← Zurück zur Liste
Stelle

Security Engineer – GRC, Fintech & Financial Services

Security Engineer • Vor Ort • Vollzeit Vereinigte Staaten New York, USA

Join SpaceXAI to scale the Governance, Risk and Compliance (GRC) program for SpaceXAI and xMoney as they operate deeper in regulated financial environments. Architect the systems and processes that automate trust, bringing hands-on fintech compliance experience (PCI DSS, NYDFS, FFIEC) and GRC engineering skills — Compliance-as-Code, continuous evidence collection, and close partnership with engineering to design controls into the platform.

Stack

Responsibilities

  • Own and evolve financial services and payments compliance posture across PCI DSS, NYDFS (23 NYCRR 500), FFIEC guidance and related banking/fintech regulatory expectations
  • Build and maintain Compliance-as-Code capabilities — policy-as-code, automated control validation, continuous evidence collection integrated into CI/CD
  • Operate and extend GRC platforms (e.g. Vanta) for control mapping, evidence management and continuous compliance
  • Partner with Architects and Engineering Leads to bake compliance and privacy requirements into technical implementations
  • Design, implement and validate technical controls (cardholder data environment scoping and segmentation, access control, logging, encryption, change management, vulnerability management)
  • Operate the cybersecurity and compliance risk register, distinguishing theoretical gaps from meaningful business/regulatory risk
  • Lead risk assessments and compliance reviews for new products, payment flows, features, vendors and architectural changes
  • Own relationships with external auditors, assessors and regulators
  • Develop, maintain and improve policies, standards and procedures aligned to PCI, NYDFS, FFIEC, privacy laws and complementary frameworks (SOC 2, ISO 27001)

Requirements

  • Bachelor's degree in computer science, Information Security, Cybersecurity or an engineering/STEM field
  • 8+ years of experience in GRC, security compliance or technology audit roles in fintech, banking, payments or other heavily regulated financial environments
  • Hands-on experience with PCI DSS and at least one of NYDFS (23 NYCRR 500) or FFIEC cybersecurity/IT examination guidance, including implementing or operating controls
  • Experience with Compliance-as-Code practices and GRC automation tooling (e.g. Vanta or similar), with a bias toward continuous monitoring
  • Technical fluency sufficient to speak the language of engineering, cloud (AWS/GCP/Azure) and security architecture

Nice to have

  • 10+ years of security compliance, GRC engineering or technology audit-related experience in fintech or financial services
  • Hands-on experience implementing technical controls (IAM, logging and monitoring, encryption, network segmentation, infrastructure hardening) and integrating compliance checks into CI/CD
  • Experience supporting SOC 2 and/or ISO 27001 programs alongside fintech-specific obligations
  • Experience with payment ecosystems, cardholder data environments, tokenization or similar PCI-scoped architectures
  • Working knowledge of data privacy frameworks (GDPR, CCPA/CPRA)
  • Familiarity with additional financial regulatory regimes (GLBA, BSA/AML, state money-transmitter expectations, EU/UK banking rules, DORA)
  • Experience enabling enterprise sales through trust centers, vendor questionnaires and customer security reviews
  • Certifications such as CISSP, CISA, CISM, CRISC, PCIP, CIPP/US, CIPP/E or similar

Soft skills

Strong communication skills, explaining regulatory and privacy requirements in plain language to engineers, legal, sales and executivesExceptional analytical, problem-solving, organizational and project management skillsPragmatic judgment in gray areas, focusing on outcomes over opticsInitiative and hands-on ownership in a flat, high-growth organization

What we offer

  • Equity
  • Comprehensive medical, vision and dental coverage
  • Access to a 401(k) retirement plan
  • Short- and long-term disability insurance
  • Life insurance
  • Various other discounts and perks

About the company

SpaceXAI's mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. The team is small, highly motivated and focused on engineering excellence, operating with a flat organizational structure where all employees are expected to be hands-on and contribute directly to the mission.

Education: Számítástechnikai, információbiztonsági, kiberbiztonsági vagy mérnöki/STEM szakos alapdiploma

Ähnliche Stellen