Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 1
AML @ 3
AWS @ 6
Audit @ 7
Azure @ 6
CCPA @ 4
CI/CD @ 4
Change Management
Communication @ 7
Compliance @ 4
FinTech @ 4
GCP @ 6
GDPR @ 4
Payments @ 7
Project Management @ 7
Security @ 7
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
SpaceXAI is seeking an experienced Governance, Risk, and Compliance (GRC) Engineer focused on fintech and financial services regulation to help scale compliance for SpaceXAI and xMoney. The role will architect systems and processes that automate trust while balancing rigorous standards with the velocity of a high-growth company.
Responsibilities
- Own and evolve financial services and payments compliance across PCI DSS, NYDFS, including 23 NYCRR 500, FFIEC guidance, and related banking and fintech regulatory expectations supporting xMoney across relevant jurisdictions.
- Build and maintain Compliance-as-Code capabilities, including policy-as-code, automated control validation, continuous evidence collection, and monitoring integrated into CI/CD.
- Operate and extend GRC platforms such as Vanta for control mapping, evidence management, and continuous compliance.
- Integrate GRC platforms with cloud, identity, logging, and engineering systems to reduce administrative bottlenecks.
- Partner with architects and engineering leads to incorporate compliance and privacy requirements into platform design and translate regulatory obligations into technical implementations and auditor-ready narratives.
- Design, implement, and validate technical controls for fintech environments, including cardholder data environment scoping and segmentation, access control, logging, encryption, change management, and vulnerability management.
- Operate the cybersecurity and compliance risk register by identifying, quantifying, and tracking risks.
- Lead risk assessments and compliance reviews for new products, payment flows, features, vendors, and architectural changes.
- Manage relationships with external auditors, assessors such as QSAs, and regulators.
- Develop and improve policies, standards, and procedures aligned with PCI, NYDFS, FFIEC, privacy laws, SOC 2, and ISO 27001.
- Champion pragmatic governance and prioritize issues representing real security or business risk over checkbox compliance.
Requirements
- Bachelor's degree in computer science, information security, cybersecurity, or an engineering/STEM field.
- 8+ years of experience in GRC, security compliance, or technology audit roles in fintech, banking, payments, or other heavily regulated financial environments.
- Hands-on experience with PCI DSS and at least one of NYDFS 23 NYCRR 500 or FFIEC cybersecurity/IT examination guidance, including implementing or operating controls.
- Experience with Compliance-as-Code practices and GRC automation tooling such as Vanta or similar platforms.
- Technical fluency with engineering, cloud platforms such as AWS, GCP, or Azure, and security architecture.
Preferred Skills and Experience
- 10+ years of security compliance, GRC engineering, or technology audit experience in fintech or financial services.
- Experience implementing technical controls such as IAM, logging and monitoring, encryption, network segmentation, and infrastructure hardening, as well as integrating compliance checks into CI/CD pipelines.
- Experience supporting SOC 2 and/or ISO 27001 programs.
- Experience with payment ecosystems, cardholder data environments, tokenization, or similar PCI-scoped architectures.
- Working knowledge of GDPR and CCPA/CPRA, with experience partnering with Legal or Privacy.
- Familiarity with GLBA, BSA/AML technology controls, state money-transmitter expectations, DORA, or international banking rules in the EU and UK.
- Experience enabling enterprise sales through trust centers, vendor questionnaires, and customer security reviews.
- Ability to operate a risk register and apply judgment in gray areas.
- Strong analytical, problem-solving, organizational, project management, communication, and stakeholder management skills.
- Certifications such as CISSP, CISA, CISM, CRISC, PCIP, CIPP/US, or CIPP/E are preferred.
- Experience with emerging AI-related financial services expectations or securing AI features in a regulated fintech product is a plus.
Compensation and Benefits
- Base salary: $152,000–$258,000 USD.
- Equity.
- Comprehensive medical, vision, and dental coverage.
- 401(k) retirement plan.
- Short- and long-term disability insurance.
- Life insurance, discounts, and other perks.
ITAR Requirements
Applicants must be a U.S. citizen or national, U.S. lawful permanent resident, refugee, asylee, or eligible to obtain the required authorizations from the U.S. Department of State in accordance with U.S. Government export regulations.
More jobs at SpaceXAI
Software Engineer - Evals
SpaceXAI · Palo Alto, United States
USD 175,000-275,000 per year
ML Infrastructure Engineer
SpaceXAI · Palo Alto, United States
USD 180,000-440,000 per year
Software Engineer - Platform Infrastructure (Rust, C++)
SpaceXAI · Palo Alto, United States
USD 180,000-440,000 per year
AI Tutor - Sinhala
SpaceXAI · World
USD 35-45 per hour
Software Engineer - Network Software and Services
SpaceXAI · Dublin, Ireland
EUR 80,000-150,000 per year
Similar jobs
Senior Security Engineer - GRC Frameworks & AI Governance
SpaceXAI · Washington, United States, New York City, United States, Palo Alto, United States
USD 152,000-258,000 per year
Infrastructure Security Engineer
SpaceXAI · Palo Alto, United States, Washington, United States, Austin, United States, New York City, United States
USD 100,000-258,000 per year
Applied AI Security Architect
Anthropic · London, United Kingdom
GBP 190,000-230,000 per year
Staff+ Software Engineer, GRC Platform
Anthropic · San Francisco, United States, New York City, United States, Seattle, United States
USD 320,000-405,000 per year
Engineering Manager, GRC Platform
Anthropic · San Francisco, United States, New York City, United States, Seattle, United States
USD 320,000-405,000 per year
Senior Manager, Platform Operations
Collibra · United States
USD 168,000-210,000 per year
Manager, Information Security
ClickHouse · United States
USD 180,000-300,000 per year
Staff Security Risk & Compliance Program Manager - Access Management
Confluent · United States
USD 222,100-261,000 per year