Description
SpaceXAI is seeking an experienced Governance, Risk, and Compliance (GRC) Engineer focused on European Union and United Kingdom information security and financial services regulation.
As we expand deeper into regulated EU/UK markets, maintaining a robust, transparent, and technically sound information security GRC program is critical.
The ideal candidate brings hands-on experience with frameworks such as DORA, the EU AI Act, NIS2, and related EU/UK information security and operational resilience obligations, plus GRC engineering skills: Compliance-as-Code, continuous evidence collection, and deep partnership with engineering.
Responsibilities:
- Own and evolve EU/UK financial services and digital operational resilience posture across DORA
- Build and maintain Compliance-as-Code capabilities
- Operate and extend GRC platforms
- Partner with Architects and Engineering Leads to bake EU/UK information security and regulatory requirements into design
- Design, implement, and validate technical information security controls
- Operate the cybersecurity and compliance risk register
- Lead information security risk assessments and compliance reviews
- Liaise with the Data Privacy team on security-relevant intersections
- Own and cultivate relationships with external auditors, assessors, and supervisory contacts
- Develop, maintain, and continuously improve information security policies, standards, and procedures
- Champion pragmatic governance
Basic Qualifications:
- Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field
- 5+ years of experience in GRC, information security compliance, or technology audit roles
- Hands-on experience implementing or operating controls against several of the following: DORA, the EU AI Act, NIS2, PSD2/PSR, or UK PRA/FCA operational resilience expectations
- Familiar with data privacy regulations applicable to the EU/UK region
- Experience with Compliance-as-Code practices and GRC automation tooling
- Technical fluency sufficient to speak the language of engineering, On-premises, hybrid, or cloud, and security architecture
Preferred Skills and Experience:
- 7+ years of information security compliance, GRC engineering, or technology audit-related experience
- Hands-on experience implementing technical controls and integrating compliance checks into CI/CD pipelines
- Experience supporting ISO 27001 and/or SOC 2 programs
- Familiar with GDPR concepts
- Familiarity with DORA ICT third-party risk, register of information, threat-led penetration testing concepts
- Experience with AI governance under the EU AI Act or related national guidance
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting:
https://job-boards.greenhouse.io/xai/jobs/5209985007