IT hiring in the financial sector is a craft of its own. You work with sensitive data, strict supervisors and heavy regulation like DORA and NIS2. At the same time, precisely the security expertise you need is extremely scarce. How do you hire the right specialists in that context?
In this article you will learn which requirements the financial sector sets for IT hiring, why security and compliance weigh more heavily here, and how to deal with the scarcity of specialists. That way you hire effectively in a sector where the bar is high.
This blog is for clients in the financial sector: IT managers, security leads and project leaders at banks, insurers, asset managers and fintechs.
I place IT freelancers, including security and cloud specialists, and follow the regulation in the financial sector closely. This is general information; for specific compliance questions around DORA or NIS2, consult a specialist in that area.
What makes IT hiring in the financial sector different?
The combination of sensitive data, strict supervision and heavy regulation. Financial institutions process large amounts of sensitive data, are supervised by parties like De Nederlandsche Bank and the AFM, and must meet strict digital resilience requirements. That sets high demands on who you hire and how.
For your hiring, this means quality, reliability and demonstrable expertise weigh more heavily than in many other sectors. An IT professional must not only be technically strong, but also fit within an environment where security and compliance are decisive. The bar is high, and that calls for targeted hiring.
Which regulation plays a role: DORA and NIS2
Two regulations dominate. DORA, the Digital Operational Resilience Act, has applied to the financial sector since early 2025 and sets strict requirements on ICT risk management, incident reporting, resilience testing and managing risks with IT suppliers. In 2026, institutions must demonstrably comply, supervised by DNB and the AFM.
In addition, NIS2 is coming, in the Netherlands via the Cybersecurity Act, which tightens digital resilience broadly. Both emphasise demonstrable security, chain responsibility and tight processes. The result: financial institutions need a lot of security expertise to comply, precisely at the moment that expertise is scarce.
Why is the right security expertise so scarce?
Because demand for security specialists structurally exceeds supply, and regulation like DORA and NIS2 drives that demand further. Everyone needs security expertise at the same time to become compliant, while the number of experienced specialists is limited. That makes these profiles the scarcest and best-paid in the market.
For you, this means that for security hiring you must count on firm rates and an active search. Waiting for the right specialist to come along does not work in this segment. Want to know which rates are common for security profiles? Read our guide to IT rates for freelancers.
What should you watch for when hiring an IT professional in finance?
Demonstrable expertise, reliability and suitability within a regulated environment. An IT professional in the financial sector must have experience with the requirements that apply here, and you must be able to rely on their quality and integrity. Screening and demonstrable experience weigh more heavily here than in an average assignment.
A few points of attention when hiring in finance:
- Demonstrable experience with security and regulated environments
- Familiarity with requirements around digital resilience and incident reporting
- Reliability and integrity, given the sensitive data
- The ability to run independently quickly in a complex environment
- A good match with your existing security and compliance processes
Because the requirements are high and the specialists scarce, it pays to do the selection carefully or outsource it to a party that can assess and find these profiles. A mismatch is extra costly in this sector, not only financially but also in terms of risk.
How do you combine hiring with the Dutch DBA Act in finance?
As in other sectors, the Dutch DBA Act applies here too: if you hire a self-employed person, the relationship must demonstrably be that of an assignment, not of employment. In the financial sector, with often long-running and intensive security projects, that requires extra attention to definition and independence.
So here too, steer on a defined result and avoid full embedding, even though you collaborate intensively on compliance. For long-running projects, the intermediary construction can be a safe route, where the Dutch DBA Act risk is covered while the specialist stays independent. Want to know how that works? Read our guide to the 9 assessment factors of the Dutch DBA Act.
Frequently asked questions about IT hiring in the financial sector
Which IT profiles are most in demand in finance?
Security specialists foremost, driven by DORA and NIS2, followed by cloud and data experts. The emphasis on digital resilience and risk management makes security expertise the scarcest and most in demand. Profiles with experience in regulated, financial environments are extra sought-after.
What does DORA mean for my IT hiring?
DORA sets strict requirements on digital resilience, incident reporting and managing risks with IT suppliers. That increases your need for security expertise to be compliant, and means your hired specialists must be familiar with these requirements. For the details, consult a DORA specialist.
Are security specialists more expensive than other IT professionals?
Usually yes. Due to the ongoing scarcity and the extra demand from regulation, security specialists are among the best-paid profiles. Count on firm rates and an active search for this expertise. The investment stands against managing a large compliance and security risk.
Can I hire a freelancer in finance despite the strict requirements?
Yes, provided you hire carefully. Hiring a self-employed security or cloud specialist is perfectly possible, as long as the relationship is demonstrably that of an assignment and the specialist meets the requirements. Watch the definition for the Dutch DBA Act and demonstrable expertise and reliability for the sector requirements.
How do I find scarce security expertise in time?
By starting in time and using a network that knows these specialists. Waiting does not work in this scarce segment. A specialised intermediary with access to security profiles can get you the right expertise faster than searching yourself in a tight market.
Conclusion: high requirements call for targeted, careful hiring
IT hiring in the financial sector revolves around security, compliance and dealing with scarcity. Regulation like DORA and NIS2 sets high requirements, precisely on the scarce profiles. The key is targeted and careful hiring: demonstrable expertise, a good match, and attention to the Dutch DBA Act.
For whom is this most relevant? For IT and security managers at financial institutions who must meet strict requirements. For whom less? For sectors with lighter regulation, although good hiring remains important everywhere.
My advice: treat hiring in finance as a careful process, not a quick fill. Start in time, choose on demonstrable expertise and reliability, and cover your Dutch DBA Act risk. That way you bring in the scarce specialists this sector demands.
Looking for scarce security or cloud expertise?
Want to spar about how to find the right, scarce IT specialists for your financial organisation? Plan a no-obligation call with me. I know the market and the scarce profiles, and think along with you.
Note: regulations around DORA, NIS2 and the Cybersecurity Act may change and are still being implemented. For current information, consult rijksoverheid.nl and the supervisors. For specific compliance questions, I advise consulting a specialist in that area.




