Sr. Security Engineer - GRC Fintech & Financial Services

SpaceXAI

Palo Alto (CA)

On-site

USD 152,000 - 228,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Equity
Comprehensive medical, vision, dental
401(k) retirement plan

Job summary

SpaceXAI is seeking an experienced Governance, Risk, and Compliance (GRC) Engineer focused on fintech and regulatory compliance to scale our GRC program. You will architect systems that automate trust, balancing rigorous standards with rapid growth, and you will partner with engineering to embed controls into the platform.

The ideal candidate has hands‑on fintech compliance experience (PCI DSS, NYDFS, FFIEC), data privacy familiarity (GDPR, CCPA), and GRC engineering skills including

Qualifications

  • Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field.
  • 8+ years of experience in GRC, security compliance, or technology audit roles in fintech, banking, payments, or other heavily regulated financial environments.
  • Hands‑on experience with PCI DSS and at least one of NYDFS (23 NYCRR 500) or FFIEC cybersecurity/IT examination guidance — including implementing or operating controls, not only reading the requirements.
  • Experience with Compliance‑as‑Code practices and GRC automation tooling (e.g., Vanta, or similar), with a bias toward continuous monitoring and reducing manual evidence collection.
  • Technical fluency sufficient to speak the language of engineering, cloud (AWS/GCP/Azure), and security architecture, and to anticipate how design decisions impact risk and compliance.

Responsibilities

  • Own and evolve financial services and payments compliance posture across PCI DSS, NYDFS (including 23 NYCRR 500), FFIEC guidance, and related banking/fintech regulatory expectations supporting xMoney across relevant jurisdictions.
  • Build and maintain Compliance‑as‑Code capabilities — policy‑as‑code, automated control validation, continuous evidence collection, and monitoring integrated into CI/CD — so audit readiness scales with the business rather than depending on manual, point‑in‑time checks.
  • Operate and extend GRC platforms (e.g., Vanta) as the backbone for control mapping, evidence management, and continuous compliance; integrate with cloud, identity, logging, and engineering systems to reduce administrative bottlenecks.
  • Partner with Architects and Engineering Leads to bake compliance and privacy requirements; translate complex regulatory obligations into concrete technical implementations and auditor‑ready narratives without slowing development.
  • Design, implement, and validate technical controls relevant to fintech environments (cardholder data environment scoping and segmentation, access control, logging, encryption, change management, vulnerability management) — not just document them.
  • Operate the cybersecurity and compliance risk register — identify, quantify, and track risks, distinguishing theoretical gaps from meaningful business and regulatory risk.
  • Lead risk assessments and compliance reviews for new products, payment flows, features, vendors, and architectural changes that affect the regulated attack surface.
  • Own and cultivate relationships with external auditors, assessors (e.g., QSAs where applicable), and regulators; serve as the bridge between auditors and internal teams so requests are reasonable, clear, and relevant to our stack.
  • Develop, maintain, and continuously improve policies, standards, and procedures aligned to PCI, NYDFS, FFIEC, privacy laws, and complementary frameworks (e.g., SOC 2, ISO 27001) where they overlap.
  • Champion pragmatic governance — prioritize issues that represent real security or business risk over checkbox compliance.

Skills

GRC Engineering
Compliance
PCI DSS
NYDFS 23 NYCRR 500
FFIEC
Compliance‑as‑Code
CI/CD
Cloud Security
Auditing
Regulatory liaison

Education

Bachelor's degree in computer science or information security or engineering/STEM
Engineering/STEM background

Tools

Vanta
GRC automation tooling

Job description

SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands‑on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates.

SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands‑on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates.

ABOUT THE ROLE:

We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer focused on fintech and financial services regulation to help scale compliance for SpaceXAI and xMoney. As we operate deeper in regulated financial environments, maintaining a robust, transparent, and technically sound GRC program is critical. You will architect the systems and processes that automate trust — a pragmatic operator who understands that GRC exists to enable the business, balancing rigorous standards with the velocity of a high‑growth company. The ideal candidate brings hands‑on fintech compliance experience (PCI DSS, NYDFS, FFIEC), fluency in data privacy frameworks (GDPR, CCPA), and GRC engineering skills: Compliance‑as‑Code, continuous evidence collection, and deep partnership with engineering so controls are designed into the platform rather than bolted on after the fact.

