# Security Engineer - GRC Fintech & Financial Services

**Company**: SpaceXAI
**Location**: New York, NY
**Work arrangement**: hybrid
**Experience**: senior
**Job type**: full-time
**Salary**: $152,000 - $228,000 USD
**Category**: IT
**Industry**: Finance

**Apply**: https://job-boards.greenhouse.io/xai/jobs/5198194007?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_7ec43f7e-30a

## Description

SpaceXAI is looking for a Security Engineer to own and evolve financial services and payments compliance posture across PCI DSS, NYDFS, FFIEC guidance, and related banking/fintech regulatory expectations.

## Responsibilities:

- Own and evolve financial services and payments compliance posture across PCI DSS, NYDFS (including 23 NYCRR 500), FFIEC guidance, and related banking/fintech regulatory expectations supporting xMoney across relevant jurisdictions.

- Build and maintain Compliance-as-Code capabilities , policy-as-code, automated control validation, continuous evidence collection, and monitoring integrated into CI/CD.

- Operate and extend GRC platforms (e.g., Vanta) as the backbone for control mapping, evidence management, and continuous compliance.

- Partner with Architects and Engineering Leads to bake compliance and privacy requirements.

- Design, implement, and validate technical controls relevant to fintech environments.

- Operate the cybersecurity and compliance risk register , identify, quantify, and track risks.

- Lead risk assessments and compliance reviews for new products, payment flows, features, vendors, and architectural changes.

- Own and cultivate relationships with external auditors, assessors, and regulators.

- Develop, maintain, and continuously improve policies, standards, and procedures aligned to PCI, NYDFS, FFIEC, privacy laws, and complementary frameworks.

- Champion pragmatic governance , prioritize issues that represent real security or business risk over checkbox compliance.

## Basic Qualifications:

- Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field.

- 8+ years of experience in GRC, security compliance, or technology audit roles in fintech, banking, payments, or other heavily regulated financial environments.

- Hands-on experience with PCI DSS and at least one of NYDFS (23 NYCRR 500) or FFIEC cybersecurity/IT examination guidance.

- Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, or similar).

- Technical fluency sufficient to speak the language of engineering, cloud (AWS/GCP/Azure), and security architecture.

## Preferred Skills and Experience:

- 10+ years of security compliance, GRC engineering, or technology audit-related experience in fintech or financial services.

- Hands-on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, network segmentation, infrastructure hardening).

- Experience supporting SOC 2 and/or ISO 27001 programs alongside fintech-specific obligations.

- Experience with payment ecosystems, cardholder data environments, tokenization, or similar PCI-scoped architectures.

- Familiarity with additional financial regulatory regimes (e.g., GLBA, BSA/AML technology controls).

- Experience enabling enterprise sales through trust centers, vendor questionnaires, and customer security reviews.

- Proven ability to operate a risk register and apply judgment in gray areas.

- Exceptional analytical, problem-solving, organizational, and project management skills.

- Excellent communication and stakeholder management skills.

- Certifications such as CISSP, CISA, CISM, CRISC, PCIP, CIPP/US, CIPP/E, or similar.

- Experience with emerging AI-related financial services expectations or securing AI features in a regulated fintech product.

## Compensation and Benefits:

$152,000 - $228,000 USD

Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks.

## Skills

### Required
- PCI DSS
- NYDFS
- FFIEC
- Compliance-as-Code
- GRC automation
- Vanta
- cloud security
- security architecture

### Nice to have
- SOC 2
- ISO 27001
- payment ecosystems
- cardholder data environments
- tokenization
- GLBA
- BSA/AML
- CISSP
- CISA
- CISM
- CRISC
- PCIP
- CIPP/US
- CIPP/E

---

Source: [Apply at job-boards.greenhouse.io](https://job-boards.greenhouse.io/xai/jobs/5198194007?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
