InternFlow

Europe Arbeitnow ·

full-time

Sr. Security Engineer - GRC Fintech & Financial Services EU/UK

Xai · London

SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates. ABOUT THE ROLE: We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer focused on European Union and United Kingdom information security and financial services regulation to help scale compliance for SpaceXAI and xMoney. As we expand deeper into regulated EU/UK markets, maintaining a robust, transparent, and technically sound information security GRC program is critical. You will architect the systems and processes that automate trust — a pragmatic operator who understands that GRC exists to enable the business, balancing rigorous standards with the velocity of a high-growth company. The ideal candidate brings hands-on experience with frameworks such as DORA, the EU AI Act, NIS2, and related EU/UK information security and operational resilience obligations, plus GRC engineering skills: Compliance-as-Code, continuous evidence collection, and deep partnership with engineering so controls are designed into the platform rather than bolted on after the fact. This role may also include additional tasks and responsibilities as needed to support the team and evolving business priorities. This position may require occasional travel. RESPONSIBILITIES: Own and evolve EU/UK financial services and digital operational resilience posture across DORA (including ICT risk management, incident reporting, resilience testing, and third-party ICT provider oversight), and complementary expectations from EBA/ESMA/EIOPA guidance, PSD2/PSR where applicable, and UK PRA/FCA operational resilience requirements supporting xMoney. Build and maintain Compliance-as-Code capabilities — policy-as-code, automated control validation, continuous evidence collection, and monitoring integrated into CI/CD — so audit and supervisory readiness scales with the business rather than depending on manual, point-in-time checks. Operate and extend GRC platforms (e.g., Vanta) as the backbone for control mapping, evidence management, and continuous compliance; integrate with cloud, identity, logging, and engineering systems to reduce administrative bottlenecks. Partner with Architects and Engineering Leads to bake EU/UK information security and regulatory requirements into design early; translate complex obligations into concrete technical implementations and auditor- or supervisor-ready narratives without slowing development. Design, implement, and validate technical information security controls relevant to regulated EU/UK environments (access control, logging and monitoring, encryption, change management, vulnerability management, ICT third-party oversight, and secure SDLC) — not just document them. Operate the cybersecurity and compliance risk register — identify, quantify, and track risks, distinguishing theoretical gaps from meaningful business and regulatory risk under EU/UK supervisory expectations. Lead information security risk assessments and compliance reviews for new products, features, vendors, and architectural changes that affect the EU/UK regulated attack surface, including ICT third-party / critical provider diligence aligned to DORA. Liaise with the Data Privacy team on security-relevant intersections (e.g., security measures supporting confidentiality and integrity. Own and cultivate relationships with external auditors, assessors, and (where applicable) supervisory contacts on i

RoleSr. Security Engineer - GRC Fintech & Financial Services EU/UK
CompanyXai
LocationLondon
Typefull-time
CompensationNot disclosed
DeadlineRolling

Typical process for this type of role

A general guide — the exact steps for this specific listing may vary; check the original posting for details.

  1. 1ApplicationSubmit your resume through the apply link.
  2. 2ScreeningRecruiter reviews your background against the role.
  3. 3AssessmentA technical test, assignment, or coding round, depending on the role.
  4. 4Interview(s)One or more rounds with the hiring team.
  5. 5OfferOffer letter with compensation and start date.

Before you apply

0/4

More at Xai

Other jobs at Xai

See all 2 openings at Xai

Explore Related Placements


// similar opportunities

You might also like

Security Engineer

Lemfi

Lemfi logo
Londonfull-time
Arbeitnow

LemFi (Series B) is building the go-to financial app for the Global South. Moving to a new country shouldn’t mean starting from zero. That's why our team of 400...

Apply now →

Lead Security Engineer

Encord

Encord logo
Londonfull-time
Arbeitnow

About us Encord is the universal data layer for AI that helps 300+ AI teams train and run models on the right data. Our platform indexes, curates, annotates, an...

Apply now →

Security Analytics Engineer

Sonyinteractiveentertainmentglobal

Sonyinteractiveentertainmentglobal logo
Londonfull-time
Arbeitnow

Why Sony Interactive Entertainment? Sony Interactive Entertainment isn’t just the Best Place to Play — it’s also the Best Place to Work. Sony Interactive Entert...

Apply now →

Application Security Engineer

Legal Counsel - 12 Month FTC At Rightmove Greenhouse

Legal Counsel - 12 Month FTC At Rightmove Greenhouse logo
Londonfull-time
Arbeitnow

Our vision is to give everyone the belief they can make their move. We aim to make moving simpler, by giving everyone the best place to turn to and return to fo...

Apply now →

Application Security Engineer

Pokemoncareers

Pokemoncareers logo
Londonfull-time
Arbeitnow

Get to know The Pokémon Company International The Pokémon Company International manages the Pokémon property outside of Asia and is responsible for brand manage...

Apply now →

GRC Security Specialist

Abound

Abound logo
Londonfull-time
Arbeitnow

About Abound We’re redefining consumer lending in the UK, and beyond. Using advanced AI and Open Banking data, we make fair, affordable personal finance availab...

Apply now →