Want to know if this job is worth applying to?
France
Remote only
Founded in 2022, Filigran is a global cybersecurity company on a mission to empower defense teams to be proactive through open-source solutions that uncover threats and drive action.
Filigran stands out in the cybersecurity ecosystem through its open-source, AI-powered and threat-informed approach to Continuous Threat Exposure Management (CTEM). Our eXtended Threat Management (XTM) platform brings together threat intelligence, exposure validation and cyber risk reduction, enabling organizations to better understand their threat landscape and take action.
At the heart of Filigran is our open-source approach. Our vision is to unite defenders into a global community to make security more open, resilient and collaborative.
As Filigran continues to scale globally, we are building the organization, infrastructure and capabilities needed for our next stage of growth. How we scale matters just as much as how fast we scale: our CORE values: Cohesion, Openness, Responsibility and Equity shape how we work together, make decisions and build for the future.
We’re looking for a DPO & Compliance Officer to design and implement Filigran’s practical, scalable compliance program.
You will be Filigran’s formal Data Protection Officer, ensuring strong privacy governance across our products, operations and international footprint. You will also lead the day-to-day design and delivery of broader compliance workstreams, including AI governance, cybersecurity regulation, operational resilience, export controls and sanctions.
You will work closely with the General Counsel, CEO, CISO, People, Product, Engineering and Sales teams, helping Filigran meet regulatory expectations in a business-minded attitude.
Act as Filigran’s Data Protection Officer and primary point of contact for supervisory authorities, including the CNIL, and for data subjects.
Design and operate Filigran’s privacy program, including ROPAs, DPIAs, privacy by design, retention, data-subject rights, breach assessment and international data transfers.
Lead the design and operational implementation of compliance controls across AI governance, NIS2, operational resilience, export controls and economic sanctions, under the General Counsel’s leadership.
Maintain a proportionate compliance framework, including policies, risk mapping, monitoring plans, internal controls and clear reporting.
Partner with Security to translate regulatory requirements into practical, business-enabling policies and controls that work for a fast-growing cybersecurity company.
Partner with Security, Product and Engineering to embed privacy, AI and regulatory requirements into product development, vendor management and customer assurance.
Monitor regulatory developments across the EU, UK, US and other relevant markets, and provide clear recommendations to the General Counsel and executive team.
Support enterprise sales and procurement by responding to privacy, AI governance and compliance requirements.
Leverage AI tools and methodologies to boost productivity and impact
Contribute to building AI capabilities into internal workflows
You will have a split reporting line:
For your statutory DPO responsibilities, you will report directly to the CEO. You will have the independence and access to senior management required to carry out those responsibilities.
For all other compliance responsibilities, you will report to the General Counsel, who retains ultimate accountability for Filigran’s wider compliance programme and material compliance decisions.
You will work closely with the General Counsel, CISO, Security, Product, Engineering, Sales, People and Finance teams. You will lead delivery across the programme while knowing when to escalate decisions and draw on internal or external specialists.
7 to 10 years’ experience as a DPO, data privacy lead or compliance officer, ideally in a fast-growing technology or SaaS company.
Demonstrable expert knowledge of data protection law and practice. A recognized DPO certification or IAPP qualification, such as CIPP/E, is strongly preferred.
Experience with a company-wide implementation of the EU AI Act.
Deep, hands-on command of GDPR and UK GDPR, including ROPAs, DPIAs, breach management, data-subject rights and international transfers.
Demonstrable ownership of at least two adjacent regulatory programmes, such as AI governance, cybersecurity regulation, operational resilience, export controls or economic sanctions.
Able to lead unfamiliar workstreams with sound judgement and appropriate specialist internal or external support.
Comfortable translating complex legal and regulatory requirements into proportionate controls that work operationally.
Able to build strong relationships and credibility with technical, commercial and executive stakeholders.
Comfortable working in a remote, async-first environment.
Autonomy, ownership and team spirit.
Strong interest in AI and its applications in the privacy & compliance function
Comfortable working with and leveraging AI-powered tools (LLMs, automation, copilots, etc.) to improve workflows and productivity
Bonus: experience in cybersecurity, threat intelligence or a technical B2B SaaS environment; fluency in English and French.
We are a fast-growing, global and remote-first company, and we believe the best work combines purpose, impact and innovation. You’ll work alongside talented people across the world who care about what they build, how they build it, and the impact they make on the broader cybersecurity ecosystem.
⭐ Be part of something bigger
We believe we do work that matters. Our open-source approach means that work extends beyond Filigran. You’re contributing to technology and ideas that strengthen a global community of defenders and help make cybersecurity more open and collaborative.
💻 Work at the edge of what’s next
We bring together cybersecurity, open source and AI — giving you the opportunity to work with emerging technologies, experiment with new ways of working, and contribute to how they are applied in practice.
🌍 Global opportunity without borders
Be part of a fast-growing, truly international team — collaborating across Europe, North America, APJ and beyond, with the flexibility of a remote-first environment. As we grow, you’ll have opportunities to expand your scope, take ownership, learn quickly and grow with us.
🧭 A culture grounded in CORE
Cohesion, Openness, Responsibility and Equity define how we work together — with openness, ownership, collaboration and respect. These are the principles that guide how we make decisions, treat people and grow together, especially when no one’s watching.
Competitive compensation + equity — everyone shares in our success
Remote-first flexibility — work from wherever you’re based, with flexibility built into how we operate
25 days PTO baseline — real time to disconnect, recharge and enjoy life outside work
Volunteer days — paid time to contribute to causes that matter to you
Set up for success — choose the equipment that works for you, with additional support for your remote work and development needs as our programs evolve
Two annual in-person get-togethers — one global company get-together and one team get-together, creating dedicated time to connect, collaborate and strengthen our culture beyond the screen
We enable cybersecurity through inclusion — from code to culture.
At Filigran, we are proud to be an equal opportunity employer. We believe the diversity of our people makes our products and our team stronger. We welcome talent of every background, identity and lived experience, regardless of race, color, religion, gender, gender identity or expression, sexual orientation, national origin, age, disability or veteran status.
What matters here is what you bring, not what you look like, where you’re from or how you identify.
Apply now and help us build the future of the cybersecurity ecosystem, together.



