Description
SpaceXAI is looking for a Security Engineer to own and evolve financial services and payments compliance posture across PCI DSS, NYDFS, FFIEC guidance, and related banking/fintech regulatory expectations.
Responsibilities:
- Own and evolve financial services and payments compliance posture across PCI DSS, NYDFS (including 23 NYCRR 500), FFIEC guidance, and related banking/fintech regulatory expectations supporting xMoney across relevant jurisdictions.
- Build and maintain Compliance-as-Code capabilities , policy-as-code, automated control validation, continuous evidence collection, and monitoring integrated into CI/CD.
- Operate and extend GRC platforms (e.g., Vanta) as the backbone for control mapping, evidence management, and continuous compliance.
- Partner with Architects and Engineering Leads to bake compliance and privacy requirements.
- Design, implement, and validate technical controls relevant to fintech environments.
- Operate the cybersecurity and compliance risk register , identify, quantify, and track risks.
- Lead risk assessments and compliance reviews for new products, payment flows, features, vendors, and architectural changes.
- Own and cultivate relationships with external auditors, assessors, and regulators.
- Develop, maintain, and continuously improve policies, standards, and procedures aligned to PCI, NYDFS, FFIEC, privacy laws, and complementary frameworks.
- Champion pragmatic governance , prioritize issues that represent real security or business risk over checkbox compliance.
Basic Qualifications:
- Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field.
- 8+ years of experience in GRC, security compliance, or technology audit roles in fintech, banking, payments, or other heavily regulated financial environments.
- Hands-on experience with PCI DSS and at least one of NYDFS (23 NYCRR 500) or FFIEC cybersecurity/IT examination guidance.
- Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, or similar).
- Technical fluency sufficient to speak the language of engineering, cloud (AWS/GCP/Azure), and security architecture.
Preferred Skills and Experience:
- 10+ years of security compliance, GRC engineering, or technology audit-related experience in fintech or financial services.
- Hands-on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, network segmentation, infrastructure hardening).
- Experience supporting SOC 2 and/or ISO 27001 programs alongside fintech-specific obligations.
- Experience with payment ecosystems, cardholder data environments, tokenization, or similar PCI-scoped architectures.
- Familiarity with additional financial regulatory regimes (e.g., GLBA, BSA/AML technology controls).
- Experience enabling enterprise sales through trust centers, vendor questionnaires, and customer security reviews.
- Proven ability to operate a risk register and apply judgment in gray areas.
- Exceptional analytical, problem-solving, organizational, and project management skills.
- Excellent communication and stakeholder management skills.
- Certifications such as CISSP, CISA, CISM, CRISC, PCIP, CIPP/US, CIPP/E, or similar.
- Experience with emerging AI-related financial services expectations or securing AI features in a regulated fintech product.
Compensation and Benefits:
$152,000 - $228,000 USD
Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks.
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting:
https://job-boards.greenhouse.io/xai/jobs/5198194007