Security Architect

Capital

Warszawa

Hybrid

PLN 280,000 - 420,000

Full time

8 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Competitive Salary
Hybrid work model
Generous time off
Health & Pension benefits
Remote work option

Job summary

Capital.com is seeking a Security Architect to own the enterprise GRC framework and regulatory posture across multiple jurisdictions. You will map controls to ISO 27001, PCI-DSS, DORA and NIS2, drive remediation, and advise executive teams on security risk and strategic investments.

The role requires 8+ years in security with a focus on GRC in regulated financial services or brokerage. Strong English and stakeholder management are essential.

Qualifications

  • 8+ years in security with a significant focus on GRC and regulatory compliance.
  • Experience designing enterprise-level security architectures in a regulated financial services environment.
  • Deep command of ISO 27001 and PCI-DSS; working knowledge of DORA and NIS2 preferred.
  • Translate regulatory text into specific controls, identify gaps, and determine mandatory versus discretionary.

Responsibilities

  • Own the enterprise security GRC framework — policy hierarchy, risk register methodology, control ownership, and audit evidence structure.
  • Map controls to DORA, NIS2, ISO 27001, and PCI-DSS, identify gaps, and set remediation priority.
  • Act as the final authority on regulatory interpretation affecting security, including positions for audits.
  • Own the compliance framework across FCA, CySEC, ASIC, SCB, SCA including horizon scanning.
  • Represent the company in regulatory discussions alongside the CISO and GC where required.
  • Define the company's human-risk philosophy and shape the security awareness architecture.
  • Advise the CISO, CHRO, Risk, and Compliance teams on security risk and regulatory trade-offs.
  • Set architectural standards the Corporate Security team executes against and sign off on major changes.
  • Support Third-Party Risk Management and Business Continuity & Crisis Management from a security and technical perspective.
  • Demonstrated ability to lead and scale a Corporate Security function in a regulated environment.

Skills

GRC management
Regulatory compliance
Security architecture
Risk assessment
Regulatory interpretation
CISSP/CISM/CRISC
English proficiency

Job description

Capital.com is a global fintech company with over 1,000,000 clients worldwide. Our platform offers CFD trading across 5,000+ markets, powered by proprietary AI technology that helps traders make better decisions. Our top-rated products have won prestigious industry awards for their cutting-edge technology and seamless client experience. We deliver only the best, so we are always in search of the best people to join our ever-growing talented team.

As part of our continued investment in security and regulatory resilience, we are seeking a Security Architect to own the design of our enterprise security governance, risk, and compliance (GRC) framework. This is a senior, high-visibility role that sits at the intersection of security architecture, multi-jurisdiction regulatory compliance, and organizational risk — shaping how a global fintech company regulated across five jurisdictions thinks about, measures, and reduces security risk.