RESPONSIBILITIES:
  • Own and evolve financial services and payments compliance posture across PCI DSS, NYDFS (including 23 NYCRR 500), FFIEC guidance, and related banking/fintech regulatory expectations supporting xMoney across relevant jurisdictions.
  • Build and maintain Compliance‑as‑Code capabilities — policy‑as‑code, automated control validation, continuous evidence collection, and monitoring integrated into CI/CD — so audit readiness scales with the business rather than depending on manual, point‑in‑time checks.
  • Operate and extend GRC platforms (e.g., Vanta) as the backbone for control mapping, evidence management, and continuous compliance; integrate with cloud, identity, logging, and engineering systems to reduce administrative bottlenecks.
  • Partner with Architects and Engineering Leads to bake compliance and privacy requirements; translate complex regulatory obligations into concrete technical implementations and auditor‑ready narratives without slowing development.
  • Design, implement, and validate technical controls relevant to fintech environments (cardholder data environment scoping and segmentation, access control, logging, encryption, change management, vulnerability management) — not just document them.
  • Operate the cybersecurity and compliance risk register — identify, quantify, and track risks, distinguishing theoretical gaps from meaningful business and regulatory risk.
  • Lead risk assessments and compliance reviews for new products, payment flows, features, vendors, and architectural changes that affect the regulated attack surface.
  • Own and cultivate relationships with external auditors, assessors (e.g., QSAs where applicable), and regulators; serve as the bridge between auditors and internal teams so requests are reasonable, clear, and relevant to our stack.
  • Develop, maintain, and continuously improve policies, standards, and procedures aligned to PCI, NYDFS, FFIEC, privacy laws, and complementary frameworks (e.g., SOC 2, ISO 27001) where they overlap.
  • Champion pragmatic governance — prioritize issues that represent real security or business risk over checkbox compliance.
BASIC QUALIFICATIONS:
  • Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field.
  • 8+ years of experience in GRC, security compliance, or technology audit roles in fintech, banking, payments, or other heavily regulated financial environments.
  • Hands‑on experience with PCI DSS and at least one of NYDFS (23 NYCRR 500) or FFIEC cybersecurity/IT examination guidance — including implementing or operating controls, not only reading the requirements.
  • Experience with Compliance‑as‑Code practices and GRC automation tooling (e.g., Vanta, or similar), with a bias toward continuous monitoring and reducing manual evidence collection.
  • Technical fluency sufficient to speak the language of engineering, cloud (AWS/GCP/Azure), and security architecture, and to anticipate how design decisions impact risk and compliance.
PREFERRED SKILLS AND EXPERIENCE:
  • 10+ years of security compliance, GRC engineering, or technology audit‑related experience in fintech or financial services.
  • Hands‑on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, network segmentation, infrastructure hardening) and integrating compliance checks into CI/CD pipelines.
  • Experience supporting SOC 2 and/or ISO 27001 programs alongside fintech‑specific obligations.
  • Experience with payment ecosystems, cardholder data environments, tokenization, or similar PCI‑scoped architectures.
  • Working knowledge of data privacy frameworks including GDPR and CCPA/CPRA, and experience partnering with Legal or Privacy.
  • Familiarity with additional financial regulatory regimes (e.g., GLBA, BSA/AML technology controls, state money‑transmitter expectations, or international banking rules in the EU, UK, or other markets, e.g DORA) is valuable.
  • Experience enabling enterprise sales through trust centers, vendor questionnaires, and customer security reviews.
  • Proven ability to operate a risk register and apply judgment in gray areas — focusing on outcomes over optics.
  • Exceptional analytical, problem‑solving, organizational, and project management skills, with the ability to take compliance programs from conception to assessment‑ready launch.
  • Excellent communication and stakeholder management skills — able to explain regulatory and privacy requirements to engineers, legal, sales, and executives in plain language.
  • Certifications such as CISSP, CISA, CISM, CRISC, PCIP, CIPP/US, CIPP/E, or similar preferred.
  • Experience with emerging AI‑related financial services expectations or securing AI features in a regulated fintech product is a plus.
COMPENSATION AND BENEFITS:

$152,000 - $228,000 USD

Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks.

ITAR REQUIREMENTS:
  • To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here .

SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Security Engineer - GRC Fintech & Financial Services
Sr. Security Engineer - GRC Fintech & Financial Services

Pantera Capital • Palo Alto (CA)

On-site
USD 152,000 - 258,000
Fraud Analyst
Fraud Analyst

Pantera Capital • Palo Alto (CA)

On-site
USD 100,000 - 135,000
Senior BSA/AML Investigator (Sat - Wed)
Senior BSA/AML Investigator (Sat - Wed)

SpaceXAI • Palo Alto (CA)

Hybrid
USD 120,000 - 145,000
Equity
Medical coverage
Vision
+6
Sr. Cyber Assurance Analyst, Finance
Sr. Cyber Assurance Analyst, Finance

InvestedintheMission • Hawthorne (CA)

On-site
USD 130,000 - 195,000
Stock options
Long-term incentives
Medical, vision, dental coverage
+5
Sr. Cyber Assurance Analyst, Finance
Sr. Cyber Assurance Analyst, Finance

SPACE EXPLORATION TECHNOLOGIES CORP • Hawthorne (CA)

On-site
USD 130,000 - 195,000
Medical, Vision, Dental coverage
401(k) retirement plan
Paid parental leave
+2
Sr. Cyber Assurance Analyst, Finance
Sr. Cyber Assurance Analyst, Finance

SpaceX • Redmond (WA)

On-site
USD 130,000 - 200,000
Stock options
Medical, vision & dental
401(k) plan
+4
Sr. Cyber Assurance Analyst, Finance
Sr. Cyber Assurance Analyst, Finance

SpaceX • Hawthorne (CA)

On-site
USD 130,000 - 195,000
Company stock
401(k) plan
Medical, vision, dental
+2
Fraud Analyst (Sat-Weds)
Fraud Analyst (Sat-Weds)

Pantera Capital • Palo Alto (CA)

Hybrid
USD 100,000 - 135,000
Equity
Medical coverage
401(k) retirement plan
+2
Sr. Cyber Assurance Analyst, Finance
Sr. Cyber Assurance Analyst, Finance

InvestedintheMission • Redmond (WA)

On-site
USD 130,000 - 200,000
Medical coverage
Vision coverage
Dental coverage
+2
Sr. Cyber Assurance Analyst, Finance
Sr. Cyber Assurance Analyst, Finance

SpaceX • Union Hill-Novelty Hill (WA)

On-site
USD 130,000 - 200,000
Company shuttles
Medical, vision, dental coverage
401(k) retirement plan
+1