Fintech GRC Engineer: Automate Compliance & Trust

SpaceXAI

Palo Alto (CA)

On-site

USD 152,000 - 228,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Equity
Comprehensive medical, vision, dental
401(k) retirement plan

Job summary

SpaceXAI is seeking an experienced Governance, Risk, and Compliance (GRC) Engineer focused on fintech and regulatory compliance to scale our GRC program. You will architect systems that automate trust, balancing rigorous standards with rapid growth, and you will partner with engineering to embed controls into the platform.

The ideal candidate has hands‑on fintech compliance experience (PCI DSS, NYDFS, FFIEC), data privacy familiarity (GDPR, CCPA), and GRC engineering skills including

Qualifications

  • Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field.
  • 8+ years of experience in GRC, security compliance, or technology audit roles in fintech, banking, payments, or other heavily regulated financial environments.
  • Hands‑on experience with PCI DSS and at least one of NYDFS (23 NYCRR 500) or FFIEC cybersecurity/IT examination guidance — including implementing or operating controls, not only reading the requirements.
  • Experience with Compliance‑as‑Code practices and GRC automation tooling (e.g., Vanta, or similar), with a bias toward continuous monitoring and reducing manual evidence collection.
  • Technical fluency sufficient to speak the language of engineering, cloud (AWS/GCP/Azure), and security architecture, and to anticipate how design decisions impact risk and compliance.

Responsibilities

  • Own and evolve financial services and payments compliance posture across PCI DSS, NYDFS (including 23 NYCRR 500), FFIEC guidance, and related banking/fintech regulatory expectations supporting xMoney across relevant jurisdictions.
  • Build and maintain Compliance‑as‑Code capabilities — policy‑as‑code, automated control validation, continuous evidence collection, and monitoring integrated into CI/CD — so audit readiness scales with the business rather than depending on manual, point‑in‑time checks.
  • Operate and extend GRC platforms (e.g., Vanta) as the backbone for control mapping, evidence management, and continuous compliance; integrate with cloud, identity, logging, and engineering systems to reduce administrative bottlenecks.
  • Partner with Architects and Engineering Leads to bake compliance and privacy requirements; translate complex regulatory obligations into concrete technical implementations and auditor‑ready narratives without slowing development.
  • Design, implement, and validate technical controls relevant to fintech environments (cardholder data environment scoping and segmentation, access control, logging, encryption, change management, vulnerability management) — not just document them.
  • Operate the cybersecurity and compliance risk register — identify, quantify, and track risks, distinguishing theoretical gaps from meaningful business and regulatory risk.
  • Lead risk assessments and compliance reviews for new products, payment flows, features, vendors, and architectural changes that affect the regulated attack surface.
  • Own and cultivate relationships with external auditors, assessors (e.g., QSAs where applicable), and regulators; serve as the bridge between auditors and internal teams so requests are reasonable, clear, and relevant to our stack.
  • Develop, maintain, and continuously improve policies, standards, and procedures aligned to PCI, NYDFS, FFIEC, privacy laws, and complementary frameworks (e.g., SOC 2, ISO 27001) where they overlap.
  • Champion pragmatic governance — prioritize issues that represent real security or business risk over checkbox compliance.

Skills

GRC Engineering
Compliance
PCI DSS
NYDFS 23 NYCRR 500
FFIEC
Compliance‑as‑Code
CI/CD
Cloud Security
Auditing
Regulatory liaison

Education

Bachelor's degree in computer science or information security or engineering/STEM
Engineering/STEM background

Tools

Vanta
GRC automation tooling

Job description

SpaceXAI is seeking an experienced Governance, Risk, and Compliance (GRC) Engineer focused on fintech and regulatory compliance to scale our GRC program. You will architect systems that automate trust, balancing rigorous standards with rapid growth, and you will partner with engineering to embed controls into the platform.

The ideal candidate has hands‑on fintech compliance experience (PCI DSS, NYDFS, FFIEC), data privacy familiarity (GDPR, CCPA), and GRC engineering skills including

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Security Engineer - GRC Fintech & Financial Services
Sr. Security Engineer - GRC Fintech & Financial Services

SpaceXAI • Palo Alto (CA)

On-site
USD 152,000 - 228,000
Equity
Comprehensive medical, vision, dental
401(k) retirement plan
Hybrid GRC Engineer — Fintech Compliance & Automation
Hybrid GRC Engineer — Fintech Compliance & Automation

PEAK6 • United States

Hybrid
GBP 65,000 - 95,000
Annual bonus
Leave & holidays
Training budget
+7
GRC Engineer — Hybrid, Automation & Audits Lead
GRC Engineer — Hybrid, Automation & Audits Lead

Apex Fintech Solutions • United States

Hybrid
GBP 70,000 - 110,000
Market-leading salary
Annual bonus
28 days annual leave
+7
Tech GRC Engineering PM: Compliance & Automation Leader
Tech GRC Engineering PM: Compliance & Automation Leader

Stripe • United States

Hybrid
USD 193,000 - 291,000
AI-Driven GRC Engineer for Continuous Compliance
AI-Driven GRC Engineer for Continuous Compliance

Treasure AI • United States

On-site
USD 140,000 - 210,000
Comprehensive medical, dental, vision
401K with company match
RSU
+2
GRC Engineer: AI-Driven Security & Compliance Architect
GRC Engineer: AI-Driven Security & Compliance Architect

Webhosting • Austin (TX)

On-site
USD 140,000 - 210,000
Equity plan
GRC Automation Engineer — Controls & Compliance
GRC Automation Engineer — Controls & Compliance

Box • United States

On-site
USD 140,000 - 190,000
Remote AI-Driven GRC Engineer for Scale
Remote AI-Driven GRC Engineer for Scale

RiverPark Ventures • New York (NY)

On-site
USD 130,000 - 170,000
Medical, Dental and Vision plans
401(k) plan with match
Paid holidays
+7
Senior GRC Engineer - Automate Compliance & Security
Senior GRC Engineer - Automate Compliance & Security

Cloud Software Group • San Ramon (CA)

On-site
USD 160,000 - 241,000
AI-Driven GRC Automation Engineer
AI-Driven GRC Automation Engineer

Granicus • United States

Remote
USD 104,000 - 123,000
Flexible Time Off
Wellbeing Days
Work From Home Reimbursement
+9