SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. The role seeks an experienced Governance, Risk, and Compliance (GRC) Engineer focused on European Union and United Kingdom information security and financial services regulation to help scale compliance for SpaceXAI and xMoney. The engineer will architect systems and processes that automate trust, balancing rigorous standards with the velocity of a high‑growth company, and work closely with engineering teams to embed compliance into the platform.
Sr. Security Engineer - GRC EU/UK Regulation & Data Protection na xAI
London, England, United Kingdom
Ver mais vagas na xAIRequirements
Skills
- Bachelor's degree in computer science, Information Security, Cybersecurity, or an engineering/STEM field
- 5+ years of experience in GRC, information security compliance, or technology audit roles in fintech, banking, payments, or other heavily regulated environments with EU and/or UK exposure
- Hands‑on experience implementing or operating controls against DORA, the EU AI Act, NIS2, PSD2/PSR, or UK PRA/FCA operational resilience expectations
- Familiar with data privacy regulations applicable to the EU/UK region (e.g., EU GDPR, UK GDPR, UK Data Protection Act 2018)
- Experience with Compliance‑as‑Code practices and GRC automation tooling (e.g., Vanta or similar)
- Technical fluency to speak the language of engineering, On‑premises, hybrid, or cloud (AWS/GCP/Azure), and security architecture
Responsibilities
- Own and evolve EU/UK financial services and digital operational resilience posture across DORA, EBA/ESMA/EIOPA guidance, PSD2/PSR, UK PRA/FCA operational resilience requirements
- Build and maintain Compliance‑as‑Code capabilities – policy‑as‑code, automated control validation, continuous evidence collection, and monitoring integrated into CI/CD
- Operate and extend GRC platforms (e.g., Vanta) as the backbone for control mapping, evidence management, and continuous compliance; integrate with cloud, identity, logging, and engineering systems
- Partner with Architects and Engineering Leads to bake EU/UK information security and regulatory requirements into design early
- Design, implement, and validate technical information security controls relevant to regulated EU/UK environments (access control, logging and monitoring, encryption, change management, vulnerability management, ICT third‑party oversight, secure SDLC)
- Operate the cybersecurity and compliance risk register – identify, quantify, and track risks
- Lead information security risk assessments and compliance reviews for new products, features, vendors, and architectural changes affecting the EU/UK regulated attack surface
- Liaise with the Data Privacy team on security‑relevant intersections
- Own and cultivate relationships with external auditors, assessors, and supervisory contacts on information security topics
- Develop, maintain, and continuously improve information security policies, standards, and procedures aligned to DORA, the EU AI Act, NIS2, ISO 27001, SOC 2
- Champion pragmatic governance – prioritize issues that represent real security or business risk over checkbox compliance
Technologies
DORAEU AI ActNIS2PSD2/PSRUK PRA/FCAVantaAWSGCPAzureIAMloggingmonitoringencryptionnetwork segmentationinfrastructure hardeningCI/CD pipelinesISO 27001SOC 2
Descubra se seu currículo está pronto para esta vaga
Veja como nossa IA pode otimizar seu currículo e aumentar suas chances de conseguir esta posição.