Sr. Security Engineer - GRC Fintech & Financial Services

USD 152,000-258,000 per year
SENIOR
✅ On-site

Tech Stack

AI @ 1 AML @ 3 AWS @ 6 Audit @ 7 Azure @ 6 CCPA @ 4 CI/CD @ 4 Change Management Communication @ 7 Compliance @ 4 FinTech @ 4 GCP @ 6 GDPR @ 4 Payments @ 7 Project Management @ 7 Security @ 7

Details

SpaceXAI is seeking an experienced Governance, Risk, and Compliance (GRC) Engineer focused on fintech and financial services regulation to help scale compliance for SpaceXAI and xMoney. The role will architect systems and processes that automate trust while balancing rigorous standards with the velocity of a high-growth company.

Responsibilities

  • Own and evolve financial services and payments compliance across PCI DSS, NYDFS, including 23 NYCRR 500, FFIEC guidance, and related banking and fintech regulatory expectations supporting xMoney across relevant jurisdictions.
  • Build and maintain Compliance-as-Code capabilities, including policy-as-code, automated control validation, continuous evidence collection, and monitoring integrated into CI/CD.
  • Operate and extend GRC platforms such as Vanta for control mapping, evidence management, and continuous compliance.
  • Integrate GRC platforms with cloud, identity, logging, and engineering systems to reduce administrative bottlenecks.
  • Partner with architects and engineering leads to incorporate compliance and privacy requirements into platform design and translate regulatory obligations into technical implementations and auditor-ready narratives.
  • Design, implement, and validate technical controls for fintech environments, including cardholder data environment scoping and segmentation, access control, logging, encryption, change management, and vulnerability management.
  • Operate the cybersecurity and compliance risk register by identifying, quantifying, and tracking risks.
  • Lead risk assessments and compliance reviews for new products, payment flows, features, vendors, and architectural changes.
  • Manage relationships with external auditors, assessors such as QSAs, and regulators.
  • Develop and improve policies, standards, and procedures aligned with PCI, NYDFS, FFIEC, privacy laws, SOC 2, and ISO 27001.
  • Champion pragmatic governance and prioritize issues representing real security or business risk over checkbox compliance.

Requirements

  • Bachelor's degree in computer science, information security, cybersecurity, or an engineering/STEM field.
  • 8+ years of experience in GRC, security compliance, or technology audit roles in fintech, banking, payments, or other heavily regulated financial environments.
  • Hands-on experience with PCI DSS and at least one of NYDFS 23 NYCRR 500 or FFIEC cybersecurity/IT examination guidance, including implementing or operating controls.
  • Experience with Compliance-as-Code practices and GRC automation tooling such as Vanta or similar platforms.
  • Technical fluency with engineering, cloud platforms such as AWS, GCP, or Azure, and security architecture.

Preferred Skills and Experience

  • 10+ years of security compliance, GRC engineering, or technology audit experience in fintech or financial services.
  • Experience implementing technical controls such as IAM, logging and monitoring, encryption, network segmentation, and infrastructure hardening, as well as integrating compliance checks into CI/CD pipelines.
  • Experience supporting SOC 2 and/or ISO 27001 programs.
  • Experience with payment ecosystems, cardholder data environments, tokenization, or similar PCI-scoped architectures.
  • Working knowledge of GDPR and CCPA/CPRA, with experience partnering with Legal or Privacy.
  • Familiarity with GLBA, BSA/AML technology controls, state money-transmitter expectations, DORA, or international banking rules in the EU and UK.
  • Experience enabling enterprise sales through trust centers, vendor questionnaires, and customer security reviews.
  • Ability to operate a risk register and apply judgment in gray areas.
  • Strong analytical, problem-solving, organizational, project management, communication, and stakeholder management skills.
  • Certifications such as CISSP, CISA, CISM, CRISC, PCIP, CIPP/US, or CIPP/E are preferred.
  • Experience with emerging AI-related financial services expectations or securing AI features in a regulated fintech product is a plus.

Compensation and Benefits

  • Base salary: $152,000–$258,000 USD.
  • Equity.
  • Comprehensive medical, vision, and dental coverage.
  • 401(k) retirement plan.
  • Short- and long-term disability insurance.
  • Life insurance, discounts, and other perks.

ITAR Requirements

Applicants must be a U.S. citizen or national, U.S. lawful permanent resident, refugee, asylee, or eligible to obtain the required authorizations from the U.S. Department of State in accordance with U.S. Government export regulations.

More jobs at SpaceXAI

Similar jobs