Назад
15 часов назад

Sr. Security Engineer - GRC EU/UK Regulation & Data Protection

Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Sr. Security Engineer - GRC EU/UK Regulation & Data Protection (DORA/EU AI Act): Building and operating automated information security GRC capabilities for regulated EU/UK financial services and AI products with an accent on Compliance-as-Code, continuous evidence collection, and operational resilience. Focus on implementing technical controls, assessing regulatory and third-party risk, and translating DORA, GDPR, NIS2, and EU AI Act obligations into secure engineering practices.

Location: London, England, United Kingdom

Company

Develops AI systems and regulated financial products, including xMoney, with a focus on engineering excellence and practical governance.

What you will do

  • Own and evolve EU/UK financial services and digital operational resilience compliance across DORA and UK PRA/FCA requirements.
  • Build Compliance-as-Code capabilities, including policy-as-code, automated control validation, continuous evidence collection, and CI/CD monitoring.
  • Operate and extend GRC platforms such as Vanta, integrating them with cloud, identity, logging, and engineering systems.
  • Design and validate technical security controls covering access management, logging, encryption, change management, vulnerability management, third-party ICT risk, and secure SDLC.
  • Partner with architects and engineering leads to embed regulatory and security requirements into product and platform design.
  • Lead risk assessments, compliance reviews, audit and supervisory relationships, policies, risk registers, and assessment-ready compliance programs.

Requirements

  • Bachelor’s degree in computer science, information security, cybersecurity, engineering, or another STEM field.
  • At least 5 years of GRC, information security compliance, or technology audit experience in fintech, banking, payments, or other heavily regulated environments with EU/UK exposure.
  • Hands-on experience with several of DORA, the EU AI Act, NIS2, PSD2/PSR, or UK PRA/FCA operational resilience requirements.
  • Experience with Compliance-as-Code, GRC automation, continuous monitoring, and reducing manual evidence collection.
  • Technical fluency across security architecture and on-premises, hybrid, or cloud environments such as AWS, GCP, or Azure.
  • Working knowledge of EU/UK privacy requirements, including EU GDPR, UK GDPR, and the UK Data Protection Act 2018.

Nice to have

  • 7+ years of information security compliance, GRC engineering, or technology audit experience with a primary EU/UK focus.
  • Experience with IAM, logging and monitoring, encryption, network segmentation, infrastructure hardening, and compliance checks in CI/CD.
  • ISO 27001 and/or SOC 2 program experience, plus DORA ICT third-party risk, register of information, TLPT, and major incident reporting knowledge.
  • Experience with AI governance, trust centers, vendor questionnaires, customer security reviews, or regulated financial institutions.
  • CISSP, CISA, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, or similar certification.

Culture & Benefits

  • Small, highly motivated team with a flat organizational structure.
  • Hands-on environment focused on engineering excellence, curiosity, initiative, and direct contribution.
  • Strong emphasis on concise, accurate communication and pragmatic governance over checkbox compliance.
  • Occasional travel may be required.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →