Senior Security Engineer GRC Fintech and Financial Services EU UK
SpaceXAI builds frontier AI models and products including the Grok conversational assistant and a multimodal developer API.
Funding history
About SpaceXAI
SpaceXAI is a US-based AI company focused on accelerating scientific discovery and understanding the universe through reasoning, voice, image, video, and generative AI systems. Formerly xAI, it was acquired by SpaceX effective February 2, 2026, while continuing to operate the x.ai site and services.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will scale EU and UK information-security compliance for SpaceXAI and xMoney. You will build continuous compliance capabilities, manage GRC platforms and risks, implement technical controls, assess products and vendors, and liaise with auditors, supervisors, engineering, and privacy partners.
Requirements
- Bachelor's degree in computer science, information security, cybersecurity, engineering, or a STEM field.
- 8+ years of GRC, information-security compliance, or technology audit experience in regulated environments with EU or UK exposure.
- Hands-on experience implementing or operating controls for DORA, the EU AI Act, NIS2, PSD2/PSR, or UK PRA/FCA expectations.
- Familiarity with EU and UK privacy regulations.
- Experience with Compliance-as-Code and GRC automation tooling.
- Technical fluency in on-premises, hybrid, or cloud environments and security architecture.
Responsibilities
- Own EU and UK financial-services and operational-resilience compliance.
- Build Compliance-as-Code, automated validation, continuous evidence collection, and CI/CD monitoring.
- Operate and extend GRC platforms such as Vanta.
- Embed EU and UK security and regulatory requirements into technical designs.
- Design, implement, and validate information-security controls.
- Operate the cybersecurity and compliance risk register.
- Lead risk assessments and compliance reviews for products, vendors, and architectural changes.
- Liaise with the Data Privacy team on security matters.
- Manage relationships with auditors, assessors, and supervisory contacts.
- Maintain information-security policies, standards, and procedures.
