Security Architect at Capital.Com

Capital.Com

Warszawa

On-site

PLN 300,000 - 480,000

Full time

8 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Generous annual leave
Health & pension benefits
Workation opportunities
Employee referral program
Hybrid/remote-friendly culture

Job summary

Capital.com, a leading fintech company in Warsaw, is seeking an experienced security professional to own enterprise GRC and regulatory compliance across multiple jurisdictions. You will translate complex regulations into actionable controls, advise C-suite stakeholders, and shape the security program from an enterprise perspective.

The role requires deep ISO 27001 and PCI-DSS knowledge, experience with DORA/NIS2, and English fluency.

Qualifications

  • 8+ years in security with a significant focus on GRC, regulatory compliance, risk management, or a combination — with a track record of owning these programs at enterprise level.
  • Experience designing enterprise-level security architectures or frameworks in regulated financial services (brokerage, payments, banking) is preferred.
  • Deep command of ISO 27001 and PCI-DSS; working knowledge of DORA and NIS2 preferred; translate regulatory text into controls.
  • Multi-jurisdiction compliance experience; FCA or CySEC exposure is a strong advantage.
  • Demonstrated ability to advise C-suite on complex security and regulatory matters; fluent English.

Responsibilities

  • Own the enterprise security GRC framework — policy hierarchy, risk register methodology, control ownership, and audit evidence structure.
  • Map controls to DORA, NIS2, ISO 27001, and PCI-DSS; identify gaps and set remediation priority.
  • Act as final authority on regulatory interpretation affecting security, including written positions for audits and regulatory submissions.
  • Own the compliance and obligation management framework across five regulated jurisdictions (FCA, CySEC, ASIC, SCB, SCA).
  • Represent the company in regulatory discussions with CISO and General Counsel as needed.
  • Define the company's human-risk philosophy and shape security awareness architecture with segmentation and measurement.
  • Advise CISO, CHRO, Risk, and Compliance on security risk and regulatory obligations.
  • Set architectural standards for Corporate Security and approve major framework changes.
  • Support Third-Party Risk Management and Business Continuity & Crisis Management from security perspective.

Skills

GRC leadership
Regulatory compliance
Risk management
Security architecture
ISO 27001
PCI-DSS
DORA
NIS2
FCA/CySEC exposure
English fluency

Education

CISSP
CISM
CRISC

Job description

This Full time on site position offers great opportunities for career growth. Capital.com is a global fintech company with over 1,000,000 clients worldwide. Our platform offers CFD trading across 5,000+ markets, powered by proprietary AI technology that helps traders make better decisions. Our top-rated products have won prestigious industry awards for their cutting-edge technology and seamless client experience. We deliver only the best, so we are always in search of the best people to join our ever-growing talented team.

