FinTech Security Architect: GRC & Regulatory Leader (Hybrid)

Capital.Com

Warszawa

On-site

PLN 300,000 - 480,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Generous annual leave
Health & pension benefits
Workation opportunities
Employee referral program
Hybrid/remote-friendly culture

Job summary

Capital.com, a leading fintech company in Warsaw, is seeking an experienced security professional to own enterprise GRC and regulatory compliance across multiple jurisdictions. You will translate complex regulations into actionable controls, advise C-suite stakeholders, and shape the security program from an enterprise perspective.

The role requires deep ISO 27001 and PCI-DSS knowledge, experience with DORA/NIS2, and English fluency.

Qualifications

  • 8+ years in security with a significant focus on GRC, regulatory compliance, risk management, or a combination — with a track record of owning these programs at enterprise level.
  • Experience designing enterprise-level security architectures or frameworks in regulated financial services (brokerage, payments, banking) is preferred.
  • Deep command of ISO 27001 and PCI-DSS; working knowledge of DORA and NIS2 preferred; translate regulatory text into controls.
  • Multi-jurisdiction compliance experience; FCA or CySEC exposure is a strong advantage.
  • Demonstrated ability to advise C-suite on complex security and regulatory matters; fluent English.

Responsibilities

  • Own the enterprise security GRC framework — policy hierarchy, risk register methodology, control ownership, and audit evidence structure.
  • Map controls to DORA, NIS2, ISO 27001, and PCI-DSS; identify gaps and set remediation priority.
  • Act as final authority on regulatory interpretation affecting security, including written positions for audits and regulatory submissions.
  • Own the compliance and obligation management framework across five regulated jurisdictions (FCA, CySEC, ASIC, SCB, SCA).
  • Represent the company in regulatory discussions with CISO and General Counsel as needed.
  • Define the company's human-risk philosophy and shape security awareness architecture with segmentation and measurement.
  • Advise CISO, CHRO, Risk, and Compliance on security risk and regulatory obligations.
  • Set architectural standards for Corporate Security and approve major framework changes.
  • Support Third-Party Risk Management and Business Continuity & Crisis Management from security perspective.

Skills

GRC leadership
Regulatory compliance
Risk management
Security architecture
ISO 27001
PCI-DSS
DORA
NIS2
FCA/CySEC exposure
English fluency

Education

CISSP
CISM
CRISC

Job description

Capital.com, a leading fintech company in Warsaw, is seeking an experienced security professional to own enterprise GRC and regulatory compliance across multiple jurisdictions. You will translate complex regulations into actionable controls, advise C-suite stakeholders, and shape the security program from an enterprise perspective.

The role requires deep ISO 27001 and PCI-DSS knowledge, experience with DORA/NIS2, and English fluency.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security GRC Architect - Fintech (Hybrid)
Senior Security GRC Architect - Fintech (Hybrid)

Capital • Warszawa

Hybrid
PLN 280,000 - 420,000
Competitive Salary
Hybrid work model
Generous time off
+2
Security Architect, GRC & Regulatory Strategy
Security Architect, GRC & Regulatory Strategy

Capital.com • Warszawa

On-site
PLN 240,000 - 420,000
Competitive Salary
Work-Life Harmony
Generous Time Off
+4
Senior GRC Analyst: FinTech Security & Compliance Architect
Senior GRC Analyst: FinTech Security & Compliance Architect

OANDA Poland sp. z o.o. • Kraków

On-site
PLN 180,000 - 270,000
Security Architect
Security Architect

Capital • Warszawa

Hybrid
PLN 280,000 - 420,000
Competitive Salary
Hybrid work model
Generous time off
+2
Senior GRC Analyst
Senior GRC Analyst

OANDA Corporation • Kraków

On-site
PLN 180,000 - 230,000
GRC & InfoSec Analyst — FinTech Risk & Compliance
GRC & InfoSec Analyst — FinTech Risk & Compliance

OANDA TMS Brokers S.A. • Warszawa

Hybrid
PLN 180,000 - 260,000
Senior GRC & Cyber Risk Lead for FinTech
Senior GRC & Cyber Risk Lead for FinTech

OANDA Corporation • Kraków

On-site
PLN 180,000 - 230,000
Global FinTech Legal Counsel — Licensing & Compliance
Global FinTech Legal Counsel — Licensing & Compliance

Capital.com • Warszawa

On-site
PLN 180,000 - 300,000
Competitive salary
Work-life harmony
Generous time off
+4
CISO & Information Security Leader - Build Global Program
CISO & Information Security Leader - Build Global Program

TechTree • Kraków

Hybrid
PLN 300,000 - 520,000
Private medical care
Sport card
Life insurance
+2
Security Architect at Capital.Com
Security Architect at Capital.Com

Capital.Com • Warszawa

On-site
PLN 300,000 - 480,000
Generous annual leave
Health & pension benefits
Workation opportunities
+2