products against GDPR and the EU AI Act, and flag gaps early to the product owner
- Internal policies: maintain our policies on data retention, access management and i
- AI model register: track which AI models and hosting locations each product uses, so we can answer client questions fast
- Audits: support audits and certification work, such as ISO 27001
What we are looking for
Must-have:
- 2+ years of experience in compliance, data privacy, IT audit or information security
- Working knowledge of GDPR, and interest in the EU AI Act
- A precise, structured way of working
- Excellent English communication, especially written
- Comfortable asking developers the right questions and turning technical answers into clear documentation
Nice-to-have:
- A certification such as CIPP/E, CIPM, ISO 27001 Lead Implementer or similar
- Experience at a software or SaaS company
- Familiarity with cloud platforms (Azure, AWS) and how AI models are hosted
- Experience working with European clients
- Experience using AI tools like Claude or ChatGPT in your work
AI tools are welcome. We are an AI company. If you use Claude, ChatGPT or similar tools to draft policies, compare regulations or prepare questionnaire answers, tell us how. We would rather hire someone who uses AI well than someone who avoids it.
What we offer
- Long-term partnership: we are investing in your future with us
- Build something from scratch: you set up the compliance function, with direct access to the leadership team
- Real questions: work where AI, privacy and regulation meet
- A clear growth path: a buddy, monthly check-ins and room to grow the compliance function
- Continuous learning: work at an Anthropic partner, with Claude as part of your daily work
- Flexible remote work
- A team that moves fast and takes quality seriously
How to apply
IMPORTANT: We assess candidates primarily through video responses. Please do not apply without submitting a video.
Step 1: Create a short video (3 to 7 minutes)
Record yourself answering these 5 questions:
1. Tell us about yourself: Briefly introduce yourself and how you got into compliance or data privacy.
2. A process you set up: Walk us through a compliance or privacy process you documented or set up. What was missing when you started, and what did you put in place?
3. A gap you found: Tell us about a compliance or security gap you found. How did you raise it, and what happened next?
4. AI in your work: How do you use AI tools in your work today? Where would you not trust AI with compliance work?
5. Your next role: What would you like to achieve in your next role? Where do you see yourself in 5 to 10 years?
Video guidelines:
- Length: 3 to 7 minutes in total
- Production: no need for professional quality, we want to see the real you
- Authenticity: it's fine to use AI to prepare, but talk to us in your own words. Please don't read from a script.
- Language: English (this assesses your communication skills)
- Format: any video format is fine (MP4, MOV, etc.)
- Hosting: upload to Google Drive, Dropbox, YouTube (unlisted) or similar
Step 2: Submit your application
Send the following to
1. Your video (link or attachment)
2. Your CV / resume
3. Optional: certifications, LinkedIn profile, or examples of policies or documentation you wrote (anonymized)
Email
What happens next
1. We review your video and CV within 2 to 3 days
2. If you are a strong match, we schedule an initial interview
3. Successful candidates get a short practical assignment
4. Final candidates meet with our founder
5. We aim to complete the entire process in 1 to 2 weeks
Who should apply
Apply if you:
- Want a long-term career in a high-performance organization
- Like bringing structure where there is none yet
- Speak up early when something is at risk
- Are curious about AI and how regulation shapes it
Don't apply if you:
- Only want short-term gigs or are juggling multiple clients
- Aren't willing to create a video response
- Have no hands-on experience with GDPR or information security
Ready to apply? Send your video and CV to
We look forward to learning more about you.
MSTR,