New The Skills of Tomorrow: how AI-exposed is every skill in 2026? See the data →
SpaceXAI

Sr. Security Engineer - GRC EU/UK Regulation & Data Protection

SpaceXAI
Apply →
senior full-time London, England

First indexed 12 Aug 2026

Description

SpaceXAI is seeking an experienced Governance, Risk, and Compliance (GRC) Engineer focused on European Union and United Kingdom information security and financial services regulation to help scale compliance for SpaceXAI and xMoney.

As we expand deeper into regulated EU/UK markets, maintaining a robust, transparent, and technically sound information security GRC program is critical. You will architect the systems and processes that automate trust , a pragmatic operator who understands that GRC exists to enable the business, balancing rigorous standards with the velocity of a high-growth company.

Responsibilities:

  • Own and evolve EU/UK financial services and digital operational resilience posture across DORA, and complementary expectations from EBA/ESMA/EIOPA guidance, PSD2/PSR where applicable, and UK PRA/FCA operational resilience requirements supporting xMoney.
  • Build and maintain Compliance-as-Code capabilities , policy-as-code, automated control validation, continuous evidence collection, and monitoring integrated into CI/CD.
  • Operate and extend GRC platforms (e.g., Vanta) as the backbone for control mapping, evidence management, and continuous compliance.
  • Partner with Architects and Engineering Leads to bake EU/UK information security and regulatory requirements into design early.
  • Design, implement, and validate technical information security controls relevant to regulated EU/UK environments.
  • Operate the cybersecurity and compliance risk register , identify, quantify, and track risks.
  • Lead information security risk assessments and compliance reviews for new products, features, vendors, and architectural changes.
  • Liaise with the Data Privacy team on security-relevant intersections.
  • Own and cultivate relationships with external auditors, assessors, and supervisory contacts on information security topics.
  • Develop, maintain, and continuously improve information security policies, standards, and procedures aligned to DORA, the EU AI Act, NIS2, and complementary frameworks.
  • Champion pragmatic governance , prioritize issues that represent real security or business risk over checkbox compliance.

Basic Qualifications:

  • Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field.
  • 5+ years of experience in GRC, information security compliance, or technology audit roles in fintech, banking, payments, or other heavily regulated environments with EU and/or UK exposure.
  • Hands-on experience implementing or operating controls against several of the following: DORA, the EU AI Act, NIS2, PSD2/PSR, or UK PRA/FCA operational resilience expectations.
  • Familiar with data privacy regulations applicable to the EU/UK region (e.g., EU GDPR, UK GDPR, UK Data Protection Act 2018).
  • Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, or similar).
  • Technical fluency sufficient to speak the language of engineering, On-premises, hybrid, or cloud (AWS/GCP/Azure), and security architecture.

Preferred Skills and Experience:

  • 7+ years of information security compliance, GRC engineering, or technology audit-related experience in fintech or financial services with a primary EU/UK focus.
  • Hands-on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, network segmentation, infrastructure hardening).
  • Experience supporting ISO 27001 and/or SOC 2 programs alongside EU/UK regulatory obligations.
  • Familiar with GDPR concepts that commonly intersect with information security.
  • Familiarity with DORA ICT third-party risk, register of information, threat-led penetration testing (TLPT) concepts, and major ICT-related incident reporting expectations.
  • Experience with AI governance under the EU AI Act or related national guidance.
  • Exceptional analytical, problem-solving, organizational, and project management skills.
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting: https://job-boards.greenhouse.io/xai/jobs/5209985007