  • Own the enterprise security GRC framework — policy hierarchy, risk register methodology,control ownership, and audit evidence structure.
  • Map controls to DORA, NIS2, ISO 27001, and PCI-DSS, identify gaps, and set remediationpriority.
  • Act as the final authority on regulatory interpretation affecting security, including writtenpositions for audits and regulatory submissions.
  • Own the compliance and obligation management framework across all five regulated jurisdictions (FCA, CySEC, ASIC, SCB, SCA), including regulatory horizon scanning.
  • Represent the company in regulatory discussions alongside the CISO and General Counselwhere required.
  • Define the company's human-risk philosophy and shape the security awareness architecture— segmentation, interventions, and measurement.
  • Advise the CISO, CHRO, Risk, and Compliance teams on security risk, regulatory obligations,and investment trade-offs.
  • Set the architectural standards the Corporate Security team executes against, and sign off onsignificant framework changes.
  • Support Third-Party Risk Management and Business Continuity & Crisis Management from asecurity and technical perspective.
  • 8+ years in security with a significant focus on GRC, regulatory compliance, riskmanagement, or a combination — with a track record of owning these programs at enterpriselevel, not just familiarity with them.
  • Proven experience designing enterprise-level security architectures or frameworks;experience in a regulated financial services environment (brokerage, payments, banking, orequivalent) is preferred but not required.
  • Deep command of ISO 27001 and PCI-DSS (working knowledge of DORA and NIS2preferred), with the ability to translate regulatory text into specific controls, identify gaps, anddetermine what is mandatory versus discretionary.
  • Multi-jurisdiction compliance experience; direct exposure to FCA or CySEC is a strongadvantage.
  • Demonstrated ability to advise and influence C-suite stakeholders on complex security andregulatory matters.
  • A structured, analytical thinking style — able to hold multiple regulatory regimessimultaneously without losing precision on any of them.
  • Fluent English, written and spoken.
  • Direct experience managing regulatory submissions or engaging with supervisory authorities(FCA, CySEC, ASIC, SCB, or SCA).
  • TPRM program design experience, including DORA ICT third-party risk requirements andsupply chain risk.
  • Business Continuity Management background, with experience meeting operational resilienceobligations and presenting at Board level.
  • Security awareness program design with measurable behaviour-change outcomes.
  • Experience building or scaling a Corporate Security function from an early stage.
  • Relevant professional certifications (CISSP, CISM, CRISC, or equivalent).
What you will get in return:
  • Competitive Salary: We believe great work deserves great pay! Your skills and talents will be rewarded with a salary that makes you feel valued and motivated.
  • Work-Life Harmony: Join a company that genuinely cares about you - because your life outside of work matters just as much as your time on the clock. #LI-Hybrid
  • Generous Time Off: Need a breather? Our annual leave policy lets you recharge and enjoy life outside of work without a worry.
  • Employee Referral Program: Love working here? Share the love! Bring your talented friends on board and get rewarded for growing our awesome team.
  • Comprehensive Health & Pension Benefits: From medical insurance to pension plans, we’ve got your back. Plus, location-specific benefits and perks!
  • Workation Wonderland: Live your digital nomad dreams with 30 extra days to work remotely from anywhere in the world (some restrictions apply). Adventure awaits!
  • Volunteer Days: Make a difference! Take two additional paid days each year to support causes you care about and give back to the community.

Be a key player at the forefront of the digital assets movement, propelling your career to new heights! Join a dynamic and rapidly expanding company that values and rewards talent, initiative, and creativity. Work alongside one of the most brilliant teams in the industry.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Architect at Capital.Com
Security Architect at Capital.Com

Capital.Com • Warszawa

On-site
PLN 300,000 - 480,000
Generous annual leave
Health & pension benefits
Workation opportunities
+2
Corporate Security Engineer, AI
Corporate Security Engineer, AI

Capital.com • Warszawa

On-site
PLN 180,000 - 260,000
Competitive Salary
Work-Life Harmony
Generous Time Off
+4
Senior Security GRC Architect - Fintech (Hybrid)
Senior Security GRC Architect - Fintech (Hybrid)

Capital • Warszawa

Hybrid
PLN 280,000 - 420,000
Competitive Salary
Hybrid work model
Generous time off
+2
Information Security Architect
Information Security Architect

UNIT4 NV • Wrocław

Hybrid
PLN 260,000 - 380,000
Remote working opportunities
Flexible leave policy
Application Security Engineer
Application Security Engineer

LionHires Recruitment • Poland

On-site
PLN 180,000 - 240,000
System Architect (Platform focus)
System Architect (Platform focus)

Euroclear • Kraków

Hybrid
PLN 260,000 - 420,000
Hybrid working model
Competitive salary
Learning & development opportunities
+1
System Architect (Platform focus)
System Architect (Platform focus)

Euroclear • Poland

Hybrid
PLN 180,000 - 240,000
Hybrid working model
Competitive salary & comprehensive
Benefits
Information Security Architect
Information Security Architect

Unit4 • Wrocław

On-site
PLN 220,000 - 320,000
Remote working opportunities
Flexible leave policy
Wellbeing days
+1
FinTech Security Architect: GRC & Regulatory Leader (Hybrid)
FinTech Security Architect: GRC & Regulatory Leader (Hybrid)

Capital.Com • Warszawa

On-site
PLN 300,000 - 480,000
Generous annual leave
Health & pension benefits
Workation opportunities
+2
Security Architect
Security Architect

Billennium • Województwo małopolskie

On-site
PLN 200,000 - 340,000
Udemy for Business
Private medical care
Multisport card
+5