Responsibilities:
  • Own the enterprise security GRC framework — policy hierarchy, risk register methodology, control ownership, and audit evidence structure.
  • Map controls to DORA, NIS2, ISO 27001, and PCI-DSS, identify gaps, and set remediation priority.
  • Act as the final authority on regulatory interpretation affecting security, including written positions for audits and regulatory submissions.
  • Own the compliance and obligation management framework across all five regulated jurisdictions (FCA, CySEC, ASIC, SCB, SCA), including regulatory horizon scanning.
  • Represent the company in regulatory discussions alongside the CISO and General Counsel where required.
  • Define the company's human-risk philosophy and shape the security awareness architecture — segmentation, interventions, and measurement.
  • Advise the CISO, CHRO, Risk, and Compliance teams on security risk, regulatory obligations, and investment trade-offs.
  • Set the architectural standards the Corporate Security team executes against, and sign off on significant framework changes.
  • Support Third-Party Risk Management and Business Continuity \& Crisis Management from a security and technical perspective.
Requirements:
  • 8+ years in security with a significant focus on GRC, regulatory compliance, riskmanagement, or a combination — with a track record of owning these programs at enterpriselevel, not just familiarity with them.
  • Proven experience designing enterprise-level security architectures or frameworks;experience in a regulated financial services environment (brokerage, payments, banking, orequivalent) is preferred but not required.
  • Deep command of ISO 27001 and PCI-DSS (working knowledge of DORA and NIS2preferred), with the ability to translate regulatory text into specific controls, identify gaps, anddetermine what is mandatory versus discretionary.
  • Multi-jurisdiction compliance experience; direct exposure to FCA or CySEC is a strongadvantage.
  • Demonstrated ability to advise and influence C-suite stakeholders on complex security andregulatory matters.
  • A structured, analytical thinking style — able to hold multiple regulatory regimessimultaneously without losing precision on any of them.
  • Fluent English, written and spoken.
  • Nice to have: Direct experience managing regulatory submissions or engaging with supervisory authorities(FCA, CySEC, ASIC, SCB, or SCA).
  • TPRM program design experience, including DORA ICT third-party risk requirements andsupply chain risk.
  • Business Continuity Management background, with experience meeting operational resilienceobligations and presenting at Board level.
  • Security awareness program design with measurable behaviour-change outcomes.
  • Experience building or scaling a Corporate Security function from an early stage.
  • Relevant professional certifications (CISSP, CISM, CRISC, or equivalent).
What you will get in return:
  • Competitive Salary: We believe great work deserves great pay! Your skills and talents will be rewarded with a salary that makes you feel valued and motivated.
  • Work-Life Harmony: Join a company that genuinely cares about you - because your life outside of work matters just as much as your time on the clock.
  • #LI-Hybrid
  • Generous Time Off: Need a breather? Our annual leave policy lets you recharge and enjoy life outside of work without a worry.
  • Employee Referral Program: Love working here? Share the love! Bring your talented friends on board and get rewarded for growing our awesome team.
  • Comprehensive Health & Pension Benefits: From medical insurance to pension plans, we’ve got your back. Plus, location-specific benefits and perks!
  • Workation Wonderland: Live your digital nomad dreams with 30 extra days to work remotely from anywhere in the world (some restrictions apply).
  • Adventure awaits!
  • Volunteer Days: Make a difference! Take two additional paid days each year to support causes you care about and give back to the community.
  • Be a key player at the forefront of the digital assets movement, propelling your career to new heights!
  • Join a dynamic and rapidly expanding company that values and rewards talent, initiative, and creativity.
  • Work alongside one of the most brilliant teams in the industry.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Architect
Security Architect

Capital • Warszawa

Hybrid
PLN 280,000 - 420,000
Competitive Salary
Hybrid work model
Generous time off
+2
Corporate Security Engineer, AI
Corporate Security Engineer, AI

Capital.com • Warszawa

On-site
PLN 180,000 - 260,000
Competitive Salary
Work-Life Harmony
Generous Time Off
+4
Legal Counsel
Legal Counsel

Capital.com • Warszawa

On-site
PLN 180,000 - 300,000
Competitive Salary
Work-Life Harmony
Generous Time Off
+3
Senior Partnerships Manager
Senior Partnerships Manager

Capital • Warszawa

Hybrid
PLN 120,000 - 180,000
Competitive Salary
Work-Life Harmony
Generous Time Off
+4
Senior Python Engineer (AI)
Senior Python Engineer (AI)

Capital Com Australia limited • Warszawa

On-site
PLN 211,000 - 297,000
Competitive Salary
Work-Life Harmony
Annual Performance Bonus
+5
Senior Governance, Risk and Compliance Engineer
Senior Governance, Risk and Compliance Engineer

payabl. • Warszawa

On-site
PLN 120,000 - 180,000
Provident Fund
Annual Learning Budget
€150 Wolt allowance
+7
Senior Product Operations Manager – LLM Automation
Senior Product Operations Manager – LLM Automation

capital.com • Warszawa

On-site
PLN 350,000 - 700,000
Salary and benefits
Work-Life Harmony
Generous Time Off
+4
Cyber Incident & Response Team Analyst
Cyber Incident & Response Team Analyst

Euroclear • Poland

Hybrid
PLN 180,000 - 260,000
Competitive benefits
Hybrid work model
Senior GRC Analyst
Senior GRC Analyst

OANDA Poland sp. z o.o. • Kraków

On-site
PLN 180,000 - 270,000
Senior Technical Recruiter
Senior Technical Recruiter

Capital.com • Warszawa

Hybrid
PLN 150,000 - 210,000
Competitive salary
Hybrid work model
Health & pension benefits
+3