Security Engineer - Grc Fintech & Financial Services

xAI xAI · AI Frontier · Palo Alto, CA · Information Security

Experienced GRC Engineer focused on fintech and financial services regulation to scale compliance for SpaceXAI and xMoney. Responsibilities include owning financial services compliance posture, building Compliance-as-Code capabilities, operating GRC platforms, partnering with engineering on controls, designing technical controls, managing risk registers, leading risk assessments, and managing external auditor relationships. Requires 8+ years of experience in GRC/security compliance/technology audit in regulated financial environments, with hands-on experience in PCI DSS and NYDFS or FFIEC, and Compliance-as-Code practices.

What you'd actually do

  1. Own and evolve financial services and payments compliance posture across PCI DSS, NYDFS (including 23 NYCRR 500), FFIEC guidance, and related banking/fintech regulatory expectations supporting xMoney across relevant jurisdictions.
  2. Build and maintain Compliance-as-Code capabilities — policy-as-code, automated control validation, continuous evidence collection, and monitoring integrated into CI/CD — so audit readiness scales with the business rather than depending on manual, point-in-time checks.
  3. Operate and extend GRC platforms (e.g., Vanta) as the backbone for control mapping, evidence management, and continuous compliance; integrate with cloud, identity, logging, and engineering systems to reduce administrative bottlenecks.
  4. Partner with Architects and Engineering Leads to bake compliance and privacy requirements; translate complex regulatory obligations into concrete technical implementations and auditor-ready narratives without slowing development.
  5. Design, implement, and validate technical controls relevant to fintech environments (cardholder data environment scoping and segmentation, access control, logging, encryption, change management, vulnerability management) — not just document them.

Skills

Required

  • 8+ years of experience in GRC, security compliance, or technology audit roles in fintech, banking, payments, or other heavily regulated financial environments.
  • Hands-on experience with PCI DSS and at least one of NYDFS (23 NYCRR 500) or FFIEC cybersecurity/IT examination guidance — including implementing or operating controls, not only reading the requirements.
  • Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, or similar), with a bias toward continuous monitoring and reducing manual evidence collection.
  • Technical fluency sufficient to speak the language of engineering, cloud (AWS/GCP/Azure), and security architecture, and to anticipate how design decisions impact risk and compliance.

Nice to have

  • 10+ years of security compliance, GRC engineering, or technology audit-related experience in fintech or financial services.
  • Hands-on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, network segmentation, infrastructure hardening) and integrating compliance checks into CI/CD pipelines.
  • Experience supporting SOC 2 and/or ISO 27001 programs alongside fintech-specific obligations.
  • Experience with payment ecosystems, cardholder data environments, tokenization, or similar PCI-scoped architectures.
  • Working knowledge of data privacy frameworks including GDPR and CCPA/CPRA, and experience partnering with Legal or Privacy.
  • Familiarity with additional financial regulatory regimes (e.g., GLBA, BSA/AML technology controls, state money-transmitter expectations, or international banking rules in the EU, UK, or other markets, e.g DORA) is valuable.
  • Experience enabling enterprise sales through trust centers, vendor questionnaires, and customer security reviews.
  • Proven ability to operate a risk register and apply judgment in gray areas — focusing on outcomes over optics.
  • Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to take compliance programs from conception

What the JD emphasized

  • fintech and financial services regulation
  • PCI DSS
  • NYDFS
  • FFIEC
  • Compliance-as-Code
  • continuous evidence collection
  • technical controls