Senior Security GRC Architect - Fintech (Hybrid)

Capital

Warszawa

Hybrid

PLN 280,000 - 420,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Competitive Salary
Hybrid work model
Generous time off
Health & Pension benefits
Remote work option

Job summary

Capital.com is seeking a Security Architect to own the enterprise GRC framework and regulatory posture across multiple jurisdictions. You will map controls to ISO 27001, PCI-DSS, DORA and NIS2, drive remediation, and advise executive teams on security risk and strategic investments.

The role requires 8+ years in security with a focus on GRC in regulated financial services or brokerage. Strong English and stakeholder management are essential.

Qualifications

  • 8+ years in security with a significant focus on GRC and regulatory compliance.
  • Experience designing enterprise-level security architectures in a regulated financial services environment.
  • Deep command of ISO 27001 and PCI-DSS; working knowledge of DORA and NIS2 preferred.
  • Translate regulatory text into specific controls, identify gaps, and determine mandatory versus discretionary.

Responsibilities

  • Own the enterprise security GRC framework — policy hierarchy, risk register methodology, control ownership, and audit evidence structure.
  • Map controls to DORA, NIS2, ISO 27001, and PCI-DSS, identify gaps, and set remediation priority.
  • Act as the final authority on regulatory interpretation affecting security, including positions for audits.
  • Own the compliance framework across FCA, CySEC, ASIC, SCB, SCA including horizon scanning.
  • Represent the company in regulatory discussions alongside the CISO and GC where required.
  • Define the company's human-risk philosophy and shape the security awareness architecture.
  • Advise the CISO, CHRO, Risk, and Compliance teams on security risk and regulatory trade-offs.
  • Set architectural standards the Corporate Security team executes against and sign off on major changes.
  • Support Third-Party Risk Management and Business Continuity & Crisis Management from a security and technical perspective.
  • Demonstrated ability to lead and scale a Corporate Security function in a regulated environment.

Skills

GRC management
Regulatory compliance
Security architecture
Risk assessment
Regulatory interpretation
CISSP/CISM/CRISC
English proficiency

Job description

Capital.com is seeking a Security Architect to own the enterprise GRC framework and regulatory posture across multiple jurisdictions. You will map controls to ISO 27001, PCI-DSS, DORA and NIS2, drive remediation, and advise executive teams on security risk and strategic investments.

The role requires 8+ years in security with a focus on GRC in regulated financial services or brokerage. Strong English and stakeholder management are essential.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Architect, GRC & Regulatory Strategy
Security Architect, GRC & Regulatory Strategy

Capital.com • Warszawa

On-site
PLN 240,000 - 420,000
Competitive Salary
Work-Life Harmony
Generous Time Off
+4
FinTech Security Architect: GRC & Regulatory Leader (Hybrid)
FinTech Security Architect: GRC & Regulatory Leader (Hybrid)

Capital.Com • Warszawa

On-site
PLN 300,000 - 480,000
Generous annual leave
Health & pension benefits
Workation opportunities
+2
Security Architect
Security Architect

Capital • Warszawa

Hybrid
PLN 280,000 - 420,000
Competitive Salary
Hybrid work model
Generous time off
+2
Global IT GRC Architect - Remote/Hybrid
Global IT GRC Architect - Remote/Hybrid

Roche • Poznań

Hybrid
PLN 212,000 - 395,000
Annual bonus
Training budget
Recharge Fridays
+8
Security Architect
Security Architect

Capital.com • Warszawa

On-site
PLN 240,000 - 420,000
Competitive Salary
Work-Life Harmony
Generous Time Off
+4
Security Architect at Capital.Com
Security Architect at Capital.Com

Capital.Com • Warszawa

On-site
PLN 300,000 - 480,000
Generous annual leave
Health & pension benefits
Workation opportunities
+2
Senior GRC Analyst: FinTech Security & Compliance Architect
Senior GRC Analyst: FinTech Security & Compliance Architect

OANDA Poland sp. z o.o. • Kraków

On-site
PLN 180,000 - 270,000
Senior GRC Analyst
Senior GRC Analyst

OANDA Corporation • Kraków

On-site
PLN 180,000 - 230,000
Senior GRC Analyst: InfoSec Governance & Risk
Senior GRC Analyst: InfoSec Governance & Risk

OANDA • Kraków

On-site
PLN 180,000 - 280,000
Hybrid Network Security Architect for FinTech Platforms
Hybrid Network Security Architect for FinTech Platforms

EPAM Systems, Inc. • Poland

Hybrid
PLN 230,000 - 360,000
Health insurance
Multisport access
Relocation support