talentyGo

Sr. Security Engineer - GRC EU/UK Regulation & Data Protection

Xai

📍 London, DE0🕐 today
Apply now →

Sign up free in 30 seconds: you also get the AI match score with your resume.

Role overview

Xai is hiring for the Sr. Security Engineer - GRC EU/UK Regulation & Data Protection role in London, DE. It is a position, Senior level, in the Tech sector. It was posted today.

On TalentyGo you can review this job and apply more effectively: Charlie prepares an ATS-optimized resume and a cover letter tailored to "Sr. Security Engineer - GRC EU/UK Regulation & Data Protection" at Xai in about a minute. Before you apply, you can also check how well your profile fits, with a match score based on skills, experience, location and seniority.

Role
Sr. Security Engineer - GRC EU/UK Regulation & Data Protection
Company
Xai
Location
London, DE
Work mode
On-site
Seniority
Senior
Sector
Tech
Posted
today

Description

<div class="content-intro"><p><span style="font-family: arial, helvetica, sans-serif;">SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge.&nbsp;</span><span style="font-family: arial, helvetica, sans-serif;">Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. </span><span style="font-family: arial, helvetica, sans-serif;">We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. </span><span style="font-family: arial, helvetica, sans-serif;">All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates.</span></p></div><h3 data-pm-slice="1 1 []"><span style="font-family: arial, helvetica, sans-serif;">ABOUT THE ROLE:</span></h3> <p>We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer focused on European Union and United Kingdom information security and financial services regulation to help scale compliance for SpaceXAI and xMoney. As we expand deeper into regulated EU/UK markets, maintaining a robust, transparent, and technically sound information security GRC program is critical. You will architect the systems and processes that automate trust — a pragmatic operator who understands that GRC exists to enable the business, balancing rigorous standards with the velocity of a high-growth company. The ideal candidate brings hands-on experience with frameworks such as DORA, the EU AI Act, NIS2, and related EU/UK information security and operational resilience obligations, plus GRC engineering skills: Compliance-as-Code, continuous evidence collection, and deep partnership with engineering so controls are designed into the platform rather than bolted on after the fact.</p> <p><em>This role may also include additional tasks and responsibilities as needed to support the team and evolving business priorities. This position may require occasional travel.</em></p> <h3><span style="font-family: arial, helvetica, sans-serif;">RESPONSIBILITIES:</span></h3> <ul> <li>Own and evolve EU/UK financial services and digital operational resilience posture across DORA (including ICT risk management, incident reporting, resilience testing, and third-party ICT provider oversight), and complementary expectations from EBA/ESMA/EIOPA guidance, PSD2/PSR where applicable, and UK PRA/FCA operational resilience requirements supporting xMoney.</li> <li>Build and maintain Compliance-as-Code capabilities — policy-as-code, automated control validation, continuous evidence collection, and monitoring integrated into CI/CD — so audit and supervisory readiness scales with the business rather than depending on manual, point-in-time checks.</li> <li>Operate and extend GRC platforms (e.g., Vanta) as the backbone for control mapping, evidence management, and continuous compliance; integrate with cloud, identity, logging, and engineering systems to reduce administrative bottlenecks.</li> <li>Partner with Architects and Engineering Leads to bake EU/UK information security and regulatory requirements into design early; translate complex obligations into concrete technical implementations and auditor- or supervisor-ready narratives without slowing development.</li> <li>Design, implement, and validate technical information security controls relevant to regulated EU/UK environments (access control, logging and monitoring, encryption, change management, vulnerability management, ICT third-party oversight, and secure SDLC) — not just document them.</li> <li>Operate the cybersecurity and compliance risk register — identify, quantify, and track risks, distinguishing theoretical gaps from meaningful business and regulatory risk under EU/UK supervisory expectations.</li> <li>Lead information security risk assessments and compliance reviews for new products, features, vendors, and architectural changes that affect the EU/UK regulated attack surface, including ICT third-party / critical provider diligence aligned to DORA.</li> <li>Liaise with the Data Privacy team on security-relevant intersections (e.g., security measures supporting confidentiality and integrity.</li> <li>Own and cultivate relationships with external auditors, assessors, and (where applicable) supervisory contacts on information security topics; serve as the bridge between external parties and internal teams so requests are reasonable, clear, and relevant to our stack.</li> <li>Develop, maintain, and continuously improve information security policies, standards, and procedures aligned to DORA, the EU AI Act, NIS2 where in scope, and complementary frameworks (e.g., ISO 27001, SOC 2) where they overlap.</li> <li>Champion pragmatic governance — prioritize issues that represent real security or business risk over checkbox compliance.</li> </ul> <h3><span style="font-family: arial, helvetica, sans-serif;">BASIC QUALIFICATIONS:</span></h3> <ul> <li>Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field.</li> <li>5+ years of experience in GRC, information security compliance, or technology audit roles in fintech, banking, payments, or other heavily regulated environments with EU and/or UK exposure.</li> <li>Hands-on experience implementing or operating controls against several of the following: DORA, the EU AI Act, NIS2, PSD2/PSR, or UK PRA/FCA operational resilience expectations — not only reading the requirements.</li> <li>Familiar with data privacy regulations applicable to the EU/UK region (e.g., EU GDPR, UK GDPR, UK Data Protection Act 2018) sufficient to liaise with Privacy counterparts.</li> <li>Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, or similar), with a bias toward continuous monitoring and reducing manual evidence collection.</li> <li>Technical fluency sufficient to speak the language of engineering, On-premises, hybrid, or cloud (AWS/GCP/Azure), and security architecture, and to anticipate how design decisions impact information security risk and compliance.</li> </ul> <h3><span style="font-family: arial, helvetica, sans-serif;">PREFERRED SKILLS AND EXPERIENCE:</span></h3> <ul> <li>7+ years of information security compliance, GRC engineering, or technology audit-related experience in fintech or financial services with a primary EU/UK focus.</li> <li>Hands-on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, network segmentation, infrastructure hardening) and integrating compliance checks into CI/CD pipelines.</li> <li>Experience supporting ISO 27001 and/or SOC 2 programs alongside EU/UK regulatory obligations.</li> <li>Familiar with GDPR concepts that commonly intersect with information security (e.g., security of processing, breach notification timelines, encryption/pseudonymization as security measures) when collaborating with DPO/Legal/Privacy functions.</li> <li>Familiarity with DORA ICT third-party risk, register of information, threat-led penetration testing (TLPT) c

The market for this role in London

TalentyGo lists 5357 similar roles (25 in London), 24% remote. Charlie ranks them against your CV, each with a clear score.

Similar roles
5357
Remote
24%
New / 7d
130

Similar jobs

Network Engineer
📍 San Francisco · Remote · tech
Senior Backend Engineer, Compliance Engineering
📍 Remote - United States · Remote · tech
Staff Machine Learning Engineer, Traffic Intelligence
📍 United States · tech
Legal & Compliance AI Engineer
📍 San Francisco · tech
Backend Engineer, Source Code Experience (Ruby)
📍 Remote · Remote · tech
Senior Backend Engineer, Create: Source Code Experience (Ruby)
📍 Remote · Remote · tech
See all similar jobs →
Apply now →

TalentyGo is an aggregator of job postings from public sources. Always verify information directly with the company. Applications go through the original company website; TalentyGo does not manage hiring processes.